Agent MakoBLOCK
Local-first MCP server that gives coding agents structured context packets, code/schema facts, and diagnostics - backed by a local SQLite store.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/agentmako) [](https://github.com/drhalto/agentmako/actions/workflows/smoke.yml) [](./LICENSE) [](https://nodejs.org/) [](https://glama.ai/mcp/servers/drhalto/agentmako)
agentmako is a local-first codebase intelligence engine for AI coding tools.
It gives agents like Codex, Claude Code, Cursor, and local harnesses a compact Reef-first tool surface for understanding a project before they edit it. Mako indexes your repo, builds local SQLite-backed facts, tracks diagnostics and review notes, and answers evidence-backed questions instead of making the agent orchestrate broad tool chains or rediscover everything with raw grep.
Mako is built for the first mile of coding-agent work:
What files matter? What routes, symbols, tables, diagnostics, and prior findings are relevant? What should the agent read next?
What You Get
- MCP server for coding agents:
agentmako mcp - Local dashboard:
agentmako dashboard - Primary project query:
reef_askacross code, database, findings,
diagnostics, instructions, freshness, and literal checks
- Queryable workflow orientation:
mako_help - Deterministic context expansion:
context_packet _hintson tool results so agents get result-specific next steps- Central MCP annotations so clients can distinguish safe reads, live reads,
and local-state mutations
- Compact loop/fallback tools:
reef_status,reef_verify,reef_impact,
live_text_search, lint_files, and `tool_
095fe6cde56bOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add agentmako -- npx -y [email protected]
Exposed tools (19)
12 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
apply_patch | write | Apply a multi-file unified diff. Hunks must apply cleanly with exact context. |
create_file | write | Create a new file at a project-relative path. Errors if the file already exists; use file_write to overwrite. |
cross_search | write | Search a term across code chunks, schema objects, RPC/trigger bodies, routes, and stored memories in one call. Exact code literals route to a bounded live_text_search preview. Use live_text_search directly for full inventories, regex, or custom glob scope. |
delete_file | destructive | Delete a file at a project-relative path. Snapshot captures the bytes for undo. |
file_edit | write | Replace a substring in an existing file. The substring must occur exactly once unless replaceAll is true. |
file_write | destructive | Create or overwrite a file at a project-relative path. Returns a snapshot id for undo. |
memory_list | read | List stored memories for the active project, most recent first. Optional category, tag, and since filters. |
memory_recall | read | Search stored memories. Returns hybrid FTS+vector results when an embedding provider is healthy, or FTS-only results with a mode signal when it is not. |
memory_remember | read | Store a durable fact scoped to the active project. Optionally embed it for semantic recall. Returns the memory id and whether an embedding was produced. |
preflight_table | read | Return the full preflight surface for a table: columns, primary key, indexes, foreign keys, RLS state + policies, triggers, related routes, and zod schemas whose surrounding file references the table. Snapshot-strict. |
semantic_search | read | Search repo-local code symbols, markdown docs, and memories. Returns hybrid FTS+vector results when embeddings are healthy, or FTS-only results with a mode signal when they are not. |
shell_run | write | Run a shell command with arguments as a list (never concatenated). cwd is locked to the project root or a subdirectory; env keys must be allowlisted. |
sub_agent_spawn | read | Delegate a scoped task to a child agent session. The child runs with its own context and returns a summary when done. Use when a task is large enough that isolating its context from the parent |
tool_search | read | Search the immediate, deferred, and blocked tool catalog. Use when you are unsure which tool fits a task or why a tool is unavailable in this session. |
trace_edge | read | Trace a handler / edge function: its own route, app-code callers (ast-grep on fetch( |
trace_error | read | Trace an error term across throw sites (ast-grep |
trace_file | read | Trace a file end-to-end from the snapshot: declared symbols, outbound imports, inbound dependents, routes contributed, and related evidence. Read-only. |
trace_rpc | read | Trace an RPC end-to-end: the RPC definition (searchSchemaObjects filtered to rpc), other PL/pgSQL bodies whose body text references it (searchSchemaBodies), overload-aware table refs (listFunctionTableRefs), and app-code .rpc( |
trace_table | read | Trace a table end-to-end: columns, indexes, foreign keys, RLS, triggers (via getSchemaTableSnapshot), schema-scoped RPC → table edges (via listFunctionTableRefs), and app-code .from( |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
message: "Dynamic code execution via eval(); attacker-influenced input here is remote code execution.",
patterns: [{ pattern: "eval($X)", captures: ["X"] }],message: "Dynamic code generation via new Function(...); avoid building executable code from runtime values.",
patterns: [{ pattern: "new Function($$$ARGS)" }],{ pattern: "exec($X)", captures: ["X"] },/^id_rsa(\.|$)/i,
/^id_ed25519(\.|$)/i,
/^id_ecdsa(\.|$)/i,
message: "Math.random() is not cryptographically secure; use crypto.randomBytes/randomUUID for tokens or secrets.",
const url = `http://127.0.0.1:${args.port}`;const DEFAULT_ENDPOINT = process.env.MAKO_HARNESS_URL ?? "http://127.0.0.1:3018";
const DEFAULT_ENDPOINT = process.env.MAKO_HARNESS_URL ?? "http://127.0.0.1:3018";
const HARNESS_ORIGIN = process.env.MAKO_HARNESS_URL ?? "http://127.0.0.1:3018";
$env:MAKO_TEST_DATABASE_URL = "postgresql://postgres:[email protected]:54322/postgres"
delete_file, file_write
" return crypto.createHash('md5').update(input).digest('hex');",out = resolve(here, "../../../packages/harness-contracts/models/snapshot.json");
fileURLToPath(new URL("../../services/indexer/package.json", import.meta.url)),"../../packages/harness-contracts/models/snapshot.json",
const sourceDir = resolve(here, "../../apps/web/dist");
import type { FlowGraph, FlowNode, FlowNodeKind } from "../../lib/flow/graph-model";- MCP at `http://127.0.0.1:3017/mcp`
"export const agent = new https.Agent({ rejectUnauthorized: false });",@ast-grep/napi, @inquirer/password, @modelcontextprotocol/sdk, @napi-rs/keyring, @vscode/ripgrep, eventsource-parser, pg, pgsql-parser
@tanstack/react-query, d3-force, react, react-dom, react-router-dom, shiki, sonner, @tailwindcss/vite
Gates applied: no_behavioural_pass.
095fe6cde56bfull audit observations/trust-audit/mcp-server/drhalto__agent-mako.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 095fe6cde56b | BLOCK | F | 55 | first audit |
Questions
What is the Agent Mako MCP server?
Local-first MCP server that gives coding agents structured context packets, code/schema facts, and diagnostics - backed by a local SQLite store.
What tools does Agent Mako expose?
19 in total: 12 read-only, 5 that write, and 2 that can delete or overwrite (delete_file, file_write). Every one is listed on this page with its risk.
Is Agent Mako safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Agent Mako need?
It reads MAKO_ANTHROPIC_API_KEY, MAKO_OPENAI_API_KEY, MAKO_PROJECT_PROVIDER_KEY, MAKO_TEST_SECRET and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Agent Mako run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as agentmako at 0.2.3.
How current is this page?
The grade is for one exact copy of the source (095fe6cde56b), read on 2026-10-08. The repository is watched and re-audited when it changes.