← Home

For AI coding agents

NativeKeel MCP: React Native ground truth for your AI agent

AI agents lose hours on React Native upgrades: native build errors, library versions that do not match your React Native version, New Architecture blockers, store rules that changed last month. NativeKeel already knows the answers. Over the Model Context Protocol, Claude Code, Codex, Cursor and other agents can ask it instead of guessing.

Set it up

Install in CursorInstall in VS Code

Claude Code

The plugin adds the MCP server and a skill that tells Claude when to use it, so you do not have to ask:

claude plugin marketplace add AlicanAkyol/nativekeel
claude plugin install nativekeel@nativekeel

Or only the MCP server: claude mcp add nativekeel -- npx -y nativekeel@latest mcp

Codex

The plugin adds the MCP server and the same skill:

codex plugin marketplace add AlicanAkyol/nativekeel
codex plugin add nativekeel@nativekeel

Codex starts plugin servers in the plugin's own folder, so the plugin uses your home folder as the boundary. To narrow it to one project, configure the server yourself in ~/.codex/config.toml (below) with NATIVEKEEL_MCP_ROOTS in its env.

Or only the MCP server:

# ~/.codex/config.toml
[mcp_servers.nativekeel]
command = "npx"
args = ["-y", "nativekeel@latest", "mcp"]

Any agent, no MCP needed

Add one line to your project's AGENTS.md or CLAUDE.md:

Before upgrading React Native or Expo, adding a native library, or preparing a store release, run `npx -y nativekeel@latest --json` and fix the critical and high findings first.

Also listed in the official MCP Registry as io.github.AlicanAkyol/nativekeel.

What changes, on one real app

We asked Claude Code the same question in an open-source Expo SDK 57 app, without naming NativeKeel: "I want to upgrade this app to the latest React Native. What will break and what should I do first?"

With the NativeKeel pluginWithout
How it workedLoaded the skill on its own, called upgrade_plan and scan_projectRead files, searched the web
Turns · cost9 · $0.3416 · $0.63
Xcode 27 / UISceneFound, with the exact package versionsFound
Missing account deletion (App Store 5.1.1(v), Google Play)Found: it blocks the next releaseMissed
Expo SDK 58 changes (R8 on by default in release builds)Found, and checked that the app's release scripts are affectedFound

One app, one run each, so read it as an example rather than a benchmark. The first run (NativeKeel 0.1.57) missed the SDK 58 changes, which the agent without NativeKeel found on the web; 0.1.59 added them, and the table shows the run after that.

What the agent can ask

ToolAnswers
security_auditFocused security review: data exposure, account access, unsafe code execution and backend rules. Source evidence, attacker prerequisites, fixes, validation steps and explicit coverage limits. No live attack.
scan_projectWhat is wrong with this project: upgrade blockers, New Architecture, Google Play and App Store rules (target SDK, 16 KB pages, Xcode 27 UIScene, privacy manifests), crash risks, OWASP MASVS security findings, and malware planted in the project. Each with file:line and the fix.
upgrade_planThe order to do it in: phases, the reason for each, concrete steps.
explain_errorA build, launch, crash or App Store / Google Play review error: what it means, the fix, and where this project is affected. Matched locally against errors we reproduced or verified at the source.
verify_upgradeAfter an upgrade, before committing: what got fixed, what is new and how versions moved compared with the last commit (or any revision).
check_libraryBefore adding or upgrading a package: latest version, New Architecture support, maintenance status, the range that works with your React Native version, replacements and known traps.

Built for untrusted code

An agent reads what a tool returns, so a malicious repository could try to use the tool to pass instructions to the agent. The server is designed against that:

Details: SECURITY.md.

Prefer the terminal?

npx nativekeel
See a sample reportWhat's new