
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
MCP server that lets AI coding assistants search the icon packages actually installed in your project.
TrueIcon is an MCP server that gives AI coding assistants exact, version-correct icon references. Your assistant searches the icon packages your project actually uses (lucide-react, react-icons, @heroicons/react) and gets back real icon names, import paths and a ready-to-paste import line.
AI assistants often guess icon names. The guess can be an icon that never existed, one renamed a few releases ago, or one from a different library, and you only find out when the build fails. TrueIcon closes that gap:
search_icons and gets results that are guaranteed to exist in that version, for example import { Trash2 } from 'lucide-react';.| Provider id | npm package | Icon naming |
|---|---|---|
lucide | lucide-react | Lucide's file names, e.g. trash-2 → Trash2 |
heroicons | @heroicons/react | <icon>-<size>-<style>, e.g. trash-24-outline → TrashIcon |
react-icons | react-icons | <set>-<icon>, e.g. fa6-beer-mug-empty → FaBeerMugEmpty |
Tools accept either the provider id or the npm package name ("lucide" or "lucide-react"). Usage snippets are for React.
TrueIcon needs Node.js 20 or newer.
# Run without installing (this is what the MCP configs below do)
npx -y trueicon
# Or install globally and run the `trueicon` binary
npm i -g trueicon
trueicon
trueicon is a stdio MCP server. Your MCP client starts it; running it by hand only prints trueicon: v0.1.0 running on stdio to stderr and waits for JSON-RPC on stdin.
Add a .iconmcp.json to your project root that lists your icon packages:
{
"providers": [
{ "package": "lucide-react" },
{ "package": "@heroicons/react", "version": "2.1.5" }
]
}
Register TrueIcon with your MCP client (Claude Code or Claude Desktop).
Ask your assistant for an icon. The first search for each package downloads and indexes it, which takes a few seconds. Later searches use the local cache.
.iconmcp.jsonTrueIcon looks for .iconmcp.json in the project directory. That is $TRUEICON_PROJECT_DIR if set, otherwise the server's working directory.
{
"providers": [
{ "package": "lucide-react" },
{ "package": "react-icons", "version": "5.3.0" },
{ "package": "@heroicons/react", "version": "^2.1.0" }
]
}
| Field | Type | Required | Meaning |
|---|---|---|---|
providers | array | yes | Icon packages the project uses. search_icons searches all of them by default. |
providers[].package | string | yes | npm package name: lucide-react, react-icons or @heroicons/react. |
providers[].version | string | no | Exact version or npm range. If omitted, it is read from package.json (see below). |
search_icons then only works when you pass provider explicitly, and get_icon still works.search_icons reports them as a warning.| Variable | Default | Purpose |
|---|---|---|
TRUEICON_PROJECT_DIR | working directory | Project root holding .iconmcp.json and package.json |
TRUEICON_CACHE | ~/.trueicon/cache | Where downloaded packages and indexes are stored |
A provider's version is resolved in this order:
version argument passed to the tool call, if any.version in .iconmcp.json.package.json, checking dependencies first and then devDependencies.If none of these is available, the tool asks you to pin the version or add the package to package.json. TrueIcon reads the declared range from package.json. It does not read node_modules or the lockfile. For a range, it indexes the range's base version: ^0.460.0 indexes lucide-react@0.460.0. For a || b ranges, only the first part counts. To match an exact installed version, pin it in .iconmcp.json.
Indexes are keyed by major.minor:
0.460.x. The index built from 0.460.0 answers requests for 0.460.3.lucide-react from 0.460 to 0.461 builds a fresh index on the next search, with no manual step.synonyms.json changes (detected by hash) or the index format changes.Add TrueIcon from your project directory:
claude mcp add trueicon -- npx -y trueicon
Or commit a .mcp.json at the project root to share it with your team:
{
"mcpServers": {
"trueicon": {
"command": "npx",
"args": ["-y", "trueicon"]
}
}
}
Claude Code starts the server in your project directory, so it finds .iconmcp.json and package.json there. If it runs from somewhere else, add "env": { "TRUEICON_PROJECT_DIR": "/absolute/path/to/project" }.
Claude Desktop doesn't start servers in your project directory, so set TRUEICON_PROJECT_DIR. Edit claude_desktop_config.json: ~/Library/Application Support/Claude/claude_desktop_config.json on macOS, %APPDATA%\Claude\claude_desktop_config.json on Windows.
{
"mcpServers": {
"trueicon": {
"command": "npx",
"args": ["-y", "trueicon"],
"env": {
"TRUEICON_PROJECT_DIR": "/absolute/path/to/your/project"
}
}
}
}
Restart Claude Desktop after editing the file.
Every tool returns a single JSON text block. On failure, the block is {"error": "..."} and the MCP result is flagged with isError: true.
search_iconsSearches the index and returns ranked matches with import statements.
| Argument | Type | Required | Description |
|---|---|---|---|
query | string | yes | What the icon should depict, e.g. "trash" |
provider | string | no | Provider id or package. Default: every provider in .iconmcp.json |
version | string | no | Version or range. Default: resolved as described in Versions |
style | string | no | Exact style filter: "outline" or "solid" (lucide icons are all outline) |
set | string | no | Exact set filter, e.g. "fa6" or "md" for react-icons |
limit | integer | no | Maximum results, 1 to 50, default 10 |
Example call:
{ "query": "trash", "provider": "lucide", "limit": 3 }
Response:
{
"results": [
{ "name": "trash", "importName": "Trash", "importPath": "lucide-react", "package": "lucide-react",
"version": "0.460.0", "style": "outline", "set": "lucide",
"usage": "import { Trash } from 'lucide-react';", "score": 2.0e-14 },
{ "name": "trash-2", "importName": "Trash2", "importPath": "lucide-react", "package": "lucide-react",
"version": "0.460.0", "style": "outline", "set": "lucide",
"usage": "import { Trash2 } from 'lucide-react';", "score": 1.6e-6 },
{ "name": "delete", "importName": "Delete", "importPath": "lucide-react", "package": "lucide-react",
"version": "0.460.0", "style": "outline", "set": "lucide",
"usage": "import { Delete } from 'lucide-react';", "score": 1.2e-4 }
]
}
How search works:
provider, style and set are exact, case-insensitive filters. They are applied before ranking."detele" finds Delete.score runs from 0 (perfect) to 1, so lower is better. Results from several providers are merged and sorted by score."trash", "settings", "beer") work best. The query is matched as one string, so a multi-word phrase such as "trash can" may return fewer results than its main keyword alone.warnings array explains why. The other providers still return results.list_providersTakes no arguments. Returns the providers configured in .iconmcp.json with their resolved versions, plus every provider TrueIcon supports.
{
"configured": [
{ "id": "lucide", "package": "lucide-react", "version": "^0.460.0", "source": "package.json" },
{ "id": "heroicons", "package": "@heroicons/react", "version": "2.1.5", "source": "iconmcp.json" }
],
"registry": [
{ "id": "react-icons", "package": "react-icons", "description": "Aggregated icon sets (Font Awesome, Material, Feather, and more) as React components" },
{ "id": "lucide", "package": "lucide-react", "description": "Lucide icons as React components" },
{ "id": "heroicons", "package": "@heroicons/react", "description": "Heroicons by the Tailwind CSS team as React components" }
]
}
source is "iconmcp.json" or "package.json". version and source are null when neither file provides a version. id is null for a configured package TrueIcon doesn't support.
get_iconGets the full record and import statement for an icon whose name the assistant already knows.
| Argument | Type | Required | Description |
|---|---|---|---|
name | string | yes | Icon name ("trash-2") or import name ("Trash2"). Exact match first, then case-insensitive |
provider | string | yes | Provider id or package |
version | string | no | Version or range. Default: resolved as described in Versions |
Example call:
{ "name": "Trash2", "provider": "lucide" }
Response:
{
"id": "lucide-react@0.460:trash-2",
"name": "trash-2",
"importName": "Trash2",
"importPath": "lucide-react",
"provider": "lucide",
"package": "lucide-react",
"version": "0.460.0",
"style": "outline",
"set": "lucide",
"categories": [],
"tags": [],
"keywords": ["trash", "2", "delete", "remove", "bin", "garbage", "rubbish"],
"svg": "<path d=\"M3 6h18\"/><path d=\"M19 6v14c0 1-1 2-2 2H7c-1 0-2-1-2-2V6\"/>…",
"usage": "import { Trash2 } from 'lucide-react';"
}
svg is the icon's inner SVG markup, meaning the children of the root <svg> element. Heroicons uses the same import name in every size and style (TrashIcon). Pass the full variant name, such as "trash-24-outline", to get a specific one.
pingA health check that returns {"status":"ok","server":"trueicon"}.
The first time a tool needs package@major.minor, TrueIcon does the following:
https://registry.npmjs.org, verifies its sha512 integrity, and extracts it into the cache.index.json (one record per icon) and meta.json (exact version, synonyms hash, index format, build time).Later calls only read index.json. Package files are never touched at query time, and your node_modules is never read or modified. If several tool calls need the same index at once, they share one download.
The cache root is ~/.trueicon/cache, or $TRUEICON_CACHE if set:
~/.trueicon/cache/
├── lucide-react@0.460/ # extracted package + index.json + meta.json
├── react-icons@5.3/ # extracted package + index.json + meta.json
├── heroicons-react@2.1/ # extracted @heroicons/react package
└── @heroicons/react@2.1/ # index.json + meta.json for @heroicons/react
<package>@<major.minor>, where scoped names are flattened: @heroicons/react becomes heroicons-react. A .download-complete marker is written last, and a directory without it is treated as partial and replaced.<package>@<major.minor>/index.json and meta.json. For unscoped packages this is the same directory as the download.Each record's keywords combine the name parts, the tags, and synonym expansions from the bundled synonyms.json. The expansions are added at index time, so "bin" finds Trash2 without any extra work at query time.
git clone https://github.com/manikumarkv/trueicon.git
cd trueicon
npm ci
npm run build # compile to dist/
npm test # vitest
npm run lint # eslint
npm run typecheck # tsc --noEmit
CI runs lint, typecheck and tests on Node 20 and 22 for every push and pull request.
synonyms.jsonsrc/synonyms/synonyms.json maps a term to extra search terms:
{
"trash": ["delete", "remove", "bin", "garbage", "rubbish"],
"logout": ["sign-out", "signout", "exit", "leave"]
}
-) and its tags. trash-2 matches the key trash.keywords.bin should also find icons named delete, add both "trash": ["bin"] and "delete": ["bin"], or add a reverse entry.tests/synonyms.test.ts checks this.src/providers/registry.ts with a stable id, the npm package and a short description.src/providers/adapters/<provider>.ts that exports parseIcons(packageDir: string): RawIcon[] (see src/providers/adapter.ts). It gets the extracted package directory and returns one RawIcon per icon:
name: kebab-case and unique within the package, because it becomes part of the record id. Use toKebabCase from adapter.ts. If the package has variants with clashing component names, add the variant to the name, as the heroicons and react-icons adapters do.importName and importPath: the exact export and module specifier a user would import.svg: the inner SVG markup. LiteralCursor (src/providers/jsLiteral.ts) parses JS object and array literals without executing code. toSvgAttrs and renderSvg (src/providers/svg.ts) turn React props into SVG markup.style, set, categories and tags.src/providers/adapters/index.ts by adding it to ADAPTERS under the provider id.tests/fixtures/<provider>/ that mirrors the package layout, with a few real icon files plus any files the adapter must skip. Then add tests/adapters/<provider>.test.ts, covering name mapping, import paths, SVG output and buildIndex record ids like the existing adapter tests. tests/adapters/common.test.ts fails if a registered provider has no adapter.MIT © 2026 manikumarkv
FAQs
MCP server that lets AI coding assistants search the icon packages actually installed in your project.
The npm package trueicon receives a total of 1,136 weekly downloads. As such, trueicon popularity was classified as popular.
We found that trueicon demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.