Atlas / MCP servers / biegehydra / Bifrost

BifrostSAFE

mcp/biegehydra/bifrost

VSCode Extension with an MCP server that exposes semantic tools like Find Usages and Rename to LLMs

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
19 17r · 2w · 0d
Transport
sse
License
AGPL-3.0
Stars
223
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

<img src="https://img.shields.io/visual-studio-marketplace/d/ConnorHallman.bifrost-mcp?label=VSCode%20Extension%20Downloads&cacheSeconds=3600" alt="VSCode Extension Downloads" width="250">

This VS Code extension provides a Model Context Protocol (MCP) server that exposes VSCode's powerful development tools and language features to AI tools. It enables advanced code navigation, analysis, and manipulation capabilities when using AI coding assistants that support the MCP protocol.

Table of Contents

  • Features
  • Installation/Usage
  • Multi-Project Support
  • Available Tools
  • Available Commands
  • Troubleshooting
  • Contributing
  • Debugging
  • License

Features

  • Language Server Integration: Access VSCode's language server capabilities for any supported language
  • Code Navigation: Find references, definitions, implementations, and more
  • Symbol Search: Search for symbols across your workspace
  • Code Analysis: Get semantic tokens, document symbols, and type information
  • Smart Selection: Use semantic selection ranges for intelligent code selection
  • Code Actions: Access refactoring suggestions and quick fixes
  • HTTP/SSE Server: Exposes language features over an MCP-compatible HTTP server
  • AI Assistant Integration: Ready to work with AI assistants that support the MCP protocol

Usage

Installation

  1. Install the extension from the VS Code marketplace
  2. Install any language-specific extensions you need for your development
  3. Open your pro
Read from source at commit 8b51149ac987OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add bifrost-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "bifrost-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (19)

17 read · 2 write · 0 destructive.

ToolRiskDescription
find_implementationsreadDiscovers all concrete implementations of an interface, abstract class, or abstract method in the codebase.
find_usagesreadFinds all references to a symbol at a specified location in code. This tool helps you identify where functions, variables, types, or other symbols are used throughout the codebase.
get_call_hierarchyreadAnalyzes and visualizes the call relationships between functions and methods in the codebase.
get_code_actionsreadProvides context-aware code actions and refactoring suggestions at a specified location.
get_code_lensreadGets CodeLens information for a document, showing actionable contextual information inline with code
get_completionsreadProvides intelligent code completion suggestions based on the current context and cursor position.
get_declarationreadFinds declarations of a symbol at a specified location. This helps in navigating to where symbols are declared, particularly useful for imported symbols.
get_document_highlightsreadFinds all highlights of a symbol in a document. This is useful for highlighting all occurrences of a symbol within the current document.
get_document_symbolsreadAnalyzes and returns a hierarchical list of all symbols defined within a document.
get_hover_inforeadRetrieves comprehensive information about a symbol when hovering over it in code.
get_rename_locationswriteIdentifies all locations that need to be updated when renaming a symbol.
get_selection_rangereadGets selection ranges for a position in a document. This helps in smart selection expansion based on semantic document structure.
get_semantic_tokensreadProvides detailed semantic token information for enhanced code understanding and highlighting.
get_signature_helpreadProvides detailed information about function signatures as you type function calls.
get_type_definitionreadFinds type definitions of a symbol at a specified location. This is particularly useful for finding the underlying type definitions of variables, interfaces, and classes.
get_type_hierarchyreadAnalyzes and visualizes the inheritance and implementation relationships between types.
get_workspace_symbolsreadSearches for symbols across the entire workspace. This is useful for finding symbols by name across all files. Especially useful for finding the file and positions of a symbol to use in other tools.
go_to_definitionreadNavigates to the original definition of a symbol at a specified location in code.
renamewriteIdentifies all locations that need to be updated when renaming a symbol, and performs the renaming.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
sse
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.binary · CWE-1104
icon.txt
icon.txt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
placeholder.txt
placeholder.txt
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vscode-test.mjs
.vscode-test.mjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/cors, @types/express, cors, express, @types/mocha, @types/vscode, @typescript-eslint/eslint-plugin
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 8b51149ac987full audit observations/trust-audit/mcp-server/biegehydra__bifrost.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-068b51149ac987SAFEB89first audit
06

Questions

What is the Bifrost MCP server?

VSCode Extension with an MCP server that exposes semantic tools like Find Usages and Rename to LLMs

What tools does Bifrost expose?

19 in total: 17 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Bifrost safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Bifrost need?

No credential environment variables were found in its source, so it appears to need none.

How does Bifrost run?

It speaks sse, so it runs as a service you connect to over the network. It is published on npm as bifrost-mcp at 0.0.14.

How current is this page?

The grade is for one exact copy of the source (8b51149ac987), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement