Skip to main content

DevPilot MCP

Tests License: MIT

An MCP server that gives an AI model structured, security-conscious access to one software repository. It can read and search code, describe the repository, inspect Git and GitHub, gather evidence for developer questions, apply patches you supply (and revert them), and run the repository's Python tests.

DevPilot collects evidence and performs tightly bounded actions. The AI model does the reasoning.

AI model (e.g. Gemini) ──► MCP client ──stdio──► DevPilot MCP server ──► your repository

Features

  • Explore: list, read and search files; source-only code search.
  • Understand: languages, structure, dependency manifests, tests, entry points and frameworks.
  • Git and GitHub: status, log, diff and branches; repository, issues and pull requests (all read-only).
  • Investigate: ranked evidence for questions like "Where is authentication implemented?"
  • Patch: apply an explicit unified diff atomically, and revert it.
  • Test: detect pytest/unittest, run tests with a fixed command, and produce a validation report.

Tools

Tool What it does Access
list_directory List a directory Read-only
read_file Read a text file Read-only
search_files Search text in all files, optionally in one folder Read-only
search_code Smart-case search in source files Read-only
analyze_repository Languages, structure, manifests, tests, entry points Read-only
git_status Branch, staged, unstaged and untracked files Read-only
git_log Recent commits Read-only
git_diff Staged or unstaged changes Read-only
git_branch Local branches Read-only
github_repository GitHub metadata for origin Read-only
github_issues Recent issues Read-only
github_pull_requests Recent pull requests Read-only
investigate_repository Ranked evidence for a developer question Read-only
apply_patch Apply a unified diff you supply, atomically Writes files
revert_patch Undo an applied patch Writes files
get_test_commands Detect pytest/unittest (runs nothing) Read-only
run_tests Run the detected test command Executes code
validate_repository Validation report; tests only on request Executes code

Quick Start

Requires Python 3.10+ (3.11+ recommended) and Git.

Install from PyPI:

pip install devpilot-mcp

When installed this way, always set DEVPILOT_WORKSPACE to the absolute path of the repository DevPilot should work on, for example in your MCP client's server settings.

Or clone the repository (includes the tests and a sample workspace):

git clone https://github.com/KD-kaustubh/devpilot-mcp.git
cd devpilot-mcp
python -m venv .venv
.venv\Scripts\activate           # macOS/Linux: source .venv/bin/activate
pip install -e .
copy .env.example .env           # macOS/Linux: cp .env.example .env

In .env, set DEVPILOT_WORKSPACE to the repository DevPilot should work on. The default is the bundled ./workspace sample, which is not a Git repository. GITHUB_TOKEN is optional.

Try It

1. Run the test suite

python -m unittest discover -s tests -t .

2. Explore it with MCP Inspector (needs Node.js)

npx @modelcontextprotocol/inspector

Set Transport to STDIO and Command to the full path of .venv\Scripts\devpilot-mcp.exe, then click Connect and List Tools. Try search_code with query = format_price.

3. Connect an AI client. Register DevPilot as a stdio server. For example, with Claude Code:

claude mcp add devpilot -e DEVPILOT_WORKSPACE=D:/path/to/repo -- D:/path/to/devpilot-mcp/.venv/Scripts/devpilot-mcp.exe

Then ask: "Use DevPilot to analyze this repository and explain its structure." More in the usage guide.

Security at a Glance

  • Every path stays inside the workspace. .., absolute, drive and UNC paths, and escaping symlinks are rejected.
  • Only two places start processes: allowlisted read-only Git commands, and two fixed Python test commands. There is no shell and no caller-supplied command.
  • Patches are validated in full and applied atomically. .git and secret files can never be written.
  • GitHub access is HTTPS GET to api.github.com only, and the token never appears in output.
  • Every tool is annotated as read-only, writes-files or executes-code, so clients can ask before risky calls.

It is not a sandbox. Tests run with DevPilot's own permissions and network access, and secret redaction is best-effort. See Security for the full model and known limitations.

Documentation

Document Contents
Usage guide Configuration, MCP Inspector, client setup, example workflows
Tool reference Every tool's inputs, output examples and limits
Security Security model, known limitations, security tests
Development Architecture, running tests, CI, phase history

License

MIT

Release files for devpilot-mcp 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for devpilot-mcp 0.1.0
File Size Uploaded
devpilot_mcp-0.1.0.tar.gz 124.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for devpilot-mcp 0.1.0
File Interpreter ABI Platform
devpilot_mcp-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 210.5 kB

Release files / devpilot_mcp-0.1.0.tar.gz

Download URL devpilot_mcp-0.1.0.tar.gz
Size 124.9 kB
Tags Source
SHA-256 checksum
How to use checksums
959146a7fbfef1b5feb1433ca7eb4faaac10aad00bccad8363d5f8361fc70a4f
BLAKE2b-256 checksum
How to use checksums
dee5524772cccc3a8a0dc99022062d4a5f06bc55f0d4e7649fcf3ac7f89be6ab
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / devpilot_mcp-0.1.0-py3-none-any.whl

Download URL devpilot_mcp-0.1.0-py3-none-any.whl
Size 85.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f7c2b0c1fe9e58d38242a8d88df968769f3b1ce1e8335bc1cdf86995267a1bec
BLAKE2b-256 checksum
How to use checksums
6ecc0bac8562dbeb0d486ce7cc0451337a12486dee3403d6f8394a96ac4eacfb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page