
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@perfonext/build-mcp
Advanced tools
MCP server for analyzing Next.js build artifacts, route bundle footprint, and shared chunks
Analyze Next.js build artifacts to find heavy routes, shared chunks, and bundle growth.
perfonext-build-mcp is a Model Context Protocol (MCP) server that gives GitHub Copilot, Claude Desktop,
Claude Code, and other MCP clients structured bundle analysis for Next.js performance work. It loads .next
build artifacts and turns them into route-size rankings, shared-chunk and duplication findings, and
severity-ranked fix suggestions — evidence agents can reason over instead of inspecting raw .next manifests.
Run directly with npx:
npx -y @perfonext/build-mcp
Or install globally:
npm install -g @perfonext/build-mcp
The executable command remains perfonext-build-mcp after installation.
Add the server to VS Code in .vscode/mcp.json (the workspace MCP configuration file):
{
"servers": {
"perfonext-build": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@perfonext/build-mcp"]
}
}
}
Then reload the VS Code window and run MCP: List Servers to start it, or accept the trust prompt when it appears. For a locally-built checkout, point command/args at node and the repo's dist/index.js instead.
Then ask Copilot: "Load the Next.js build in ./.next and show me the largest routes."
.next directory| Tool | Description |
|---|---|
load_build_stats | Parse a Next.js .next directory and load the build snapshot into memory |
get_largest_routes | Rank the heaviest user-facing routes by total emitted chunk bytes |
get_shared_chunks | Rank shared chunks by size and show which routes depend on them |
compare_builds | Compare a baseline and current build snapshot to show which routes and chunks grew or shrank |
explain_growth | Severity-rank which routes and chunks drove bundle growth between two builds, with evidence-backed fix suggestions |
how_to_collect_stats | Return the recipe (manual) or an action plan (automatic) to generate .next/stats.json |
load_webpack_stats | Parse .next/stats.json and link it to a loaded build; required before trace_import |
trace_import | Explain why a module or npm package is bundled by walking its import chain to the entry |
find_duplicates | Rank npm packages whose code is emitted into more than one chunk, by wasted bytes |
explain_shared_chunks | Show which packages and app code dominate the shared chunks loaded by many routes |
suggest_optimizations | Aggregate route, chunk, and webpack-stats evidence into severity-ranked, evidence-backed fix suggestions |
The output stays machine-readable and includes raw byte counts so Copilot can explain regressions, prioritise fixes, and suggest concrete dependency or import-level follow-up.
Because Next.js content-hashes emitted filenames (framework-<hash>.js, and CSS files named purely by hash), compare_builds and explain_growth match chunks across builds by a hash-normalized identity. This prevents a rehashed-but-unchanged chunk from being misreported as removed-and-recreated, while still flagging genuinely new chunks.
The core tools read build artifacts developers already have after running next build:
.next/build-manifest.json.next/prerender-manifest.json when present.next/app-build-manifest.json when presentnext build output text to derive build durationImport-level attribution (trace_import, find_duplicates, explain_shared_chunks) and the
stats-enriched suggestions from suggest_optimizations additionally need a webpack module-stats file
at .next/stats.json. A stock next build does not emit one; how_to_collect_stats returns the
recipe to generate it. The manifest tools above never read it, so they work with or without it.
The manifest tools work with zero setup. To answer "why is this package bundled?", collect a webpack stats file first:
how_to_collect_stats({ method: 'manual' | 'automatic' }) and apply the returned steps — it
adds webpack-stats-plugin, gates a next.config hook behind ANALYZE=true && !isServer, and rebuilds.load_build_stats({ buildDir }) to get a buildId.load_webpack_stats({ buildId }) to parse the generated .next/stats.json.trace_import({ buildId, moduleName }) to see the import chain that pulls a module in.find_duplicates({ buildId }) to find packages bundled into more than one chunk, and
explain_shared_chunks({ buildId }) to see what dominates the chunks loaded by many routes.suggest_optimizations({ buildId }) for severity-ranked, evidence-backed recommendations.
It works on manifests alone and is enriched with dedupe, shared-chunk, and package-import
findings once stats are loaded. Code-split advice is tailored for Next.js framework routes
(/404, /500, /_error, /_app, /_document) — these are flagged to be slimmed down by
trimming imports rather than split with next/dynamic, which does not apply to them.If the app builds with Turbopack there is no webpack module graph, so how_to_collect_stats says so
and points back to the manifest-only tools. The attribution tools degrade gracefully with a
breadcrumb when no stats file is loaded — it is never an error.
./.next and show me the largest routes.".next builds and show me which routes or shared chunks grew the most.".next builds and what I should fix first."axios in my bundle? Trace its import chain."npm install
npm run build
npm test
Sample fixtures for local validation live under tests/fixtures/.
MIT
FAQs
MCP server for analyzing Next.js build artifacts, route bundle footprint, and shared chunks
The npm package @perfonext/build-mcp receives a total of 65 weekly downloads. As such, @perfonext/build-mcp popularity was classified as not popular.
We found that @perfonext/build-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.