Atlas / MCP servers / giancarloerra / Socraticode

SocraticodeSAFE

mcp/giancarloerra/socraticode

Enterprise-grade (40m+ LOC) codebase intelligence, zero-setup, local & private Plugin/Skill/Extension or MCP: hybrid semantic search, polyglot dependency graphs, symbol-level impact analysis & call-flow, interactive HTML viewer, cross-project & branch-aware search, DB/API/infra knowledge. 61% less t

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
30 23r · 4w · 3d
Transport
stdio
License
AGPL-3.0
Stars
3,319
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

= 18.17">

Read from source at commit e1a11a896e7bOBSERVED · 2026-09-22
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add socraticode --env OPENAI_API_KEY=${OPENAI_API_KEY} --env GOOGLE_API_KEY=${GOOGLE_API_KEY} --env OLLAMA_API_KEY=${OLLAMA_API_KEY} --env LMSTUDIO_API_KEY=${LMSTUDIO_API_KEY} -- npx -y [email protected]
03

Exposed tools (30)

23 read · 4 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
changedreadChanged artifact
codebase_aboutreadDisplay information about SocratiCode — what it is, its tools and how to use it. Use this to get a quick overview of the MCP tools and their purpose.
codebase_contextreadList all context artifacts defined in .socraticodecontextartifacts.json — database schemas, API specs, infra configs, architecture docs, etc. Shows each artifact
codebase_context_indexreadIndex or re-index all context artifacts defined in .socraticodecontextartifacts.json. Chunks and embeds artifact content into the vector database for semantic search. Usually not needed — codebase_context_search auto-indexes on first use.
codebase_context_removedestructiveRemove all indexed context artifacts for a project from the vector database. Blocked while indexing is in progress — use codebase_stop or wait for the operation to finish first.
codebase_context_searchreadSemantic search across context artifacts (database schemas, API specs, infra configs, etc.) defined in .socraticodecontextartifacts.json. Auto-indexes on first use and auto-detects stale artifacts. Use this to find relevant infrastructure or domain knowledge.
codebase_flowreadTrace the EXECUTION FLOW forward from an entry point — what does this code call into? With NO args, returns a ranked list of auto-detected entry points (orphans with outgoing calls, conventional names like main(), framework routes, tests). With an entrypoint argument, returns the call tree.
codebase_graph_buildreadBuild a dependency graph of the codebase using static analysis (ast-grep). Maps import/require/export relationships between files. Runs in the background — call codebase_graph_status to poll progress until complete.
codebase_graph_circularreadFind circular dependencies in the codebase.
codebase_graph_queryreadQuery the code dependency graph for a specific file. Returns what the file imports and what files depend on it.
codebase_graph_removedestructiveRemove a project
codebase_graph_statsreadGet statistics about the code dependency graph: total files, edges, most connected files, orphan files, circular dependencies.
codebase_graph_statusreadCheck the status of the code dependency graph: build progress (if building), node/edge count, when it was last built, whether it
codebase_graph_visualizeread
codebase_healthreadCheck the health of all infrastructure: Docker, Qdrant container, Ollama, and embedding model. Use this to diagnose setup issues.
codebase_impactreadImpact Analysis — return the BLAST RADIUS for a file or symbol. Lists every file (and, where helpful, function) that could break if you change the target. Polymorphic on target: a path-like string (
codebase_indexwriteStart indexing a codebase in the background. Returns immediately. Call codebase_status to poll progress until 100%. Do NOT search until indexing is complete. If already indexing, returns current progress.
codebase_list_projectsreadList all projects that have been indexed (have collections in Qdrant).
codebase_prunereadInventory stored project identities and their resources. Report-only by default. Applying requires an exact identity, the confirmation token from a fresh inventory, and an acknowledgement that no other host is writing to it; path absence on this host is advisory, not proof of abandonment.
codebase_removedestructiveRemove a project
codebase_searchreadSemantic search across an indexed codebase. Only use after codebase_index is complete (check codebase_status first). Returns relevant code chunks matching a natural language query.
codebase_statusreadCheck index status: chunk count, indexing progress (%), last completed operation, file watcher state. Call after codebase_index to poll until 100% complete.
codebase_stopwriteGracefully stop an in-progress indexing operation. The current batch will finish and checkpoint, preserving all progress. Re-run codebase_index to resume from where it left off.
codebase_symbolread360° view of a symbol: definition, kind, callers, callees, confidence levels. Use to understand a function or class before changing it.
codebase_symbolsreadList symbols in a file, or search by name across the project. Use to discover what exists before drilling into a single symbol with codebase_symbol.
codebase_updatewriteIncrementally update an existing codebase index. Only re-indexes changed files. Runs synchronously. Use it to refresh a manual/off snapshot, or whenever an immediate catch-up is needed.
codebase_watchwriteStart/stop watching a project directory for file changes and automatically update the index. When starting, first runs an incremental update to catch up, then watches for changes. SOCRATICODE_WATCHER=manual allows explicit starts only; off rejects starts.
referencereadReference documentation
samereadSame artifact
schemareadDB
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
codebase_context_remove, codebase_graph_remove, codebase_remove
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coderabbit.yaml
.coderabbit.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-it.json
.release-it.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.socraticodecontextartifacts.json.example
.socraticodecontextartifacts.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.socraticodeignore.example
.socraticodeignore.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
extension/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/full-workflow.test.ts:25
import { invalidateGraphCache } from "../../src/services/code-graph.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/full-workflow.test.ts:26
import { stopAllWatchers } from "../../src/services/watcher.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/full-workflow.test.ts:27
import { handleGraphTool } from "../../src/tools/graph-tools.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/full-workflow.test.ts:28
import { handleIndexTool } from "../../src/tools/index-tools.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/e2e/full-workflow.test.ts:29
import { handleManageTool } from "../../src/tools/manage-tools.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:64
if curl --connect-timeout 1 --max-time 2 -fsS http://127.0.0.1:6333/healthz >/dev/null; then
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:81
QDRANT_MODE=external QDRANT_URL=http://127.0.0.1:6333 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:121
if curl --connect-timeout 1 --max-time 2 -fsS http://127.0.0.1:6333/healthz >/dev/null; then
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:130
QDRANT_URL=http://127.0.0.1:6333 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/ci.yml:145
if curl --connect-timeout 1 --max-time 2 -fsS http://127.0.0.1:6333/healthz >/dev/null; then
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
extension/package.json
@biomejs/biome, @types/node, @types/vscode, @vscode/vsce, esbuild, ovsx, tsx, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@ast-grep/lang-bash, @ast-grep/lang-c, @ast-grep/lang-cpp, @ast-grep/lang-csharp, @ast-grep/lang-dart, @ast-grep/lang-elixir, @ast-grep/lang-go, @ast-grep/lang-java
Why it matters. 43 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
socraticode_logo.png
socraticode_logo.png
Why it matters. 1970981 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha e1a11a896e7bfull audit observations/trust-audit/mcp-server/giancarloerra__socraticode.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-22e1a11a896e7bSAFEB89source changed, verdict held
2026-09-18fdafd68090a0SAFEB89first audit
06

Questions

What is the Socraticode MCP server?

Enterprise-grade (40m+ LOC) codebase intelligence, zero-setup, local & private Plugin/Skill/Extension or MCP: hybrid semantic search, polyglot dependency graphs, symbol-level impact analysis & call-flow, interactive HTML viewer, cross-project & branch-aware search, DB/API/infra knowledge. 61% less t

What tools does Socraticode expose?

30 in total: 23 read-only, 4 that write, and 3 that can delete or overwrite (codebase_context_remove, codebase_graph_remove, codebase_remove). Every one is listed on this page with its risk.

Is Socraticode safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Socraticode need?

It reads GOOGLE_API_KEY, LITELLM_API_KEY, LMSTUDIO_API_KEY, OLLAMA_API_KEY, OPENAI_API_KEY and QDRANT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Socraticode run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as socraticode at 1.14.0.

How current is this page?

The grade is for one exact copy of the source (e1a11a896e7b), read on 2026-09-22. The repository is watched and re-audited when it changes.

Advertisement