Atlas / MCP servers / arman-kudaibergenov / BSL Atlas

BSL AtlasCAUTION

mcp/arman-kudaibergenov/bsl-atlas

MCP-сервер для 1С/BSL: векторный поиск, структурный индекс, граф вызовов

Verdict
CAUTION
Grade
C
Trust score
78 /100
Exposed tools
14 13r · 1w · 0d
Transport
streamable-http
License
AGPL-3.0
Stars
79
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://hub.docker.com/r/armankudaibergenov/bsl-atlas)

Публичный MCP-сервер для быстрой индексации и поиска по исходникам 1С. Работает с XML/BSL-выгрузкой конфигурации или расширения и отдает структурный и, при необходимости, семантический поиск для AI-ассистентов.

Что умеет

  • искать функции, процедуры и модули через SQLite/FTS
  • искать объекты метаданных, реквизиты и связи
  • строить контекст по вызовам и структуре модулей
  • работать в fast режиме без внешних embedding API
  • переиндексировать проект после новой выгрузки

Режимы

fast — основной и рекомендуемый стартовый режим.

Важно: mount исходников обязателен

Если вы запускаете bsl-atlas в Docker, контейнер обязан видеть реальные исходники проекта через bind mount SOURCE_PATH -> /data/source.

  • SOURCE_PATH нужен для индексации файлов
  • если bind mount настроен неверно, /data/source внутри контейнера может существовать, но будет пустым
  • в этом случае Atlas честно сообщит, что каталог исходников пустой

Это отдельная тема от RLM: Atlas читает файлы проекта напрямую, поэтому без source mount индексировать нечего.

Быстрый старт

1. Выгрузите исходники 1С

В конфигураторе используйте Конфигурация -> Выгрузить конфигурацию в файлы и укажите пустой каталог.

2. Скачайте конфиги

curl -O https://raw.githubusercontent.com/Arman-Kudaibergenov/bsl-atlas/master/docker-compose.yml
curl -O https://raw.githubusercontent.com/Arman-Kudaibergenov/bsl-atlas/master/.env.example
cp .env.example .env

3. Заполните .env

SOURCE_PATH=C:\bsl-src
INDEXING_MODE=fast

Для full режима дополнительно укажите embedding pr

Read from source at commit f0beaa530838OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add bsl-atlas --env COHERE_API_KEY=${COHERE_API_KEY} --env JINA_API_KEY=${JINA_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- uvx bsl-atlas
claude-desktop
{
  "mcpServers": {
    "bsl-atlas": {
      "command": "uvx",
      "args": [
        "bsl-atlas"
      ],
      "env": {
        "COHERE_API_KEY": "${COHERE_API_KEY}",
        "JINA_API_KEY": "${JINA_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
      }
    }
  }
}
03

Exposed tools (14)

13 read · 1 write · 0 destructive.

ToolRiskDescription
code_grepreadSearch for text pattern in BSL code with AST context.
get_form_inforeadStructure + event handlers of a managed form (Form.xml), read on demand.
get_module_functionsreadList all functions and procedures in a BSL module.
get_object_detailsreadGet attributes, tabular parts, and register movements for a metadata object.
get_skd_inforeadDatasets / query text / fields / parameters of a DataCompositionSchema (СКД).
metadatasearchreadSearch 1C metadata objects.
read_functionreadRead a function/procedure with its full neighbourhood in ONE call — the
reindex_changedreadPick up edited/added/deleted .bsl files since the last index — fast.
repomapreadLay-of-the-land map: signatures only of the most central symbols (no bodies).
search_functionreadFind a function or procedure by name across all indexed modules.
statsreadGet statistics about indexed data.
triggers_on_writewriteWhat fires when an object is written/posted — object handlers + subscriptions + register movements.
verify_callreadOracle: does `caller` actually call `callee`? Check before asserting it.
verify_fieldreadOracle: does `field` exist on the object (attribute or tabular-part attribute)?
04

Trust audit

CAUTIONgrade C · trust 78/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (3 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (14)

MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:11
&& rm -rf /var/lib/apt/lists/*
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:32
&& rm -rf /tmp/tree-sitter-bsl
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:43
&& rm -rf /var/lib/apt/lists/*
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/parsers/code.py:36
EXPORT_PATTERN = re.compile(r"\bЭкспорт\b|\bExport\b", re.IGNORECASE)
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/parsers/code.py:153
r"(?:([А-Яа-яёЁA-Za-z_]\w*)\s*\.\s*)?([А-Яа-яёЁA-Za-z_]\w*)\s*\("
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/parsers/code.py:187
"Новый", "XMLСтрока", "XMLЗначение", "XMLТип",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/parsers/code.py:193
"ТипЗначения", "Маx", "Min",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/parsers/code.py:250
r"([А-Яа-яёЁA-Za-z]+)\.([А-Яа-яёЁA-Za-z0-9_]+)",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
Dockerfile:1
# syntax=docker/dockerfile:1
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/__init__.py:1
"""1C Cloud MCP Server - Fast vector indexing with cloud embeddings."""
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/config.py:1
"""Configuration management via environment variables."""
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/indexer/embeddings.py:1
"""Embedding providers abstraction with cloud API support."""
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_vector_pipeline.py:170
h = hashlib.md5(t.encode()).digest()
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/test_advanced_search.py:1
"""Tests for advanced search functionality."""

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha f0beaa530838full audit observations/trust-audit/mcp-server/arman-kudaibergenov__bsl-atlas.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07f0beaa530838CAUTIONC78first audit
06

Questions

What is the BSL Atlas MCP server?

MCP-сервер для 1С/BSL: векторный поиск, структурный индекс, граф вызовов

What tools does BSL Atlas expose?

14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is BSL Atlas safe to connect to an agent?

With care. The audit graded it C (78/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does BSL Atlas need?

It reads COHERE_API_KEY, JINA_API_KEY, OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does BSL Atlas run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as bsl-atlas.

How current is this page?

The grade is for one exact copy of the source (f0beaa530838), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement