# flutter-lamp

Flutter Lamp — an MCP server giving AI live eyes on a running Flutter app over the Dart VM Service: exceptions, logs, network, frames, memory + root-cause diagnosis.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.21.0
- **Author:** Chandrabhushan Prakash
- **License:** MIT
- **npm:** flutter-lamp
- **Source:** https://github.com/itsonu/flutter-lamp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 1 day

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-02T01:39:43.460Z
- **Version scanned:** 0.21.0
- **CVEs:** none found by OSV at scan time

## Tools

22 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `connect_vm`
- `ensure_tcp_device`
- `runtime_status` — Report connection health, the current debugging session, reconnection state, how many runtime events have been captured by category, and the retention window (p
- `get_dashboard_url` — Return the URL of the live Realtime Runtime Dashboard (a browser UI streaming logs, network, exceptions, frames & memory). Open it in a browser to watch the app
- `get_logs` — Console output (Stdout/Stderr) and dart:developer logging, most recent first.
- `get_exceptions` — Flutter framework errors and unhandled VM exceptions, most recent first. Each includes the error summary, offending widget, library, and a reconstructed stack t
- `get_frames` — Frame build/raster timings. Set onlyJanky to focus on frames over the frame budget —
- `get_network` — HTTP requests/responses captured via dart:io profiling (covers Dio & package:http). Fetches the latest profile on demand, then returns completed requests most r
- `diagnose_runtime` — Correlate captured runtime evidence into a root-cause diagnosis. Returns status (diagnosed|unknown), summary, rootCause, evidence (each with a citable eventId),
- `diagnose_performance`
- `get_widget_tree` — Snapshot of the running app's widget tree (summary tree from the Flutter Inspector). Use to understand structure, find a widget, or see what is mounted.
- `get_selected_widget` — The widget currently selected in the Flutter Inspector (via 'select widget mode' in the app/DevTools). Returns null if nothing is selected.
- `get_memory` — Current Dart heap usage for the main isolate (Dart heap in use, capacity, and external/native memory), in MB. Also records a snapshot into runtime history.
- `get_timeline` — Recent VM timeline trace events (build/paint/layout/GC/etc.), most recent first. Requires timeline recording — enable with recordFrom=true (sets Dart, GC, Compi
- `runtime_health` — One compact answer to 'is this app healthy right now'. Returns a verdict (healthy/degraded/failing/no-data) plus exception, network, frame, log and memory summa
- `what_changed`
- `get_navigation` — The current route and recent route transitions, each with how long it was on screen and the exceptions, failed requests and janky frames attributed to it. Use t
- `get_rebuilds` — Which widgets are rebuilding and how often, resolved to widget name, file and line, with your own code ranked above package code. Use for 'why is this screen sl
- `get_state_activity`
- `explain_diagnosis` — Why diagnose_runtime reached its conclusion: the claim, every cited event resolved back to its full record, the timeline around the root cause, competing explan
- `export_session`
- `get_capabilities` — Machine-readable capability report: active collectors, every tool with its safety class, what can and cannot be observed on this target, and the current redacti

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"flutter-lamp\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"flutter-lamp\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 13, ceiling 31 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/flutter-lamp
- Install plan: https://forgeregistry.com/api/v1/packages/flutter-lamp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/flutter-lamp
- HTML page: https://forgeregistry.com/registry/flutter-lamp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
