Atlas / MCP servers / ali-kamali / Axon

AxonBLOCK

mcp/ali-kamali/axon

Transform your codebase into an intelligent knowledge base for AI-powered development with Cursor IDE, Google AntiGravity, and MCP-enabled assistants

Verdict
BLOCK
Grade
F
Trust score
43 /100
Exposed tools
22 22r · 0w · 0d
Transport
stdio
License
NOASSERTION
Stars
166
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Model Context Protocol (MCP) Server for AI IDEs - Cursor, AntiGravity & Claude

Transform your codebase into an intelligent knowledge base for AI-powered development with Cursor IDE, Google AntiGravity, and MCP-enabled assistants

[](https://www.python.org/downloads/) [](LICENSE) [](#-license--commercial-use) [](https://github.com/ali-kamali/Axon.MCP.Server/actions/workflows/ci.yml) [](https://github.com/ali-kamali/Axon.MCP.Server/pkgs/container/axon-mcp-server) []() [](https://modelcontextprotocol.io) [](https://ali-kamali.github.io/Axon.MCP.Server/) []()

📋 Table of Contents

  • The Problem
  • The Solution
  • See It In Action
  • Architecture Overview
  • MCP Tools for AI Assistants
  • Key Features
  • Quick Start
  • Use Cases
  • Documentation
  • Development
  • Roadmap
  • Contributing
  • License

🎯 The Problem

Modern codebases are

Read from source at commit 25e4c8ac4e42OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add axon-mcp-ui --env AZUREDEVOPS_SSH_KEY_PATH=${AZUREDEVOPS_SSH_KEY_PATH} --env GITLAB_SSH_KEY_PATH=${GITLAB_SSH_KEY_PATH} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "axon-mcp-ui": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AZUREDEVOPS_SSH_KEY_PATH": "${AZUREDEVOPS_SSH_KEY_PATH}",
        "GITLAB_SSH_KEY_PATH": "${GITLAB_SSH_KEY_PATH}"
      }
    }
  }
}
03

Exposed tools (22)

22 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_architecturereadAnalyze architecture
find_api_endpointsreadFind API endpoints
find_calleesreadFind callees
find_callersreadFind callers
find_implementationsreadFind interface implementations
find_referencesreadFind all references
find_usagesreadFind symbol usages
get_call_hierarchyreadGet call hierarchy
get_file_contentreadRead file content
get_file_treereadGet directory tree
get_module_summaryreadGet module summary
get_project_mapreadGet project map
get_symbol_contextreadGet detailed context for a specific symbol
list_dependenciesreadList package dependencies
list_repositoriesreadList available repositories
list_symbols_in_filereadList symbols in file
query_codebase_structurereadQuery codebase structure
search_by_pathreadSearch files by path
search_codereadSearch for code symbols across repositories
search_configurationreadSearch configuration settings
search_documentationreadSearch markdown documentation files
trace_request_flowreadTrace request flow
04

Trust audit

BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (12 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/security.py:234
(r'-----BEGIN PRIVATE KEY-----', 'private_key'),
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/utils/security.py:235
(r'-----BEGIN RSA PRIVATE KEY-----', 'rsa_key'),
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/azuredevops/repository_manager.py:47
credentials_file = Path.home() / ".git-credentials"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/azuredevops/repository_manager.py:261
ssh_key_path = os.getenv("AZUREDEVOPS_SSH_KEY_PATH", str(Path.home() / ".ssh" / "id_rsa"))
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/gitlab/repository_manager.py:97
ssh_key_path = os.getenv("GITLAB_SSH_KEY_PATH", str(Path.home() / ".ssh" / "id_rsa"))
Why it matters. touches a credential store
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/azuredevops/repository_manager.py:278
config_options.extend(["-c", f"http.https://{parsed_url.netloc}/.sslVerify=false"])
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:44
DATABASE_URL=postgresql://axon:password@localhost:5432/axon_mcp  # (REQUIRED)
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:45
# Note: When running via Docker Compose, use: postgresql://axon:password@postgres:5432/axon_mcp
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
alembic.ini:4
sqlalchemy.url = postgresql://axon:axon_dev_password@localhost:5432/axon_mcp
MEDIUMInventory / provenance · inv.binary · CWE-1104
roslyn_analyzer/bin/Release/net9.0/Newtonsoft.Json.dll
Newtonsoft.Json.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
roslyn_analyzer/bin/Release/net9.0/RoslynAnalyzer.dll
RoslynAnalyzer.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
roslyn_analyzer/bin/Release/net9.0/RoslynAnalyzer.exe
RoslynAnalyzer.exe
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
roslyn_analyzer/bin/Release/net9.0/RoslynAnalyzer.pdb
RoslynAnalyzer.pdb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
roslyn_analyzer/bin/Release/net9.0/cs/Microsoft.CodeAnalysis.CSharp.resources.dll
Microsoft.CodeAnalysis.CSharp.resources.dll
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/api/auth.py:89
logger.warning("invalid_api_key_attempt", key_prefix=api_key[:8] if len(api_key) > 8 else "too_short")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:125
API_CORS_ORIGINS=["http://localhost:3000","http://127.0.0.1:3000"]  # Explicit browser origins (JSON array)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
docker/docker-compose.yml:243
- VITE_API_BASE_URL=http://10.30.81.101/
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/config/settings.py:131
api_cors_origins: list[str] = ["http://localhost:3000", "http://127.0.0.1:3000"]
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/config/settings.py:190
"http://127.0.0.1:3000",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
ACCESS_URLS.md:125
postgresql://axon:password@localhost:5432/axon_mcp
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
roslyn_analyzer/obj/Release/net9.0/.NETCoreApp,Version=v9.0.AssemblyAttributes.cs
.NETCoreApp,Version=v9.0.AssemblyAttributes.cs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
ui/.eslintrc.cjs
.eslintrc.cjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/api/services/search_service.py:432
key_hash = hashlib.md5(key_str.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/utils/redis_cache.py:173
key_hash = hashlib.md5(key.encode()).hexdigest()

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 25e4c8ac4e42full audit observations/trust-audit/mcp-server/ali-kamali__axon.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0625e4c8ac4e42BLOCKF43first audit
06

Questions

What is the Axon MCP server?

Transform your codebase into an intelligent knowledge base for AI-powered development with Cursor IDE, Google AntiGravity, and MCP-enabled assistants

What tools does Axon expose?

22 in total: 22 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Axon safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (43/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Axon need?

It reads AZUREDEVOPS_SSH_KEY_PATH and GITLAB_SSH_KEY_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Axon run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as axon-mcp-ui at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (25e4c8ac4e42), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement