Atlas / MCP servers / codealive-ai / CodeAlive

CodeAliveCAUTION

mcp/codealive-ai/codealive

Context engine for large codebases, exposed through MCP. Gives AI coding agents precise repository context; benchmarked at frontier-agent quality with ~25x lower model cost and 45% fewer tokens with semantic search.

Verdict
CAUTION
Grade
C
Trust score
75 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
91
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.codealive.ai/)

Connect your AI assistant to CodeAlive's powerful code understanding platform in seconds!

This MCP (Model Context Protocol) server enables AI clients like Claude Code, Cursor, Claude Desktop, Continue, VS Code (GitHub Copilot), Cline, Codex, OpenCode, SourceCraft Code Assistant, SourceCraft CLI, Zed, KodaCode, GigaCode, Qwen Code, Gemini CLI, Roo Code, Goose, Kilo Code, Windsurf, Kiro, Qoder, n8n, and Amazon Q Developer to access CodeAlive's advanced semantic code search and codebase interaction features.

What is CodeAlive?

CodeAlive is a Context Engine for large codebases, powered by graph-based retrieval and exposed through MCP. It gives AI agents like Cursor, Claude Code, Codex, and other MCP-compatible tools precise repository context instead of forcing them to read files blindly. In our RepoQA benchmark, CodeAlive + Qwen3.6 deep reached frontier-agent quality at ~25x lower model cost, and semantic search reduced captured tokens by 45%.

It's like Context7, but for your (large) codebases.

It allows AI-Coding Agents to:

  • Find relevant code faster with semantic search
  • Understand the bigger picture beyond isolated files
  • Provide better answers with full project context
  • Reduce costs and time by removing guesswork

🛠 Available Tools

Once connected, you'll have access to these powerful tools:

  1. `get_data_sources` - List your indexed repositories and workspaces
  2. `semantic_search` - Canonical semantic search across indexed artifacts
  3. `grep_search` - Exact literal or regex text search inside file content, plus literal file-name/path matching (returns files like Form.xml even when their content never mentions the name), with line-level previews for cont
Read from source at commit cea644d63230OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add codealive-mcp:main --env CODEALIVE_API_KEY=${CODEALIVE_API_KEY} -- docker run -i --rm ghcr.io/codealive-ai/codealive-mcp:main:None
03

Trust audit

CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (14)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tests/test_oauth.py:288
token="header.payload.signature",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tests/test_oauth.py:499
token="header.payload.signature",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tests/test_oauth.py:522
token="header.payload.signature",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tests/test_oauth.py:530
token="header.payload.signature",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/tests/test_oauth.py:542
token="header.payload.signature",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/test_http_compatibility.py:83
"CODEALIVE_BASE_URL": f"http://127.0.0.1:{backend.server_port}",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/test_http_compatibility.py:84
"OTEL_EXPORTER_OTLP_ENDPOINT": f"http://127.0.0.1:{backend.server_port}",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/test_http_compatibility.py:94
url = f"http://127.0.0.1:{port}"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/test_oauth.py:112
provider = build_oauth_provider(_config(mcp_resource="http://127.0.0.1:8000/api"))
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/test_stdio_smoke.py:91
"CODEALIVE_BASE_URL": f"http://127.0.0.1:{port}/api",
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/tests/test_response_transformer.py:370
"lineText": "\tТипШтрихкодаИВидУпаковки.ТипШтрихкода = Перечисления.ТипыШтрихкодов.GS1_DataMatrix;",
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:96
Choose your client in the [MCP integration guides](https://docs.codealive.ai/integrations/mcp) and follow the current setup instructions there.
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha cea644d63230full audit observations/trust-audit/mcp-server/codealive-ai__codealive.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07cea644d63230CAUTIONC75first audit
05

Questions

What is the CodeAlive MCP server?

Context engine for large codebases, exposed through MCP. Gives AI coding agents precise repository context; benchmarked at frontier-agent quality with ~25x lower model cost and 45% fewer tokens with semantic search.

Is CodeAlive safe to connect to an agent?

With care. The audit graded it C (75/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does CodeAlive need?

It reads CODEALIVE_API_KEY, CODEALIVE_MCP_OAUTH_ENABLED, CODEALIVE_OAUTH_INTERNAL_CLIENT_ID, CODEALIVE_OAUTH_INTERNAL_CLIENT_SECRET and CODEALIVE_OAUTH_ISSUER from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does CodeAlive run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as codealive-mcp.

How current is this page?

The grade is for one exact copy of the source (cea644d63230), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement