CodebaseBLOCK
A vector embedding-based code semantic search tool with MCP server and multi-model integration. Can be used as a pure CLI tool. Supports Ollama for fully local embedding and reranking, enabling complete offline operation and privacy protection for your code repository
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@autodev/codebase) [](https://github.com/anrgct/autodev-codebase) [](https://opensource.org/licenses/MIT)
A vector embedding-based code semantic search tool with MCP server and multi-model integration. Can be used as a pure CLI tool. Supports Ollama for fully local embedding and reranking, enabling complete offline operation and privacy protection for your code repository.
# Semantic code search - Find code by meaning, not just keywords
╭─ ~/workspace/autodev-codebase
╰─❯ codebase search "user manage" --demo
Found 20 results in 5 files for: "user manage"
==================================================
File: "hello.js"
==================================================
(L7-20)
class UserManager {
constructor() {
this.users = [];
}
addUser(user) {
this.users.push(user);
console.log('User added:', user.name);
}
getUsers() {
return this.users;
}
}
......
# Call graph analysis - Trace function call relationships and execution paths
╭─ ~/workspace/autodev-codebase
╰─❯ codebase call --demo --query="app,addUser"
Connections between app, addUser:
Found 2 matching node(s):
- demo/app:L1-29
- demo/hello.UserManager.addUser:L12-15
Direct connections:
- demo/app:L1-29 → demo/hello.UserManager.addUser:L12-15
Chains found:
- demo/app:L1-29 → demo/hello.UserManager.addUser:L12-15
# Code outline with AI summaries - Understand code structure at a glance
╭─ ~/workspace/autodev-codebase
╰─❯ codebase outline 'hello.js' --demo --summarize
# hello.js (23 lines)
└─ Defines a greeting function that logs a personalized hello message and returns a welcome string. Implements a UserManager class managing an array of users with methods 6cd509855b44OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add codebase --env API_KEY=${API_KEY} --env STAGE3_TOKENS=${STAGE3_TOKENS} -- npx -y @autodev/[email protected]{
"mcpServers": {
"codebase": {
"command": "npx",
"args": [
"-y",
"@autodev/[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"STAGE3_TOKENS": "${STAGE3_TOKENS}"
}
}
}
}Exposed tools (3)
2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
addition | read | 两个数字相加 |
finish | write | You are an ADVISOR — you have NO other tools. You cannot search, read files, run code, or inspect the codebase. |
foo | read |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
echo "[2/2] Running eval (search layer=$local_search_layer)..."
You are an ADVISOR — you have NO other tools. You cannot search, read files, run code, or inspect the codebase.
libggml-base.dylib
libggml-blas.dylib
libggml-cpu.dylib
libggml-metal.dylib
libggml.metal.b9370.2da1n284.dylib
console.log(`[case] shape warning: nTokens=${nTokens} differs from query token count=${nQueryTokens}`);console.log(`Token count: ${nTokens}`);console.log(`Per-token embeddings all identical? ${allSame ? "✅ YES (late-chunking IS a no-op)" : "❌ NO (late-chunking COULD work)"}`);console.log(`\nSingle-chunk last-token (NONE):`);
console.log(`\nMulti-chunk last-token (NONE, late-chunking simulation):`);
const proxyUrl = `http://127.0.0.1:${handle.port}`console.log(`\n🔍 语义变化最大发生在: L${jumpLayer - 1} → L${jumpLayer} (Δcos = ${maxJump.toFixed(4)})`);const apiKey = "test-mistral-api-key"
const apiKey = "test-mistral-api-key"
.version
AGENTS.md
const segmentHash = createHash('md5')const CODE_PATH = path.resolve(import.meta.dirname ?? __dirname, "../../demo/model.py")
import { startEscalateServer } from '../../src/escalate/server'import { QRRankerHighlighter } from "../../src/code-index/highlighters/qrranker";import { QRRankerReranker } from "../../src/code-index/rerankers/qrranker";import type { RerankerCandidate } from "../../src/code-index/interfaces";Gates applied: no_behavioural_pass, no_license.
6cd509855b44full audit observations/trust-audit/mcp-server/anrgct__codebase-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6cd509855b44 | BLOCK | F | 55 | first audit |
Questions
What is the Codebase MCP server?
A vector embedding-based code semantic search tool with MCP server and multi-model integration. Can be used as a pure CLI tool. Supports Ollama for fully local embedding and reranking, enabling complete offline operation and privacy protection for your code repository
What tools does Codebase expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Codebase safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Codebase need?
It reads API_KEY and STAGE3_TOKENS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Codebase run?
It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as @autodev/codebase at 1.0.1.
How current is this page?
The grade is for one exact copy of the source (6cd509855b44), read on 2026-10-07. The repository is watched and re-audited when it changes.