AI coding assistants can calculate a hash, decode a JWT, format JSON, or generate a UUID. The problem is not that these operations are difficult. The problem is making the assistant use a defined tool with visible boundaries instead of guessing, switching to an unreviewed web service, or producing a plausible but incorrect result.
DevUtils MCP packages a local Model Context Protocol server for Cursor and Claude Code. The plugin currently declares version 1.0.7 and starts devutils-mcp-server through npx. The related server exposes 36 utilities for hashing, encoding, UUIDs, JWTs, JSON, network calculations, and text processing.
This tutorial installs the plugin, shows the equivalent configuration, and verifies the important security boundary: the utility call runs in a local process, while the first npx launch may download the package from npm.
TL;DR
Install DevUtils MCP from Cursor Settings or add the repository as a Claude Code plugin. If you need a manual MCP configuration, use the documented npx -y devutils-mcp-server command. Then ask your assistant to generate a UUID or validate JSON and confirm that the tool appears in the client's MCP list.
Prerequisites
You need:
- Cursor with MCP support, or Claude Code with plugin support.
- Node.js 18 or newer. The server package declares
engines.nodeas>=18. - Permission to run
npxand download a public npm package the first time the server starts.
The plugin and server are MIT-licensed. The plugin repository is public and non-archived, and its manifest identifies Fernando Paladini as the author.
Install the plugin
Cursor
Open Cursor Settings, choose Customize, search for DevUtils MCP, and select Install. The repository also documents the alternative Add from GitHub path with paladini/devutils-cursor-plugin.
After installation, enable the devutils MCP server under Customize > MCPs. The plugin is a distribution wrapper: its manifest describes the plugin, while mcp.json tells the client which local command to start.
Claude Code
Run the two commands documented by the repository:
/plugin marketplace add paladini/devutils-cursor-plugin
/plugin install devutils-mcp@devutils-cursor-plugin
The plugin repository is responsible for installation and documentation. The MCP server repository remains the place for the utility implementation and tool behavior.
Any MCP client
If your client supports a manually configured stdio MCP server, use this configuration from the repository's current mcp.json:
{
"mcpServers": {
"devutils": {
"command": "npx",
"args": ["-y", "devutils-mcp-server"]
}
}
}
The -y flag lets npx proceed without an interactive install confirmation. For a reproducible release-oriented setup, pin the package explicitly instead:
npx -y devutils-mcp-server@1.1.0
The unpinned command is the repository's current example. The pinned command targets the server's stable GitHub release v1.1.0, which is also the current npm version checked for this tutorial.
Try a useful tool call
Once the server is enabled, ask the assistant for a small operation with an inspectable result:
Use DevUtils to generate one UUID v4. Return only the UUID and the tool name.
The server README lists generate_uuid among its generator tools. You can also try:
Use DevUtils to validate this JSON and explain the error location:
{"name":"Ada","skills":["typescript",]}
Or ask for a deterministic transformation:
Use DevUtils to calculate the network, broadcast address, and host count for 10.0.0.0/24.
These prompts are deliberately narrow. They give you an easy way to distinguish an MCP tool result from an answer generated from the model's general knowledge.
Verify the local transport
You can verify that the pinned server starts and speaks MCP over standard input and output without opening Cursor. Send an MCP initialize request to the command:
printf '%s\n' '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"smoke-test","version":"1.0"}}}' | npx -y devutils-mcp-server@1.1.0
A successful response includes serverInfo.name set to devutils-mcp-server, serverInfo.version set to 1.1.0, and a tools capability. The server writes a short startup message to stderr and returns the JSON-RPC response on stdout. That separation matters when an MCP client parses stdout as protocol messages.
For a client-level check, open the MCP tools panel and confirm that devutils is enabled. Then run one UUID or JSON validation request and save the returned value in your terminal or test notes. Repeating the same request should let you compare the tool output with a native library or a known test vector.
Why the wrapper is useful
The plugin solves distribution rather than inventing a second utility implementation. Cursor and Claude Code users can install one named integration, while other MCP clients can use the same server configuration. The underlying server uses consistent names such as hash_sha256, json_validate, jwt_decode, and cidr_calculate, so an assistant can select a narrow operation instead of improvising a multi-step shell command.
The project README lists 36 tools in eight groups: hash, encoding, generators, JWT, formatters, converters, network, and text. The server uses stdio transport and the package metadata identifies TypeScript, Node.js, the MCP SDK, bcryptjs, nanoid, and zod as its implementation stack.
Failure modes and limitations
If the plugin does not appear, check that you installed the repository named paladini/devutils-cursor-plugin, then restart or reload the client. If the server does not start, verify node -v, run the pinned npx command directly, and inspect stderr for npm or permission errors.
The plugin does not make an MCP-incompatible client compatible. It also does not replace native libraries in application code. The server README explicitly recommends native libraries when you are writing regular programs or need extreme performance. MCP adds process and model-tool overhead in exchange for a stable tool contract that an assistant can call.
The current plugin repository has no GitHub release object even though its manifest declares version 1.0.7. Treat that manifest version as the documented plugin version, not as proof of a tagged plugin release. The related server does have stable release v1.1.0. Keep those two version surfaces separate when reporting an installation.
Security and privacy boundaries
The plugin privacy policy says that tool inputs are processed locally by the MCP server and that the author does not operate a cloud service or receive telemetry from the plugin. That is a useful boundary, but it is not a blanket security guarantee.
The first npx invocation can contact npm to download devutils-mcp-server. Review the package source, lock down the version when your workflow requires it, and use your organization's npm controls if package downloads are restricted. Also remember that your AI client still receives the prompt and may decide which tool to call. Do not paste secrets into an assistant conversation merely because the utility itself runs locally.
JWT decoding is not signature verification, and hashing is not encryption. A local tool can reduce accidental guessing, but it does not make sensitive data safe to disclose or prove that a token is trusted.
FAQ
Does the plugin send input to Fernando Paladini?
The published privacy policy says no. The tool process runs locally, while npm may be contacted to download the package on first use.
Do I need Cursor to use the server?
No. The server is intended for any MCP-compatible client. Cursor and Claude Code are the convenient plugin paths.
Should I use the plugin or manual configuration?
Use the plugin when your client supports it and you want a guided install. Use manual configuration when you need explicit control over the command and version.
Is this a replacement for application code?
No. It is an assistant-facing utility layer. Use a native library when your application needs direct calls, tests, or high throughput.
Takeaway
DevUtils MCP gives Cursor and Claude Code a small, local toolbox with a reviewable installation path. Start with the plugin, verify one narrow tool call, and pin devutils-mcp-server@1.1.0 when release reproducibility matters. The useful habit is to keep the client integration, package download, local process, and sensitive input boundaries visible.
What is the first repetitive developer utility you would rather delegate to a validated local MCP tool than ask an AI assistant to recreate?
AI assistance disclosure: This tutorial was researched and drafted with AI assistance. Repository files, package metadata, the stable server release, and the MCP initialize example were checked against primary sources before publication.
Top comments (0)