Code Graph RAGCAUTION
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Project is obsolete and canceled
ade3c7351bbdOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add code-graph-rag-mcp --env CLOUDRU_API_KEY=${CLOUDRU_API_KEY} --env MCP_EMBEDDING_API_KEY=${MCP_EMBEDDING_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y @er77/[email protected]{
"mcpServers": {
"code-graph-rag-mcp": {
"command": "npx",
"args": [
"-y",
"@er77/[email protected]"
],
"env": {
"CLOUDRU_API_KEY": "${CLOUDRU_API_KEY}",
"MCP_EMBEDDING_API_KEY": "${MCP_EMBEDDING_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (27)
24 read · 0 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_code_impact | read | Use when: you need a reverse-dependency view (who uses/depends on this). Typical flow: list_file_entities → analyze_code_impact(entityId, filePath hint) → inspect affected files. Output: dependents and affected files; requires indexing. |
analyze_hotspots | read | Use when: you want a quick list of risky areas (complexity/changes/coupling). Typical flow: analyze_hotspots(metric) → inspect top files/entities → suggest_refactoring. Output: ranked hotspots with the chosen metric. |
batch_index | read | Use when: you need reliable indexing on strict clients/timeouts. Typical flow: batch_index(reset:true) → keep calling batch_index(sessionId) until done:true. Output: progress + stats + next arguments; returns sessionId for resumable sessions. |
clean_index | destructive | Use when: you want a guaranteed clean rebuild (reset + full index). Typical flow: clean_index → query/semantic_search. Output: indexing result; may time out on strict clients—use batch_index if needed. |
clear_bus_topic | destructive | Use when: you need to invalidate cached knowledge bus entries for a topic. Typical flow: get_bus_stats → clear_bus_topic(topic). Output: confirmation + updated stats. |
cross_language_search | read | Use when: you want discovery constrained to specific languages. Typical flow: cross_language_search(query, languages) → open results → list_file_entities. Output: results filtered by language set; semantic must be available for best quality. |
detect_code_clones | read | Use when: you want semantic clone groups across the codebase. Typical flow: detect_code_clones → prioritize hotspots → suggest_refactoring. Output: clone groups; consider jscpd_detect_clones for fast tokenizer-based scanning. |
find_related_concepts | read | Use when: you want conceptually related code for an entity (semantic neighbors). Typical flow: list_file_entities → find_related_concepts(entityId) → open candidates. Output: related entities/snippets; semantic must be available. |
find_similar_code | read | Use when: you have a snippet and want near-duplicate or conceptually similar code. Typical flow: find_similar_code → open candidate file(s) → suggest_refactoring/detect_code_clones. Output: ranked similar snippets with scores (semantic must be available). |
get_agent_metrics | read | Use when: you need per-agent telemetry (queues, memory, CPU) to debug slow/failed tool calls. Typical flow: get_agent_metrics → adjust concurrency/memory limits. Output: agent snapshots and coordinator metrics. |
get_bus_stats | read | Use when: you need to debug caching/events and topic growth. Typical flow: get_bus_stats → clear_bus_topic for hot/large topics. Output: topic/entry/subscription counts. |
get_entity_source | read | Use when: you need the exact source snippet for an entity to ground answers. Typical flow: resolve_entity/list_file_entities → get_entity_source(entityId, contextLines) → analyze_code_impact. Output: snippet + line ranges; requires file access and indexing. |
get_graph | read | Use when: you need a bounded snapshot of entities and relationships for inspection/debugging. Avoid when: exporting entire large graphs—use a query filter/limit. Output: entities + relations + stats; requires indexing. |
get_graph_health | read | Use when: you need to verify DB health (counts + sample read). Typical flow: get_graph_health → if unhealthy, clean_index/reset_graph. Output: health status, totals, and sample verification. |
get_graph_stats | read | Use when: you need counts/summary stats for the indexed graph. Typical flow: get_graph_stats → get_graph_health if counts look suspicious. Output: counts and DB metrics; requires indexing. |
get_metrics | read | Use when: you need runtime resource usage and agent queue snapshots for debugging. Typical flow: get_metrics → get_agent_metrics for deeper agent telemetry. Output: CPU/memory/resource manager + knowledge bus stats. |
get_version | read | Use when: you need server version/runtime info (node/platform/memory/uptime) for debugging. Output: version + runtime details; does not require indexing. |
index | read | Use when: you want a one-shot index of a repo and your client can tolerate a long-running tool call. Avoid when: strict transports may time out—use batch_index instead. Typical flow: clean_index → index or batch_index. Output: JSON status + counts; indexing is required for most graph tools. |
jscpd_detect_clones | read | Use when: you want fast, tokenizer-based duplicate detection (no embeddings). Typical flow: jscpd_detect_clones(paths, formats) → review clone blocks → refactor. Output: clone blocks with locations; best for quick duplication sweeps. |
lerna_project_graph | read | Use when: you want a package/workspace dependency graph from Lerna config. Typical flow: lerna_project_graph(force?) → optionally ingest → query graph. Output: package DAG; may require Lerna setup in the repo. |
list_file_entities | read | Use when: you have a file and need the exact entityId for follow-up graph tools. Typical flow: list_file_entities(filePath) → pick entityId → list_entity_relationships/analyze_code_impact. Output: entity list with locations/metadata; requires indexing. |
list_module_importers | read | Use when: you care about module-level dependents (who imports ./x). Typical flow: list_module_importers(moduleSource) → inspect importer files/entities. Output: importing files/entities; requires indexing. |
query | read | Use when: you want a best-effort hybrid answer (semantic + structural) for discovery. Typical flow: query → refine with list_file_entities/list_entity_relationships/analyze_code_impact. Output: combined semantic and structural matches (semantic may be unavailable/disabled). |
reset_graph | destructive | Use when: you need a clean slate (schema reset, corrupted index, or changing indexing config). Typical flow: reset_graph → clean_index/batch_index. Output: confirmation; destructive to indexed data. |
resolve_entity | read | Use when: a name is ambiguous and you need the correct entityId before deeper graph tools. Typical flow: resolve_entity(name, filePathHint) → pick entityId → get_entity_source/list_entity_relationships. Output: ranked candidates with reasons; requires indexing. |
semantic_search | read | Use when: you want semantic discovery across the codebase. Typical flow: semantic_search → list_file_entities (for exact IDs) → list_entity_relationships. Output: ranked matches; semantic may be disabled; ground results with graph/source follow-ups. |
suggest_refactoring | read | Use when: you want refactoring suggestions for a file or snippet. Typical flow: identify target via semantic_search/query → suggest_refactoring(filePath, focusArea/entityId). Output: suggestions; validate against real code context. |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
query_cache.db
this.baseUrl = opts.baseUrl ?? "http://127.0.0.1:11434";
clean_index, clear_bus_topic, reset_graph
const internalHash = createHash("sha1").update(content).digest("hex");createHash("md5").update(value).digest("hex").substring(0, TOKEN_HASH_LENGTH);import { getConfig } from "../../config/yaml-config.js";} from "../../types/semantic.js";
import { logger as appLogger } from "../../utils/logger.js";import { makeProviderLogger } from "../../utils/provider-logger.js";const packageRoot = fileURLToPath(new URL("../../", import.meta.url));@er77/code-graph-rag-mcp, @modelcontextprotocol/sdk, better-sqlite3, lru-cache, nanoid, sqlite-vec, tree-sitter-kotlin, yaml
Gates applied: no_behavioural_pass.
ade3c7351bbdfull audit observations/trust-audit/mcp-server/er77__code-graph-rag.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ade3c7351bbd | CAUTION | B | 83 | first audit |
Questions
What tools does Code Graph RAG expose?
27 in total: 24 read-only, 0 that write, and 3 that can delete or overwrite (clean_index, clear_bus_topic, reset_graph). Every one is listed on this page with its risk.
Is Code Graph RAG safe to connect to an agent?
With care. The audit graded it B (83/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Code Graph RAG need?
It reads CLOUDRU_API_KEY, MCP_EMBEDDING_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Code Graph RAG run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @er77/code-graph-rag-mcp at 2.7.18.
How current is this page?
The grade is for one exact copy of the source (ade3c7351bbd), read on 2026-10-07. The repository is watched and re-audited when it changes.