Atlas / MCP servers / aimasteracc / Tree-sitter Analyzer

Tree-sitter AnalyzerBLOCK

mcp/aimasteracc/tree-sitter-analyzer

Cross-language-safe code-intelligence MCP for AI agents: 13 languages, family-gated call graph, blast radius, health grading, 8 facade tools, JSON envelopes, 100% local. Run miswire-audit on your repo.

Verdict
BLOCK
Grade
F
Trust score
52 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
MIT
Stars
54
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 日本語 | 简体中文

[](https://pypi.org/project/tree-sitter-analyzer/) [](https://python.org) [](LICENSE) [](https://codecov.io/gh/aimasteracc/tree-sitter-analyzer) [](https://github.com/aimasteracc/tree-sitter-analyzer) [](#supported-agents)

Code intelligence AI agents can trust — correct cross-language structure across the supported language inventory, agent-native (MCP + CLI).

TSA indexes your codebase with tree-sitter and serves correct call graphs, symbol search, and structural queries to AI coding agents — locally, with no telemetry.

Why it's different:

  • Cross-language bindings are gated by language family. A name match alone does not create a cross-language edge, and the gates that enforce this are executable tests rather than a convention.
  • Built agent-native. 8 MCP tools provide structured JSON output and verdict envelopes, with CLI access and curated workflows.
  • Broad and correctly classified. The generated support-depth inventory distinguishes pipeline evidence from unverified cross-file behavior.
Upgrading from v1.x? See docs/MIGRATION.md.

Get Started

Requires Python 3.10+ (check: python3 --version). Install from python.org if needed.

Automated install (recommended)

curl -fsSL https://raw.githubusercontent.com/
Read from source at commit 03d473f20a6dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add tree-sitter-analyzer -- None tree-sitter-analyzer==2.2.0
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_code_scalereadAnalyze code scale, complexity, and structure metrics with CLI-compatible output format
subscriberead测试订阅入口
unsubscriberead测试退订入口
04

Trust audit

BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (6 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tree_sitter_analyzer/mcp/tools/security_scanner.py:118
"pickle.loads() — arbitrary code execution risk",
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/extract_node_counts.py:52
ts_module = __import__(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/generate_corpus_expected.py:106
ts_module = __import__(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/generate_expected_counts.py:194
ts_module = __import__(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/generate_facade_actions_doc.py:292
tool_cls = getattr(importlib.import_module(module_name), class_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/measure_self_health_baseline.py:118
module = importlib.import_module(f"tree_sitter_analyzer.mcp.tools.{module_name}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tree_sitter_analyzer/mcp/tools/codegraph_query_tool.py:513
logger.debug("codegraph_query resolve(%r) failed: %s", token, exc)
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-hooks.yaml
.pre-commit-hooks.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.secrets.baseline
.secrets.baseline
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/unit/api/test_pulse.py:64
restored = pickle.loads(pickle.dumps(value))
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/unit/formatters/test_formatter_registry.py:528
assert type(pickle.loads(pickle.dumps(JsonFormatter()))) is JsonFormatter
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/unit/mcp/test_security_scanner.py:97
"data = pickle.loads(payload)\n"
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/contracts/test_outdated_uv_qualification.py:653
exec(textwrap.dedent(code), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/integration/_test_phase7_security_scenarios.py:45
"eval(base64_decode('bWFsaWNpb3VzX2NvZGU='))",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/unit/formatters/test_javascript_formatter_robustness.py:144
("new Function()", "function"),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/unit/languages/test_kotlin_plugin.py:25
exec(  # noqa: S102 - exact import-surface compatibility regression
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/unit/languages/test_python_plugin.py:802
plugin._get_node_type_for_element(Function("f", 1, 1, "def f(): pass"))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/format_change_management.py:512
spec_hash = hashlib.md5(
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/format_monitoring_tool.py:377
output_hash = hashlib.md5(output.encode("utf-8")).hexdigest()  # nosec
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/integration/formatters/test_data_manager.py:220
source_hash = hashlib.md5(source_code.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/unit/no1_010b/test_patch.py:76
oid = hashlib.sha1(header + inflated, usedforsecurity=False).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/unit/no1_010b/test_patch.py:244
valid_oid = hashlib.sha1(
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/unit/mcp/tools/test_build_project_index_security.py:59
ssh_path = os.path.expanduser("~/.ssh")
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/unit/mcp/utils/test_error_sanitizer.py:196
raise OSError("could not read /Users/private/.ssh/id_rsa")
Why it matters. touches a credential store

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 03d473f20a6dfull audit observations/trust-audit/mcp-server/aimasteracc__tree-sitter-analyzer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0803d473f20a6dBLOCKF52first audit
06

Questions

What is the Tree-sitter Analyzer MCP server?

Cross-language-safe code-intelligence MCP for AI agents: 13 languages, family-gated call graph, blast radius, health grading, 8 facade tools, JSON envelopes, 100% local. Run miswire-audit on your repo.

What tools does Tree-sitter Analyzer expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Tree-sitter Analyzer safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (52/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Tree-sitter Analyzer need?

It reads GIT_CONFIG_KEY_0, PYPI_API_TOKEN, RFC0022_AUTHORITY_ARTIFACT_DIR, RFC0022_AUTHORITY_CASE_DIR and UV_PUBLISH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Tree-sitter Analyzer run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as health-project-fixture.

How current is this page?

The grade is for one exact copy of the source (03d473f20a6d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement