Tree-sitter AnalyzerBLOCK
Cross-language-safe code-intelligence MCP for AI agents: 13 languages, family-gated call graph, blast radius, health grading, 8 facade tools, JSON envelopes, 100% local. Run miswire-audit on your repo.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 日本語 | 简体中文
[](https://pypi.org/project/tree-sitter-analyzer/) [](https://python.org) [](LICENSE) [](https://codecov.io/gh/aimasteracc/tree-sitter-analyzer) [](https://github.com/aimasteracc/tree-sitter-analyzer) [](#supported-agents)
Code intelligence AI agents can trust — correct cross-language structure across the supported language inventory, agent-native (MCP + CLI).
TSA indexes your codebase with tree-sitter and serves correct call graphs, symbol search, and structural queries to AI coding agents — locally, with no telemetry.
Why it's different:
- Cross-language bindings are gated by language family. A name match alone does not create a cross-language edge, and the gates that enforce this are executable tests rather than a convention.
- Built agent-native. 8 MCP tools provide structured JSON output and verdict envelopes, with CLI access and curated workflows.
- Broad and correctly classified. The generated support-depth inventory distinguishes pipeline evidence from unverified cross-file behavior.
Upgrading from v1.x? See docs/MIGRATION.md.
Get Started
Requires Python 3.10+ (check: python3 --version). Install from python.org if needed.Automated install (recommended)
curl -fsSL https://raw.githubusercontent.com/
03d473f20a6dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add tree-sitter-analyzer -- None tree-sitter-analyzer==2.2.0
Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_code_scale | read | Analyze code scale, complexity, and structure metrics with CLI-compatible output format |
subscribe | read | 测试订阅入口 |
unsubscribe | read | 测试退订入口 |
Trust audit
BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (25)
"pickle.loads() — arbitrary code execution risk",
ts_module = __import__(module_name)
ts_module = __import__(module_name)
ts_module = __import__(module_name)
tool_cls = getattr(importlib.import_module(module_name), class_name)
module = importlib.import_module(f"tree_sitter_analyzer.mcp.tools.{module_name}")logger.debug("codegraph_query resolve(%r) failed: %s", token, exc).pre-commit-config.yaml
.pre-commit-hooks.yaml
.secrets.baseline
restored = pickle.loads(pickle.dumps(value))
assert type(pickle.loads(pickle.dumps(JsonFormatter()))) is JsonFormatter
"data = pickle.loads(payload)\n"
exec(textwrap.dedent(code), namespace)
"eval(base64_decode('bWFsaWNpb3VzX2NvZGU='))",("new Function()", "function"),exec( # noqa: S102 - exact import-surface compatibility regression
plugin._get_node_type_for_element(Function("f", 1, 1, "def f(): pass"))spec_hash = hashlib.md5(
output_hash = hashlib.md5(output.encode("utf-8")).hexdigest() # nosecsource_hash = hashlib.md5(source_code.encode()).hexdigest()
oid = hashlib.sha1(header + inflated, usedforsecurity=False).hexdigest()
valid_oid = hashlib.sha1(
ssh_path = os.path.expanduser("~/.ssh")raise OSError("could not read /Users/private/.ssh/id_rsa")Gates applied: no_behavioural_pass.
03d473f20a6dfull audit observations/trust-audit/mcp-server/aimasteracc__tree-sitter-analyzer.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 03d473f20a6d | BLOCK | F | 52 | first audit |
Questions
What is the Tree-sitter Analyzer MCP server?
Cross-language-safe code-intelligence MCP for AI agents: 13 languages, family-gated call graph, blast radius, health grading, 8 facade tools, JSON envelopes, 100% local. Run miswire-audit on your repo.
What tools does Tree-sitter Analyzer expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Tree-sitter Analyzer safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (52/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Tree-sitter Analyzer need?
It reads GIT_CONFIG_KEY_0, PYPI_API_TOKEN, RFC0022_AUTHORITY_ARTIFACT_DIR, RFC0022_AUTHORITY_CASE_DIR and UV_PUBLISH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Tree-sitter Analyzer run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as health-project-fixture.
How current is this page?
The grade is for one exact copy of the source (03d473f20a6d), read on 2026-10-08. The repository is watched and re-audited when it changes.