For AI coding agents
NativeKeel MCP: React Native ground truth for your AI agent
AI agents lose hours on React Native upgrades: native build errors, library versions that do not match your React Native version, New Architecture blockers, store rules that changed last month. NativeKeel already knows the answers. Over the Model Context Protocol, Claude Code, Codex, Cursor and other agents can ask it instead of guessing.
Set it up
# Claude Code, from the project folder
claude mcp add nativekeel -- npx -y nativekeel mcp
# Codex: ~/.codex/config.toml
[mcp_servers.nativekeel]
command = "npx"
args = ["-y", "nativekeel", "mcp"]
// Cursor: .cursor/mcp.json
{ "mcpServers": { "nativekeel": { "command": "npx", "args": ["-y", "nativekeel", "mcp"],
"env": { "NATIVEKEEL_MCP_ROOTS": "/absolute/path/to/your/projects" } } } }
What the agent can ask
| Tool | Answers |
|---|---|
scan_project | What is wrong with this project: upgrade blockers, New Architecture, Google Play and App Store rules (target SDK, 16 KB pages, Xcode 27 UIScene, privacy manifests), crash risks, OWASP MASVS security findings. Each with file:line and the fix. |
upgrade_plan | The order to do it in: phases, the reason for each, concrete steps. |
check_library | Before adding or upgrading a package: latest version, New Architecture support, maintenance status, the range that works with your React Native version, replacements and known traps. |
Built for untrusted code
An agent reads what a tool returns, so a malicious repository could try to use the tool to pass instructions to the agent. The server is designed against that:
- Read-only. No tool writes files, runs commands or executes project code.
- Only your folders. It scans folders under the directory it was started in (plus
NATIVEKEEL_MCP_ROOTS), with symlinks resolved. - No source code in results. Findings point to
file:line; file contents are never returned. - Cleaned text. Control, zero-width and bidi characters are removed; text that reads like instructions to an AI agent is replaced and reported.
- git cannot be turned against you. A repository's own git config cannot make the scan run a program.
- No dependencies, published with npm provenance.
Details: SECURITY.md.