Atlas / MCP servers / corbell-ai / Corbell

CorbellCAUTION

mcp/corbell-ai/corbell

AI-powered spec generation and review using multi-repo code graph intelligence for backend teams that ship to production.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
4 4r · 0w · 0d
Transport
sse · stdio
License
Apache-2.0
Stars
628
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Corbell Multi-repo architecture graph, AI-powered spec generation, and architecture review — for backend teams that ship to production.

What problem does this solve?

You're a staff engineer or architect at a company where features touch 5–10 repositories. Every quarter your team re-litigates the same architectural decisions: "should we use Kafka or SQS?", "why do we have three different auth patterns?", "who owns the rate-limiting layer?"

The decisions live in Confluence pages nobody reads, Slack messages nobody can find, and the memories of engineers who've since left.

When a new engineer joins—or even when you return to a service you haven't touched in 6 months—you're starting from scratch.

Corbell gives your team a living knowledge graph of your architecture — built from the actual code in your repos and your team's past design docs. When you need a new spec, Corbell generates one that respects your established patterns instead of inventing new ones. When you push to Linear, each task carries the exact method signatures, call paths, and cross-service impacts an AI coding agent needs to work autonomously.

How it looks

Star History (thank you)

How it works

You
Read from source at commit 3cfa7ae10408OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add corbell --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} --env BEDROCK_API_KEY=${BEDROCK_API_KEY} --env CORBELL_JIRA_API_TOKEN=${CORBELL_JIRA_API_TOKEN} --env CORBELL_JIRA_PROJECT_KEY=${CORBELL_JIRA_PROJECT_KEY} -- uvx corbell
claude-desktop
{
  "mcpServers": {
    "corbell": {
      "command": "uvx",
      "args": [
        "corbell"
      ],
      "env": {
        "AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}",
        "BEDROCK_API_KEY": "${BEDROCK_API_KEY}",
        "CORBELL_JIRA_API_TOKEN": "${CORBELL_JIRA_API_TOKEN}",
        "CORBELL_JIRA_PROJECT_KEY": "${CORBELL_JIRA_PROJECT_KEY}"
      }
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
code_searchreadSemantic search across Corbell
get_architecture_contextreadGet architecture and code context for a feature without LLM generation.
graph_queryreadQuery Corbell
list_servicesreadList all services in the current Corbell workspace graph.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (3)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
corbell/core/llm_client.py:187
or os.path.exists(os.path.expanduser("~/.aws/credentials"))
Why it matters. touches a credential store
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
corbell/core/graph/method_graph.py:265
mod = __import__(module_name)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_jira_export.py:133
decoded = base64.b64decode(encoded).decode()

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 3cfa7ae10408full audit observations/trust-audit/mcp-server/corbell-ai__corbell.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-303cfa7ae10408CAUTIONB89first audit
06

Questions

What is the Corbell MCP server?

AI-powered spec generation and review using multi-repo code graph intelligence for backend teams that ship to production.

What tools does Corbell expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Corbell safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Corbell need?

It reads AWS_ACCESS_KEY_ID, BEDROCK_API_KEY, CORBELL_JIRA_API_TOKEN, CORBELL_JIRA_PROJECT_KEY, CORBELL_LINEAR_API_KEY, CORBELL_LLM_API_KEY, CORBELL_NOTION_TOKEN and GOOGLE_APPLICATION_CREDENTIALS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Corbell run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on PyPI as corbell.

How current is this page?

The grade is for one exact copy of the source (3cfa7ae10408), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement