DevPilot MCP
An MCP server that gives an AI model structured, security-conscious access to one software repository. It can read and search code, describe the repository, inspect Git and GitHub, gather evidence for developer questions, apply patches you supply (and revert them), and run the repository's Python tests.
DevPilot collects evidence and performs tightly bounded actions. The AI model does the reasoning.
AI model (e.g. Gemini) ──► MCP client ──stdio──► DevPilot MCP server ──► your repository
Features
- Explore: list, read and search files; source-only code search.
- Understand: languages, structure, dependency manifests, tests, entry points and frameworks.
- Git and GitHub: status, log, diff and branches; repository, issues and pull requests (all read-only).
- Investigate: ranked evidence for questions like "Where is authentication implemented?"
- Patch: apply an explicit unified diff atomically, and revert it.
- Test: detect pytest/unittest, run tests with a fixed command, and produce a validation report.
Tools
| Tool | What it does | Access |
|---|---|---|
list_directory |
List a directory | Read-only |
read_file |
Read a text file | Read-only |
search_files |
Search text in all files, optionally in one folder | Read-only |
search_code |
Smart-case search in source files | Read-only |
analyze_repository |
Languages, structure, manifests, tests, entry points | Read-only |
git_status |
Branch, staged, unstaged and untracked files | Read-only |
git_log |
Recent commits | Read-only |
git_diff |
Staged or unstaged changes | Read-only |
git_branch |
Local branches | Read-only |
github_repository |
GitHub metadata for origin |
Read-only |
github_issues |
Recent issues | Read-only |
github_pull_requests |
Recent pull requests | Read-only |
investigate_repository |
Ranked evidence for a developer question | Read-only |
apply_patch |
Apply a unified diff you supply, atomically | Writes files |
revert_patch |
Undo an applied patch | Writes files |
get_test_commands |
Detect pytest/unittest (runs nothing) | Read-only |
run_tests |
Run the detected test command | Executes code |
validate_repository |
Validation report; tests only on request | Executes code |
Quick Start
Requires Python 3.10+ (3.11+ recommended) and Git.
Install from PyPI:
pip install devpilot-mcp
When installed this way, always set DEVPILOT_WORKSPACE to the absolute path of the repository DevPilot should work on, for example in your MCP client's server settings.
Or clone the repository (includes the tests and a sample workspace):
git clone https://github.com/KD-kaustubh/devpilot-mcp.git
cd devpilot-mcp
python -m venv .venv
.venv\Scripts\activate # macOS/Linux: source .venv/bin/activate
pip install -e .
copy .env.example .env # macOS/Linux: cp .env.example .env
In .env, set DEVPILOT_WORKSPACE to the repository DevPilot should work on. The default is the bundled ./workspace sample, which is not a Git repository. GITHUB_TOKEN is optional.
Try It
1. Run the test suite
python -m unittest discover -s tests -t .
2. Explore it with MCP Inspector (needs Node.js)
npx @modelcontextprotocol/inspector
Set Transport to STDIO and Command to the full path of .venv\Scripts\devpilot-mcp.exe, then click Connect and List Tools. Try search_code with query = format_price.
3. Connect an AI client. Register DevPilot as a stdio server. For example, with Claude Code:
claude mcp add devpilot -e DEVPILOT_WORKSPACE=D:/path/to/repo -- D:/path/to/devpilot-mcp/.venv/Scripts/devpilot-mcp.exe
Then ask: "Use DevPilot to analyze this repository and explain its structure." More in the usage guide.
Security at a Glance
- Every path stays inside the workspace.
.., absolute, drive and UNC paths, and escaping symlinks are rejected. - Only two places start processes: allowlisted read-only Git commands, and two fixed Python test commands. There is no shell and no caller-supplied command.
- Patches are validated in full and applied atomically.
.gitand secret files can never be written. - GitHub access is HTTPS GET to
api.github.comonly, and the token never appears in output. - Every tool is annotated as read-only, writes-files or executes-code, so clients can ask before risky calls.
It is not a sandbox. Tests run with DevPilot's own permissions and network access, and secret redaction is best-effort. See Security for the full model and known limitations.
Documentation
| Document | Contents |
|---|---|
| Usage guide | Configuration, MCP Inspector, client setup, example workflows |
| Tool reference | Every tool's inputs, output examples and limits |
| Security | Security model, known limitations, security tests |
| Development | Architecture, running tests, CI, phase history |
License
Release files for devpilot-mcp 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| devpilot_mcp-0.1.0.tar.gz | 124.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| devpilot_mcp-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 210.5 kB
Release files / devpilot_mcp-0.1.0.tar.gz
| Download URL | devpilot_mcp-0.1.0.tar.gz |
|---|---|
| Size | 124.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
959146a7fbfef1b5feb1433ca7eb4faaac10aad00bccad8363d5f8361fc70a4f
|
|
BLAKE2b-256 checksum How to use checksums |
dee5524772cccc3a8a0dc99022062d4a5f06bc55f0d4e7649fcf3ac7f89be6ab
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / devpilot_mcp-0.1.0-py3-none-any.whl
| Download URL | devpilot_mcp-0.1.0-py3-none-any.whl |
|---|---|
| Size | 85.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f7c2b0c1fe9e58d38242a8d88df968769f3b1ce1e8335bc1cdf86995267a1bec
|
|
BLAKE2b-256 checksum How to use checksums |
6ecc0bac8562dbeb0d486ce7cc0451337a12486dee3403d6f8394a96ac4eacfb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log