CodeDebriefCAUTION
Local-first static analysis that turns source code into deterministic, source-grounded workflow maps for coding agents via MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Source-grounded workflow diagrams for coding agents and codebase exploration.
Website · Quick Start · Agent Workflow · Manual Viewer · Changelog
CodeDebrief turns a local codebase into deterministic workflow flowcharts that coding agents can inspect, render, expand, translate, and explain. It statically maps entrypoints, decisions, branches, internal calls, returns, exceptions, and outcomes before the agent answers, so the visual explanation is grounded in reusable artifacts instead of a fresh best-effort reconstruction.
The analyzer, artifacts, viewer, and MCP server are local-first and do not require an LLM provider key. CodeDebrief is not a documentation generator, a bug finder, a generic graph database, or an LLM enrichment service; it is a workflow navigation layer for understanding how code paths actually connect.
Example output: a compact presentation layer generated from local CodeDebrief artifacts. Canonical workflow visuals are vertical by default; horizontal diagrams are used when the user explic
7f9091b0ad24OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add codedebrief-viewer-workspace -- npx -y codedebrief-viewer-workspace
{
"mcpServers": {
"codedebrief-viewer-workspace": {
"command": "npx",
"args": [
"-y",
"codedebrief-viewer-workspace"
]
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
agent_context | read | Primary agent entrypoint for code-logic questions and change impact. |
expand_slice | read | Widen or deepen a workflow slice from stable flow handles. |
explain_edge | read | Explain one flowchart edge or modeled call edge with source context. |
explain_flow | read | Explain one flow with source anchors, decisions, calls, and next tools. |
explain_node | read | Explain one flowchart node with local edge and source context. |
snapshot_slice | read | Render a deterministic visual snapshot for a workflow slice. |
update_codedebrief | write | Refresh CodeDebrief after source changes and write JSON, Markdown, and HTML. |
validate_artifacts | write | Validate the generated model and optionally check source sync. |
workflow_path | read | Trace a deterministic workflow path between two flows, symbols, or concepts. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
payload.py
url = f"http://127.0.0.1:{port}/{html_path.name}".codedebriefignore
.nojekyll
@xyflow/react, elkjs, react, react-dom, zustand, @types/react, @types/react-dom, @vitejs/plugin-react
codedebrief-out/codedebrief.json
Gates applied: no_behavioural_pass.
7f9091b0ad24full audit observations/trust-audit/mcp-server/ferdinandobons__codedebrief.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7f9091b0ad24 | CAUTION | B | 89 | first audit |
Questions
What is the CodeDebrief MCP server?
Local-first static analysis that turns source code into deterministic, source-grounded workflow maps for coding agents via MCP.
What tools does CodeDebrief expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CodeDebrief safe to connect to an agent?
With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does CodeDebrief need?
No credential environment variables were found in its source, so it appears to need none.
How does CodeDebrief run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as codedebrief-viewer-workspace.
How current is this page?
The grade is for one exact copy of the source (7f9091b0ad24), read on 2026-10-08. The repository is watched and re-audited when it changes.