react-devtools-mcp (skylarbarrera/react-devtools-mcp) is an MCP server listed on the M8ven Trust Index. It scores 70 out of 100, grade C. It declares 45 tools. No publisher has claimed this listing.
Provides AI agents with visibility into React applications by exposing tools to inspect component state, props, and performance metrics. It enables debugging and state analysis for both web and React Native applications through the Model Context Protocol.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
skylarbarrera
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
connectConnect to React DevTools backend via WebSocket
disconnectDisconnect from React DevTools backend
get_connection_statusGet current connection status
get_component_treeGet the React component tree for all roots
get_element_by_idGet basic element info by ID
search_componentsSearch for components by name
inspect_elementGet full inspection data for a component including props, state, hooks
get_owners_listGet the chain of components that rendered this element
get_element_sourceGet source location for an element
override_propsOverride a prop value on a component
override_stateOverride a state value on a class component
override_hooksOverride a hook value on a function component
override_contextOverride a context value
delete_pathDelete a path from props/state/hooks/context
rename_pathRename a key in props/state/hooks/context
start_profilingStart profiling React renders
stop_profilingStop profiling and get data
get_profiling_dataGet profiling data without stopping
get_profiling_statusCheck if profiling is active
get_errors_and_warningsGet all errors and warnings from components
clear_errors_and_warningsClear all or specific element's errors/warnings
toggle_errorToggle error boundary state for testing
toggle_suspenseToggle suspense state for testing
highlight_elementHighlight an element in the app UI
clear_highlightClear any active element highlight
scroll_to_elementScroll the app to show an element
log_to_consoleLog an element to the browser/app console as $r
store_as_globalStore a value as a global variable for console access
view_sourceOpen element source in IDE (if supported)
get_component_filtersGet current component filters
set_component_filtersSet component filters (hide certain components)
set_trace_updates_enabledEnable/disable visual update highlighting
get_native_styleGet native style and layout info (React Native only)
set_native_styleSet a native style property (React Native only)
health_checkGet server and connection health status
get_capabilitiesGet negotiated protocol capabilities (features supported by backend)
get_renderersGet all connected React renderers (for multi-renderer apps)
get_rendererGet a specific renderer by ID
get_elements_by_rendererGet all elements for a specific renderer
start_inspecting_nativeStart native element inspection mode (tap-to-select)
stop_inspecting_nativeStop native element inspection mode
get_inspecting_native_statusCheck if native inspection mode is active
capture_screenshotCapture screenshot of an element (if supported)
save_to_clipboardSave content to system clipboard
view_attribute_sourceGet source location for a specific attribute path
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
ws: Memory exhaustion DoS from tiny fragments and data chunks
ws: Uninitialized memory disclosure
DEVTOOLS_AUTO_CONNECTDEVTOOLS_DEBUGDEVTOOLS_HOSTDEVTOOLS_LOG_LEVELDEVTOOLS_PORTDEVTOOLS_STANDALONEDEVTOOLS_TIMEOUTDependencies
10 dependencies, 1 flagged: puppeteer
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
45/45 tools missing one or more hints — connect (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); disconnect (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_connection_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +42 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 2/45 tools referenced in tests (4%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
0 critical, 2 high severity in production deps — @modelcontextprotocol/sdk@1.0.0 (high), ws@8.18.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
2 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/skylarbarrera/react-devtools-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check