EnolaCAUTION
Understand, analyze, and govern software systems across repositories, languages, and technologies.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
enola
enola - One graph of your whole software system, built from the code, on your machine
Website · Docs · CLI reference · Benchmarks · Releases · Report a gap
enola reads your source code and writes down what is in it: the modules, the functions, the API routes, the database tables it touches, the message topics it publishes. Then it records how each of those pieces connects to the others, inside one repository and across several. That record is a graph: a list of things, and a list of links between them. You can ask the graph questions, hand it to your coding agent, or build your own tools on it.
Runs locally as one binary. No AI model, no language server, no account, no upload. The graph comes from parsing your code. The same code always produces the same graph.
4aa21d36de96OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ts-sample -- npx -y [email protected]
{
"mcpServers": {
"ts-sample": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
list_datasets_json | read | pass |
list_users_tool | read | Tool handler — dispatched by the MCP server, no in-code caller. |
Trust audit
CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
fmt.Fprintf(os.Stderr, "Shared URL: http://127.0.0.1:%d (whichever server holds it lists all the others)\n", opts.StablePort)
streamable-http
.golangci.yml
const consumerFixtures = "../../internal/engine/testdata/repos"
echo "then re-run with: ENOLA=../../enola ./run.sh" >&2
echo "then re-run with: ENOLA=../../enola ./run.sh" >&2
echo "then re-run with: ENOLA=../../enola ./run.sh" >&2
const customClientExample = "../../examples/custom-client"
export function beacon(d) { return navigator.sendBeacon('/b', d); }for _, name := range []string{"src.getFeed", "src.getUser", "src.readCfg", "src.beacon", "src.openSocket"} {59903 api, web, mobile 57m 12s 42 http://127.0.0.1:56730 (shared)
60122 auth-service 12m 04s 8 http://127.0.0.1:56744
**One bookmarkable URL.** Besides its own port, every server competes for a fixed **shared URL**, `http://127.0.0.1:7171` by default. The first to start wins it; when that one exits another takes over
`http://127.0.0.1:7171`. The first process owns it; another can take over after that
t.Errorf("moved ΔD = %v, want -0.267", r.DeltaD())t.Fatalf("zone change must rank before a larger ΔD without one: %+v", rows)graphql-tag
grpcio
grpcio, grpcio-tools
Flask, Flask-AppBuilder
ember-source, typescript
Agent tooling starts one MCP server per session, so several run concurrently — different repos, sometimes the same repo, both binaries — and they all share `~/.enola`. Two mechanisms keep that from tu
**Pi is the exception that still gets a local file,** because Pi has no MCP client: an instruction naming enola's tools would name tools Pi cannot call. [`pkg/install/pi_extension.js`](pkg/install/pi_
The first two rules were in place from the start; the third was learned from [#288](https://github.com/enola-labs/enola/issues/288), where a comment in `hook.go` asserted that `additionalContext` hand
**Sessions share a repository's `.enola`.** Each run writes `run.json` beside the artifacts (rotated into `previous/` with them) and each pin writes `baseline/pin.json`: the agent session behind it an
Gates applied: no_behavioural_pass.
4aa21d36de96full audit observations/trust-audit/mcp-server/dejo1307__enola.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4aa21d36de96 | CAUTION | B | 82 | first audit |
Questions
What is the Enola MCP server?
Understand, analyze, and govern software systems across repositories, languages, and technologies.
What tools does Enola expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Enola safe to connect to an agent?
With care. The audit graded it B (82/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Enola need?
No credential environment variables were found in its source, so it appears to need none.
How does Enola run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as ts-sample at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (4aa21d36de96), read on 2026-10-08. The repository is watched and re-audited when it changes.