MCP server for Magento 2 coding standards - enables AI-assisted vibe coding with Claude, Cursor, Gemini, VS Code Copilot, and more
The server provides 7 well-defined tools for Magento coding standards with clear names and reasonable descriptions. All tools have explicit input schemas with proper types and required field declarations. However, there are significant gaps in output schema documentation, parameter descriptions lack depth, and error handling is minimal. Tool names follow verb_noun convention well (get_, validate_, check_, explain_, list_, manage_). Descriptions are present and reasonably detailed (averaging ~150-180 chars), meeting baseline minimums. Schemas use proper JSON types (object, string, enum, number) with required arrays. Main issues: (1) output schemas are not documented anywhere in the visible code, (2) parameter descriptions are generic ('The code to validate' vs. concrete constraints), (3) no validation guidance or actionable error messages shown, (4) manage_theme tool mixes read (list, info) and write (set, clear) actions in one tool, violating single-responsibility. The code sample is truncated, so full implementation details of error handling are not visible.
Perform security-focused validation on code. Checks for XSS vulnerabilities, SQL injection risks, insecure functions, and other security issues.
Get detailed explanation of a Magento coding standard rule including reasoning, bad/good examples, and fix suggestions.
Get the correct Magento 2 way to accomplish a task. Returns the proper pattern, code example, and what to avoid. Use this for "vibe coding" - writing Magento-compliant code naturally.
Get a summary of all Magento coding standard rules grouped by category, showing counts of errors and warnings.
List all Magento coding standard rules. Can filter by category (Security, Legacy, PHP, Functions, Templates, Less, etc.), minimum severity (1-10), or search term.
Manage theme-specific coding standards. Themes layer additional rules on top of base Magento standards. Built-in presets: hyva (Alpine.js + TailwindCSS), luma (jQuery + RequireJS + LESS), breeze (Vanilla JS), porto (Luma-based + Porto widgets). Custom themes can be added as JSON files.
Output schemas not documented. Code validation tools (validate_code, check_security) claim to return violations, errors, and suggestions but no output schema is visible. LLMs cannot plan downstream extraction or validation without knowing response structure.
Parameter descriptions are generic and lack actionable constraints. E.g., 'The code to validate' does not specify length limits, encoding requirements, or what constitutes valid code. 'The rule name to explain' lacks guidance on format (full qualified name vs. short name).
manage_theme tool combines read actions (list, info) and write actions (set, clear) in one tool, violating single-responsibility principle. Should split into list_themes/get_theme_info (read) and set_theme/clear_theme (write).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 44 | - | v1 |
Validate code against Magento 2 coding standards. Returns violations with severity, line numbers, and fix suggestions.
No visible error handling guidance. Code shows errorResponse() helper but no examples of how errors are structured or what actionable recovery guidance is provided. Cannot verify if errors include 'try X next' hints.
list_rules and get_rules_summary lack pagination parameters. If rule lists are large, returning all at once could exhaust context. No limit, offset, or cursor parameters visible.
No tool annotations present (readOnlyHint, destructiveHint, idempotentHint). While most tools are read-only (correct), manage_theme's set/clear actions should have destructiveHint or at least readOnlyHint=false to signal state mutation.