Atlas / MCP servers / er77 / Code Graph RAG

Code Graph RAGCAUTION

mcp/er77/code-graph-rag
Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
27 24r · 0w · 3d
Transport
stdio
License
MIT
Stars
122
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Read from source at commit ade3c7351bbdOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add code-graph-rag-mcp --env CLOUDRU_API_KEY=${CLOUDRU_API_KEY} --env MCP_EMBEDDING_API_KEY=${MCP_EMBEDDING_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y @er77/[email protected]
claude-desktop
{
  "mcpServers": {
    "code-graph-rag-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@er77/[email protected]"
      ],
      "env": {
        "CLOUDRU_API_KEY": "${CLOUDRU_API_KEY}",
        "MCP_EMBEDDING_API_KEY": "${MCP_EMBEDDING_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (27)

24 read · 0 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_code_impactreadUse when: you need a reverse-dependency view (who uses/depends on this). Typical flow: list_file_entities → analyze_code_impact(entityId, filePath hint) → inspect affected files. Output: dependents and affected files; requires indexing.
analyze_hotspotsreadUse when: you want a quick list of risky areas (complexity/changes/coupling). Typical flow: analyze_hotspots(metric) → inspect top files/entities → suggest_refactoring. Output: ranked hotspots with the chosen metric.
batch_indexreadUse when: you need reliable indexing on strict clients/timeouts. Typical flow: batch_index(reset:true) → keep calling batch_index(sessionId) until done:true. Output: progress + stats + next arguments; returns sessionId for resumable sessions.
clean_indexdestructiveUse when: you want a guaranteed clean rebuild (reset + full index). Typical flow: clean_index → query/semantic_search. Output: indexing result; may time out on strict clients—use batch_index if needed.
clear_bus_topicdestructiveUse when: you need to invalidate cached knowledge bus entries for a topic. Typical flow: get_bus_stats → clear_bus_topic(topic). Output: confirmation + updated stats.
cross_language_searchreadUse when: you want discovery constrained to specific languages. Typical flow: cross_language_search(query, languages) → open results → list_file_entities. Output: results filtered by language set; semantic must be available for best quality.
detect_code_clonesreadUse when: you want semantic clone groups across the codebase. Typical flow: detect_code_clones → prioritize hotspots → suggest_refactoring. Output: clone groups; consider jscpd_detect_clones for fast tokenizer-based scanning.
find_related_conceptsreadUse when: you want conceptually related code for an entity (semantic neighbors). Typical flow: list_file_entities → find_related_concepts(entityId) → open candidates. Output: related entities/snippets; semantic must be available.
find_similar_codereadUse when: you have a snippet and want near-duplicate or conceptually similar code. Typical flow: find_similar_code → open candidate file(s) → suggest_refactoring/detect_code_clones. Output: ranked similar snippets with scores (semantic must be available).
get_agent_metricsreadUse when: you need per-agent telemetry (queues, memory, CPU) to debug slow/failed tool calls. Typical flow: get_agent_metrics → adjust concurrency/memory limits. Output: agent snapshots and coordinator metrics.
get_bus_statsreadUse when: you need to debug caching/events and topic growth. Typical flow: get_bus_stats → clear_bus_topic for hot/large topics. Output: topic/entry/subscription counts.
get_entity_sourcereadUse when: you need the exact source snippet for an entity to ground answers. Typical flow: resolve_entity/list_file_entities → get_entity_source(entityId, contextLines) → analyze_code_impact. Output: snippet + line ranges; requires file access and indexing.
get_graphreadUse when: you need a bounded snapshot of entities and relationships for inspection/debugging. Avoid when: exporting entire large graphs—use a query filter/limit. Output: entities + relations + stats; requires indexing.
get_graph_healthreadUse when: you need to verify DB health (counts + sample read). Typical flow: get_graph_health → if unhealthy, clean_index/reset_graph. Output: health status, totals, and sample verification.
get_graph_statsreadUse when: you need counts/summary stats for the indexed graph. Typical flow: get_graph_stats → get_graph_health if counts look suspicious. Output: counts and DB metrics; requires indexing.
get_metricsreadUse when: you need runtime resource usage and agent queue snapshots for debugging. Typical flow: get_metrics → get_agent_metrics for deeper agent telemetry. Output: CPU/memory/resource manager + knowledge bus stats.
get_versionreadUse when: you need server version/runtime info (node/platform/memory/uptime) for debugging. Output: version + runtime details; does not require indexing.
indexreadUse when: you want a one-shot index of a repo and your client can tolerate a long-running tool call. Avoid when: strict transports may time out—use batch_index instead. Typical flow: clean_index → index or batch_index. Output: JSON status + counts; indexing is required for most graph tools.
jscpd_detect_clonesreadUse when: you want fast, tokenizer-based duplicate detection (no embeddings). Typical flow: jscpd_detect_clones(paths, formats) → review clone blocks → refactor. Output: clone blocks with locations; best for quick duplication sweeps.
lerna_project_graphreadUse when: you want a package/workspace dependency graph from Lerna config. Typical flow: lerna_project_graph(force?) → optionally ingest → query graph. Output: package DAG; may require Lerna setup in the repo.
list_file_entitiesreadUse when: you have a file and need the exact entityId for follow-up graph tools. Typical flow: list_file_entities(filePath) → pick entityId → list_entity_relationships/analyze_code_impact. Output: entity list with locations/metadata; requires indexing.
list_module_importersreadUse when: you care about module-level dependents (who imports ./x). Typical flow: list_module_importers(moduleSource) → inspect importer files/entities. Output: importing files/entities; requires indexing.
queryreadUse when: you want a best-effort hybrid answer (semantic + structural) for discovery. Typical flow: query → refine with list_file_entities/list_entity_relationships/analyze_code_impact. Output: combined semantic and structural matches (semantic may be unavailable/disabled).
reset_graphdestructiveUse when: you need a clean slate (schema reset, corrupted index, or changing indexing config). Typical flow: reset_graph → clean_index/batch_index. Output: confirmation; destructive to indexed data.
resolve_entityreadUse when: a name is ambiguous and you need the correct entityId before deeper graph tools. Typical flow: resolve_entity(name, filePathHint) → pick entityId → get_entity_source/list_entity_relationships. Output: ranked candidates with reasons; requires indexing.
semantic_searchreadUse when: you want semantic discovery across the codebase. Typical flow: semantic_search → list_file_entities (for exact IDs) → list_entity_relationships. Output: ranked matches; semantic may be disabled; ground results with graph/source follow-ups.
suggest_refactoringreadUse when: you want refactoring suggestions for a file or snippet. Typical flow: identify target via semantic_search/query → suggest_refactoring(filePath, focusArea/entityId). Output: suggestions; validate against real code context.
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (6 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMInventory / provenance · inv.binary · CWE-1104
data/query_cache.db
query_cache.db
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/semantic/providers/ollama-provider.ts:28
this.baseUrl = opts.baseUrl ?? "http://127.0.0.1:11434";
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clean_index, clear_bus_topic, reset_graph
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/parsers/tree-sitter-parser.ts:257
const internalHash = createHash("sha1").update(content).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/vendor/jscpd/tokenizer/tokens-map.ts:8
createHash("md5").update(value).digest("hex").substring(0, TOKEN_HASH_LENGTH);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/semantic/__tests__/provider-mapping.test.ts:9
import { getConfig } from "../../config/yaml-config.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/semantic/providers/factory.ts:6
} from "../../types/semantic.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/semantic/providers/factory.ts:7
import { logger as appLogger } from "../../utils/logger.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/semantic/providers/factory.ts:8
import { makeProviderLogger } from "../../utils/provider-logger.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/storage/sqlite-manager.ts:143
const packageRoot = fileURLToPath(new URL("../../", import.meta.url));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@er77/code-graph-rag-mcp, @modelcontextprotocol/sdk, better-sqlite3, lru-cache, nanoid, sqlite-vec, tree-sitter-kotlin, yaml
Why it matters. 25 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ade3c7351bbdfull audit observations/trust-audit/mcp-server/er77__code-graph-rag.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ade3c7351bbdCAUTIONB83first audit
06

Questions

What tools does Code Graph RAG expose?

27 in total: 24 read-only, 0 that write, and 3 that can delete or overwrite (clean_index, clear_bus_topic, reset_graph). Every one is listed on this page with its risk.

Is Code Graph RAG safe to connect to an agent?

With care. The audit graded it B (83/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Code Graph RAG need?

It reads CLOUDRU_API_KEY, MCP_EMBEDDING_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Code Graph RAG run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @er77/code-graph-rag-mcp at 2.7.18.

How current is this page?

The grade is for one exact copy of the source (ade3c7351bbd), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement