AxonBLOCK
Transform your codebase into an intelligent knowledge base for AI-powered development with Cursor IDE, Google AntiGravity, and MCP-enabled assistants
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Model Context Protocol (MCP) Server for AI IDEs - Cursor, AntiGravity & Claude
Transform your codebase into an intelligent knowledge base for AI-powered development with Cursor IDE, Google AntiGravity, and MCP-enabled assistants
[](https://www.python.org/downloads/) [](LICENSE) [](#-license--commercial-use) [](https://github.com/ali-kamali/Axon.MCP.Server/actions/workflows/ci.yml) [](https://github.com/ali-kamali/Axon.MCP.Server/pkgs/container/axon-mcp-server) []() [](https://modelcontextprotocol.io) [](https://ali-kamali.github.io/Axon.MCP.Server/) []()
📋 Table of Contents
- The Problem
- The Solution
- See It In Action
- Architecture Overview
- MCP Tools for AI Assistants
- Key Features
- Quick Start
- Use Cases
- Documentation
- Development
- Roadmap
- Contributing
- License
🎯 The Problem
Modern codebases are
25e4c8ac4e42OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add axon-mcp-ui --env AZUREDEVOPS_SSH_KEY_PATH=${AZUREDEVOPS_SSH_KEY_PATH} --env GITLAB_SSH_KEY_PATH=${GITLAB_SSH_KEY_PATH} -- npx -y [email protected]{
"mcpServers": {
"axon-mcp-ui": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"AZUREDEVOPS_SSH_KEY_PATH": "${AZUREDEVOPS_SSH_KEY_PATH}",
"GITLAB_SSH_KEY_PATH": "${GITLAB_SSH_KEY_PATH}"
}
}
}
}Exposed tools (22)
22 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_architecture | read | Analyze architecture |
find_api_endpoints | read | Find API endpoints |
find_callees | read | Find callees |
find_callers | read | Find callers |
find_implementations | read | Find interface implementations |
find_references | read | Find all references |
find_usages | read | Find symbol usages |
get_call_hierarchy | read | Get call hierarchy |
get_file_content | read | Read file content |
get_file_tree | read | Get directory tree |
get_module_summary | read | Get module summary |
get_project_map | read | Get project map |
get_symbol_context | read | Get detailed context for a specific symbol |
list_dependencies | read | List package dependencies |
list_repositories | read | List available repositories |
list_symbols_in_file | read | List symbols in file |
query_codebase_structure | read | Query codebase structure |
search_by_path | read | Search files by path |
search_code | read | Search for code symbols across repositories |
search_configuration | read | Search configuration settings |
search_documentation | read | Search markdown documentation files |
trace_request_flow | read | Trace request flow |
Trust audit
BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (12 observation(s))
- Network
- declared (10 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
(r'-----BEGIN PRIVATE KEY-----', 'private_key'),
(r'-----BEGIN RSA PRIVATE KEY-----', 'rsa_key'),
credentials_file = Path.home() / ".git-credentials"
ssh_key_path = os.getenv("AZUREDEVOPS_SSH_KEY_PATH", str(Path.home() / ".ssh" / "id_rsa"))ssh_key_path = os.getenv("GITLAB_SSH_KEY_PATH", str(Path.home() / ".ssh" / "id_rsa"))config_options.extend(["-c", f"http.https://{parsed_url.netloc}/.sslVerify=false"])DATABASE_URL=postgresql://axon:password@localhost:5432/axon_mcp # (REQUIRED)
# Note: When running via Docker Compose, use: postgresql://axon:password@postgres:5432/axon_mcp
sqlalchemy.url = postgresql://axon:axon_dev_password@localhost:5432/axon_mcp
Newtonsoft.Json.dll
RoslynAnalyzer.dll
RoslynAnalyzer.exe
RoslynAnalyzer.pdb
Microsoft.CodeAnalysis.CSharp.resources.dll
logger.warning("invalid_api_key_attempt", key_prefix=api_key[:8] if len(api_key) > 8 else "too_short")API_CORS_ORIGINS=["http://localhost:3000","http://127.0.0.1:3000"] # Explicit browser origins (JSON array)
- VITE_API_BASE_URL=http://10.30.81.101/
api_cors_origins: list[str] = ["http://localhost:3000", "http://127.0.0.1:3000"]
"http://127.0.0.1:3000",
postgresql://axon:password@localhost:5432/axon_mcp
.pre-commit-config.yaml
.NETCoreApp,Version=v9.0.AssemblyAttributes.cs
.eslintrc.cjs
key_hash = hashlib.md5(key_str.encode()).hexdigest()
key_hash = hashlib.md5(key.encode()).hexdigest()
Gates applied: critical_finding, no_behavioural_pass.
25e4c8ac4e42full audit observations/trust-audit/mcp-server/ali-kamali__axon.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 25e4c8ac4e42 | BLOCK | F | 43 | first audit |
Questions
What is the Axon MCP server?
Transform your codebase into an intelligent knowledge base for AI-powered development with Cursor IDE, Google AntiGravity, and MCP-enabled assistants
What tools does Axon expose?
22 in total: 22 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Axon safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (43/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Axon need?
It reads AZUREDEVOPS_SSH_KEY_PATH and GITLAB_SSH_KEY_PATH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Axon run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as axon-mcp-ui at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (25e4c8ac4e42), read on 2026-10-06. The repository is watched and re-audited when it changes.