Agent LSPCAUTION
MCP server that orchestrates language servers into agent-native workflows. 65 tools, 30 CI-verified languages.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English · 简体中文 · Русский · हिन्दी · العربية
Code intelligence infrastructure for AI agents. 65 tools, 32 CI-verified languages, 24 agent workflows. Single Go binary.
curl -fsSL https://raw.githubusercontent.com/blackwell-systems/agent-lsp/main/install.sh | sh && agent-lsp init
What is it?
agent-lsp is an MCP server t
d85f852c6b97OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add agent-lsp -- npx -y @blackwell-systems/[email protected]
Trust audit
CAUTIONgrade C · trust 78/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
url = "postgresql://postgres:postgres@localhost:5432/prismatest?schema=public"
const token = "testtoken-integration"
greeter.cpp.9E8894AE24BDC63E.idx
person.cpp.B4A194926E14B7F4.idx
person.h.A09FB4C76E6CAEB5.idx
.coderabbit.yaml
.goreleaser.yml
.polywave-ownership.json
.saw-agent-brief.md
.saw-worktree-env
docs/changelog.md
- os/exec (for LookPath)
_, err := ValidateFilePath("/home/user/project/../../etc/passwd", "/home/user/project")baseURL := "http://127.0.0.1:" + strconv.Itoa(port)
@prisma/client
> Note: npm skipped 0.19.2 (its publish was blocked by the token deprecation); 0.19.3 carries the 0.19.2 fixes forward, including the `detect_changes` argument-injection fix ([#23](https://github.com/
- **Proactive server notifications.** Four server-initiated MCP notification channels push state changes to agents without requiring a tool call: (1) diagnostic changes with 2-second debouncing to coa
- **MCP log notifications** — internal log messages (LSP server start, tool dispatch errors, indexing events) now route as `notifications/message` to the connected MCP client via `mcpSessionSender`; w
Language servers report long-running work (like indexing a workspace) via `$/progress` notifications, each tagged with a token. agent-lsp tracks active tokens to know when the server is ready. Workspa
**MQL (mql-lsp-server):** Runs in a dedicated `multi-lang-mql` job without `continue-on-error`. The job installs the self-contained linux-x64 binary from the [davalillo/mql-language-server releases](h
assets/banner.png
assets/social-preview-minimal.png
assets/social-preview.png
- **SQL integration test** — `sqls` (`go install github.com/sqls-server/sqls@latest`); fixture at `test/fixtures/sql/` with `schema.sql` (CREATE TABLE person + post), `query.sql` (two SELECT statement
Gates applied: no_behavioural_pass.
d85f852c6b97full audit observations/trust-audit/mcp-server/blackwell-systems__agent-lsp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d85f852c6b97 | CAUTION | C | 78 | first audit |
Questions
What is the Agent LSP MCP server?
MCP server that orchestrates language servers into agent-native workflows. 65 tools, 30 CI-verified languages.
Is Agent LSP safe to connect to an agent?
With care. The audit graded it C (78/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Agent LSP need?
No credential environment variables were found in its source, so it appears to need none.
How does Agent LSP run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as fixture at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (d85f852c6b97), read on 2026-10-07. The repository is watched and re-audited when it changes.