Atlas / MCP servers / drhalto / Agent Mako

Agent MakoBLOCK

mcp/drhalto/agent-mako

Local-first MCP server that gives coding agents structured context packets, code/schema facts, and diagnostics - backed by a local SQLite store.

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
19 12r · 5w · 2d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
54
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/agentmako) [](https://github.com/drhalto/agentmako/actions/workflows/smoke.yml) [](./LICENSE) [](https://nodejs.org/) [](https://glama.ai/mcp/servers/drhalto/agentmako)

agentmako is a local-first codebase intelligence engine for AI coding tools.

It gives agents like Codex, Claude Code, Cursor, and local harnesses a compact Reef-first tool surface for understanding a project before they edit it. Mako indexes your repo, builds local SQLite-backed facts, tracks diagnostics and review notes, and answers evidence-backed questions instead of making the agent orchestrate broad tool chains or rediscover everything with raw grep.

Mako is built for the first mile of coding-agent work:

What files matter? What routes, symbols, tables, diagnostics, and prior findings are relevant? What should the agent read next?

What You Get

  • MCP server for coding agents: agentmako mcp
  • Local dashboard: agentmako dashboard
  • Primary project query: reef_ask across code, database, findings,

diagnostics, instructions, freshness, and literal checks

  • Queryable workflow orientation: mako_help
  • Deterministic context expansion: context_packet
  • _hints on tool results so agents get result-specific next steps
  • Central MCP annotations so clients can distinguish safe reads, live reads,

and local-state mutations

  • Compact loop/fallback tools: reef_status, reef_verify, reef_impact,

live_text_search, lint_files, and `tool_

Read from source at commit 095fe6cde56bOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add agentmako -- npx -y [email protected]
03

Exposed tools (19)

12 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
apply_patchwriteApply a multi-file unified diff. Hunks must apply cleanly with exact context.
create_filewriteCreate a new file at a project-relative path. Errors if the file already exists; use file_write to overwrite.
cross_searchwriteSearch a term across code chunks, schema objects, RPC/trigger bodies, routes, and stored memories in one call. Exact code literals route to a bounded live_text_search preview. Use live_text_search directly for full inventories, regex, or custom glob scope.
delete_filedestructiveDelete a file at a project-relative path. Snapshot captures the bytes for undo.
file_editwriteReplace a substring in an existing file. The substring must occur exactly once unless replaceAll is true.
file_writedestructiveCreate or overwrite a file at a project-relative path. Returns a snapshot id for undo.
memory_listreadList stored memories for the active project, most recent first. Optional category, tag, and since filters.
memory_recallreadSearch stored memories. Returns hybrid FTS+vector results when an embedding provider is healthy, or FTS-only results with a mode signal when it is not.
memory_rememberreadStore a durable fact scoped to the active project. Optionally embed it for semantic recall. Returns the memory id and whether an embedding was produced.
preflight_tablereadReturn the full preflight surface for a table: columns, primary key, indexes, foreign keys, RLS state + policies, triggers, related routes, and zod schemas whose surrounding file references the table. Snapshot-strict.
semantic_searchreadSearch repo-local code symbols, markdown docs, and memories. Returns hybrid FTS+vector results when embeddings are healthy, or FTS-only results with a mode signal when they are not.
shell_runwriteRun a shell command with arguments as a list (never concatenated). cwd is locked to the project root or a subdirectory; env keys must be allowlisted.
sub_agent_spawnreadDelegate a scoped task to a child agent session. The child runs with its own context and returns a summary when done. Use when a task is large enough that isolating its context from the parent
tool_searchreadSearch the immediate, deferred, and blocked tool catalog. Use when you are unsure which tool fits a task or why a tool is unavailable in this session.
trace_edgereadTrace a handler / edge function: its own route, app-code callers (ast-grep on fetch(
trace_errorreadTrace an error term across throw sites (ast-grep
trace_filereadTrace a file end-to-end from the snapshot: declared symbols, outbound imports, inbound dependents, routes contributed, and related evidence. Read-only.
trace_rpcreadTrace an RPC end-to-end: the RPC definition (searchSchemaObjects filtered to rpc), other PL/pgSQL bodies whose body text references it (searchSchemaBodies), overload-aware table refs (listFunctionTableRefs), and app-code .rpc(
trace_tablereadTrace a table end-to-end: columns, indexes, foreign keys, RLS, triggers (via getSchemaTableSnapshot), schema-scoped RPC → table edges (via listFunctionTableRefs), and app-code .from(
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (9 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools/src/operators/owasp/catalog.ts:171
message: "Dynamic code execution via eval(); attacker-influenced input here is remote code execution.",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools/src/operators/owasp/catalog.ts:172
patterns: [{ pattern: "eval($X)", captures: ["X"] }],
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools/src/operators/owasp/catalog.ts:183
message: "Dynamic code generation via new Function(...); avoid building executable code from runtime values.",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools/src/operators/owasp/catalog.ts:184
patterns: [{ pattern: "new Function($$$ARGS)" }],
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/tools/src/operators/owasp/catalog.ts:197
{ pattern: "exec($X)", captures: ["X"] },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/harness-tools/src/path-guard.ts:20
/^id_rsa(\.|$)/i,
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/harness-tools/src/path-guard.ts:21
/^id_ed25519(\.|$)/i,
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/harness-tools/src/path-guard.ts:22
/^id_ecdsa(\.|$)/i,
Why it matters. touches a credential store
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
packages/tools/src/operators/owasp/catalog.ts:284
message: "Math.random() is not cryptographically secure; use crypto.randomBytes/randomUUID for tokens or secrets.",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/cli/src/commands/dashboard.ts:181
const url = `http://127.0.0.1:${args.port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/cli/src/commands/harness-http.ts:1
const DEFAULT_ENDPOINT = process.env.MAKO_HARNESS_URL ?? "http://127.0.0.1:3018";
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/cli/src/commands/harness.ts:14
const DEFAULT_ENDPOINT = process.env.MAKO_HARNESS_URL ?? "http://127.0.0.1:3018";
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/web/vite.config.ts:26
const HARNESS_ORIGIN = process.env.MAKO_HARNESS_URL ?? "http://127.0.0.1:3018";
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
test/README.md:35
$env:MAKO_TEST_DATABASE_URL = "postgresql://postgres:[email protected]:54322/postgres"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file, file_write
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
test/smoke/owasp-audit.ts:73
"  return crypto.createHash('md5').update(input).digest('hex');",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/cli/scripts/snapshot-models.ts:37
out = resolve(here, "../../../packages/harness-contracts/models/snapshot.json");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/cli/tsup.config.ts:21
fileURLToPath(new URL("../../services/indexer/package.json", import.meta.url)),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/cli/tsup.config.ts:73
"../../packages/harness-contracts/models/snapshot.json",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/cli/tsup.config.ts:82
const sourceDir = resolve(here, "../../apps/web/dist");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/web/src/components/flow/ToolFileGraph.tsx:35
import type { FlowGraph, FlowNode, FlowNodeKind } from "../../lib/flow/graph-model";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
TOOLS.md:20
- MCP at `http://127.0.0.1:3017/mcp`
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
test/smoke/owasp-audit.ts:85
"export const agent = new https.Agent({ rejectUnauthorized: false });",
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/cli/package.json
@ast-grep/napi, @inquirer/password, @modelcontextprotocol/sdk, @napi-rs/keyring, @vscode/ripgrep, eventsource-parser, pg, pgsql-parser
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/web/package.json
@tanstack/react-query, d3-force, react, react-dom, react-router-dom, shiki, sonner, @tailwindcss/vite
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 095fe6cde56bfull audit observations/trust-audit/mcp-server/drhalto__agent-mako.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08095fe6cde56bBLOCKF55first audit
06

Questions

What is the Agent Mako MCP server?

Local-first MCP server that gives coding agents structured context packets, code/schema facts, and diagnostics - backed by a local SQLite store.

What tools does Agent Mako expose?

19 in total: 12 read-only, 5 that write, and 2 that can delete or overwrite (delete_file, file_write). Every one is listed on this page with its risk.

Is Agent Mako safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Agent Mako need?

It reads MAKO_ANTHROPIC_API_KEY, MAKO_OPENAI_API_KEY, MAKO_PROJECT_PROVIDER_KEY, MAKO_TEST_SECRET and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Agent Mako run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as agentmako at 0.2.3.

How current is this page?

The grade is for one exact copy of the source (095fe6cde56b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement