AGZ Rust MCP
A standalone Rust validation MCP server built on Cargo and rustc output that never writes to your source files.
Overview
Open source developer tool
A standalone stdio MCP server. It offers bounded Rust validation based on Cargo and rustc output, source audits, crate documentation for the exact version and Rust Analyzer navigation. It does not write to source files: for rename and refactor it returns verified edit packages and does not apply them. Validation authority stays with Cargo and rustc; the trust limits of the semantic tools and edit suggestions are written down explicitly.
Who it is for: Developers who use an MCP-enabled coding client or AI agent in Rust projects.
AGZ Rust MCP
What it does
- Bounded Cargo validation: check, build, clippy, test, doc and fmt (check mode) targets, with structured diagnostics.
- Validation across a feature, target and toolchain matrix; test and regression comparison.
- Verifies a crate name and exact version in the registry and fetches the documentation for that version.
- Rust Analyzer navigation for symbols, references, definitions, implementations and hierarchies (advisory).
- Returns a verified edit package for rename and refactor; it does not write to the source.
- Produces compiler-guided repair candidates for a failing revision.
Limits
What it does not do
Knowing the limits up front avoids surprises.
- It does not write to source files; applying rename and refactor results is up to you.
- It is not an operating-system sandbox: build scripts, tests and proc macros can run with the permissions of the server account. Use a container or OS sandbox for stronger isolation.
- Rust Analyzer and audit results are advisory; Cargo and rustc are the authority.
- A successful check does not count as permission or evidence for a later request.
- It is published as open source; there is no separate support commitment.
Details
In detail
Tools
The server offers 20 tools in four groups.
| Group | Tools | What they do |
|---|---|---|
| Validation and evidence | check, profile, verify, audit, explain | Bounded Cargo validation; rebuild and runtime comparison; feature, target and toolchain matrix; bounded static source audit; explanation of macro expansion, unmet trait obligations and cfg activation. |
| Crate documentation and context | crate_lookup, docs, context, api | Verifies a crate name and exact version; exact-version Rust documentation; a task-focused, revision-bound context capsule; resolving an API signature or type-checking candidate code in an isolated copy. |
| Rust Analyzer navigation | symbol, references, definition, symbols, implementations, hierarchy | Code navigation; results are advisory. |
| Edits and workflow that do not write to source | rename, refactor, change, repair, work | Verified edit package (not applied); a revision-bound changeset in the server's scratch area; compiler-guided repair candidates; running a work item with explicit gates and single-use handoffs. |
Installation
Install from crates.io:
rustup toolchain install 1.88.0
cargo install agz-rust-mcp --locked
agz-rust-mcp --versionTo build from source, clone the repository from GitHub; the folder is named rust-mcp:
cd rust-mcp
cargo +1.88.0 build --release -p agz-rust-mcp --locked
./target/release/agz-rust-mcp --versionPrebuilt archives are available for Linux x86_64, macOS arm64 and Windows x86_64, and Linux x86_64 also has an install script. On other platforms, use an archive, cargo install or a source build.
Connecting a client
The repository has configuration examples for ZCode, OpenCode, OpenCode2 and Codex. The client starts the server as a local process. OpenCode example:
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"rust": {
"type": "local",
"command": ["agz-rust-mcp"],
"enabled": true,
"timeout": 120000
}
}
}Configuration
Settings are read in this order of precedence: command line, AGZ_RUST_MCP_* environment variables (section separator __, for example AGZ_RUST_MCP_GATE__HARD_TIMEOUT_MS=600000), a TOML file passed with --config, and defaults. Main keys: server.allow_roots, server.allow_dependency_roots, gate.scope (workspace, shadow, affected), gate.cache (auto, project, isolated), rust_analyzer.workspace_code and docs.fallback.
Processes are controlled with a process group on Unix and a Job Object on Windows, and are stopped on timeout. Default limits: gate.hard_timeout_ms 600000, repair.wall_time_ms 120000, work.wall_time_ms 600000; results are at most 49152 bytes.
Trust limits
- Cargo and rustc are the authority; Rust Analyzer and audit results are advisory.
- On a path escape or an unverifiable symlink the operation fails closed; client roots can narrow access but cannot widen it.
rust_analyzer.workspace_codedefaults todeny.
Skill packs
The repository includes four skill packs that work offline: agz-rust-workflow, agz-rust-repair, agz-rust-refactor and agz-rust-performance.
Contribute
How to contribute
Open an issue
Write the problem in the Issues section of the relevant repository. The version, your operating system and the steps that reproduce the problem are enough.
Report a vulnerability privately
Do not post security findings in public issues. The reporting route and scope are on the security page.