Atlas / MCP servers / ferdinandobons / CodeDebrief

CodeDebriefCAUTION

mcp/ferdinandobons/codedebrief

Local-first static analysis that turns source code into deterministic, source-grounded workflow maps for coding agents via MCP.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
9 7r · 2w · 0d
Transport
stdio
License
Apache-2.0
Stars
42
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Source-grounded workflow diagrams for coding agents and codebase exploration.

Website · Quick Start · Agent Workflow · Manual Viewer · Changelog

CodeDebrief turns a local codebase into deterministic workflow flowcharts that coding agents can inspect, render, expand, translate, and explain. It statically maps entrypoints, decisions, branches, internal calls, returns, exceptions, and outcomes before the agent answers, so the visual explanation is grounded in reusable artifacts instead of a fresh best-effort reconstruction.

The analyzer, artifacts, viewer, and MCP server are local-first and do not require an LLM provider key. CodeDebrief is not a documentation generator, a bug finder, a generic graph database, or an LLM enrichment service; it is a workflow navigation layer for understanding how code paths actually connect.

Example output: a compact presentation layer generated from local CodeDebrief artifacts. Canonical workflow visuals are vertical by default; horizontal diagrams are used when the user explic

Read from source at commit 7f9091b0ad24OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add codedebrief-viewer-workspace -- npx -y codedebrief-viewer-workspace
claude-desktop
{
  "mcpServers": {
    "codedebrief-viewer-workspace": {
      "command": "npx",
      "args": [
        "-y",
        "codedebrief-viewer-workspace"
      ]
    }
  }
}
03

Exposed tools (9)

7 read · 2 write · 0 destructive.

ToolRiskDescription
agent_contextreadPrimary agent entrypoint for code-logic questions and change impact.
expand_slicereadWiden or deepen a workflow slice from stable flow handles.
explain_edgereadExplain one flowchart edge or modeled call edge with source context.
explain_flowreadExplain one flow with source anchors, decisions, calls, and next tools.
explain_nodereadExplain one flowchart node with local edge and source context.
snapshot_slicereadRender a deterministic visual snapshot for a workflow slice.
update_codedebriefwriteRefresh CodeDebrief after source changes and write JSON, Markdown, and HTML.
validate_artifactswriteValidate the generated model and optionally check source sync.
workflow_pathreadTrace a deterministic workflow path between two flows, symbols, or concepts.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
src/codedebrief/render/payload.py
payload.py
Why it matters. member named after an attack tool
Fix. remove or justify
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/codedebrief/cli.py:704
url = f"http://127.0.0.1:{port}/{html_path.name}"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codedebriefignore
.codedebriefignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@xyflow/react, elkjs, react, react-dom, zustand, @types/react, @types/react-dom, @vitejs/plugin-react
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
codedebrief-out/codedebrief.json
codedebrief-out/codedebrief.json
Why it matters. 7142362 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7f9091b0ad24full audit observations/trust-audit/mcp-server/ferdinandobons__codedebrief.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087f9091b0ad24CAUTIONB89first audit
06

Questions

What is the CodeDebrief MCP server?

Local-first static analysis that turns source code into deterministic, source-grounded workflow maps for coding agents via MCP.

What tools does CodeDebrief expose?

9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CodeDebrief safe to connect to an agent?

With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does CodeDebrief need?

No credential environment variables were found in its source, so it appears to need none.

How does CodeDebrief run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as codedebrief-viewer-workspace.

How current is this page?

The grade is for one exact copy of the source (7f9091b0ad24), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement