CodeAliveCAUTION
Context engine for large codebases, exposed through MCP. Gives AI coding agents precise repository context; benchmarked at frontier-agent quality with ~25x lower model cost and 45% fewer tokens with semantic search.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.codealive.ai/)
Connect your AI assistant to CodeAlive's powerful code understanding platform in seconds!
This MCP (Model Context Protocol) server enables AI clients like Claude Code, Cursor, Claude Desktop, Continue, VS Code (GitHub Copilot), Cline, Codex, OpenCode, SourceCraft Code Assistant, SourceCraft CLI, Zed, KodaCode, GigaCode, Qwen Code, Gemini CLI, Roo Code, Goose, Kilo Code, Windsurf, Kiro, Qoder, n8n, and Amazon Q Developer to access CodeAlive's advanced semantic code search and codebase interaction features.
What is CodeAlive?
CodeAlive is a Context Engine for large codebases, powered by graph-based retrieval and exposed through MCP. It gives AI agents like Cursor, Claude Code, Codex, and other MCP-compatible tools precise repository context instead of forcing them to read files blindly. In our RepoQA benchmark, CodeAlive + Qwen3.6 deep reached frontier-agent quality at ~25x lower model cost, and semantic search reduced captured tokens by 45%.
It's like Context7, but for your (large) codebases.
It allows AI-Coding Agents to:
- Find relevant code faster with semantic search
- Understand the bigger picture beyond isolated files
- Provide better answers with full project context
- Reduce costs and time by removing guesswork
🛠 Available Tools
Once connected, you'll have access to these powerful tools:
- `get_data_sources` - List your indexed repositories and workspaces
- `semantic_search` - Canonical semantic search across indexed artifacts
- `grep_search` - Exact literal or regex text search inside file content, plus literal file-name/path matching (returns files like
Form.xmleven when their content never mentions the name), with line-level previews for cont
cea644d63230OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add codealive-mcp:main --env CODEALIVE_API_KEY=${CODEALIVE_API_KEY} -- docker run -i --rm ghcr.io/codealive-ai/codealive-mcp:main:NoneTrust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (14)
token="header.payload.signature",
token="header.payload.signature",
token="header.payload.signature",
token="header.payload.signature",
token="header.payload.signature",
.mcpbignore
"CODEALIVE_BASE_URL": f"http://127.0.0.1:{backend.server_port}","OTEL_EXPORTER_OTLP_ENDPOINT": f"http://127.0.0.1:{backend.server_port}",url = f"http://127.0.0.1:{port}"provider = build_oauth_provider(_config(mcp_resource="http://127.0.0.1:8000/api"))
"CODEALIVE_BASE_URL": f"http://127.0.0.1:{port}/api","lineText": "\tТипШтрихкодаИВидУпаковки.ТипШтрихкода = Перечисления.ТипыШтрихкодов.GS1_DataMatrix;",
Choose your client in the [MCP integration guides](https://docs.codealive.ai/integrations/mcp) and follow the current setup instructions there.
Gates applied: no_behavioural_pass.
cea644d63230full audit observations/trust-audit/mcp-server/codealive-ai__codealive.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | cea644d63230 | CAUTION | C | 75 | first audit |
Questions
What is the CodeAlive MCP server?
Context engine for large codebases, exposed through MCP. Gives AI coding agents precise repository context; benchmarked at frontier-agent quality with ~25x lower model cost and 45% fewer tokens with semantic search.
Is CodeAlive safe to connect to an agent?
With care. The audit graded it C (75/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does CodeAlive need?
It reads CODEALIVE_API_KEY, CODEALIVE_MCP_OAUTH_ENABLED, CODEALIVE_OAUTH_INTERNAL_CLIENT_ID, CODEALIVE_OAUTH_INTERNAL_CLIENT_SECRET and CODEALIVE_OAUTH_ISSUER from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does CodeAlive run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as codealive-mcp.
How current is this page?
The grade is for one exact copy of the source (cea644d63230), read on 2026-10-07. The repository is watched and re-audited when it changes.