SDLBLOCK
Symbol Delta Ledger (SDL-MCP) is a policy-centered context budget layer for coding agents: Symbol-graph intelligence combined with precision tools. It turns sprawling codebases into compact, high-signal context that saves tokens, speeds up workflows, and improves agent output.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Cards-first code context for AI coding agents.
Get started · Documentation · MCP tools · npm
[](https://roastmycode.ai/roast/latest/GlitterKill/sdl-mcp) [](https://github.com/GlitterKill/sdl-mcp/actions/workflows/ci.yml)
Work from the symbols that matter
SDL-MCP indexes a repository into a symbol graph and gives coding agents a controlled path from compact metadata to source code. Instead of starting with full files, an agent can search symbols, inspect cards, build a task-scoped slice, and request a bounded code window only when it needs one.
The result is a smaller, more deliberate context surface for debugging, reviews, implementation work, and repository exploration. SDL-MCP runs locally and supports the Model Context Protocol over stdio or HTTP.
Start in a few minutes
SDL-MCP requires Node.js 24 or later. For an interactive first install, run the wrapper package from the repository you want to index:
npx create-sdl-mcp
For a standard global install, initialize the repository, verify it, then start the stdio server:
npm install -g sdl-mcp cd
7a124b0ea950OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sdl-mcp-watchman --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env NEURALWATT_API_KEY=${NEURALWATT_API_KEY} --env SDLBENCH_TIKTOKEN_SPEC=${SDLBENCH_TIKTOKEN_SPEC} -- npx -y [email protected]{
"mcpServers": {
"sdl-mcp-watchman": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}",
"NEURALWATT_API_KEY": "${NEURALWATT_API_KEY}",
"SDLBENCH_TIKTOKEN_SPEC": "${SDLBENCH_TIKTOKEN_SPEC}"
}
}
}
}Exposed tools (52)
47 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
sdl.action.search | read | |
sdl.agent | read | |
sdl.agent.feedback | read | |
sdl.agent.feedback.query | read | |
sdl.buffer.checkpoint | read | |
sdl.buffer.push | write | |
sdl.buffer.status | read | |
sdl.code | read | |
sdl.code.getHotPath | read | |
sdl.code.getSkeleton | read | |
sdl.code.needWindow | read | |
sdl.context | read | |
sdl.context.summary | read | Generate token-bounded context summary for a symbol, file, or task query |
sdl.delta.get | read | |
sdl.example | read | Unknown profile test |
sdl.file | read | |
sdl.file.read | read | Read a non-indexed file |
sdl.file.write | write | File write visibility test tool |
sdl.index.refresh | read | |
sdl.info | read | Get unified SDL-MCP runtime, config, logging, Ladybug, and native-addon status. |
sdl.manual | read | |
sdl.memory.query | read | |
sdl.memory.remove | destructive | |
sdl.memory.store | read | |
sdl.memory.surface | read | |
sdl.policy.get | read | |
sdl.policy.set | write | |
sdl.pr.risk.analyze | read | |
sdl.qualified | read | Qualified registration |
sdl.query | read | |
sdl.repo | read | |
sdl.repo.overview | read | |
sdl.repo.register | read | |
sdl.repo.status | read | |
sdl.repo.unregister | read | |
sdl.response.get | read | |
sdl.retrieve | read | |
sdl.runtime.execute | write | |
sdl.slice.build | read | |
sdl.slice.refresh | read | |
sdl.slice.spillover.get | read | |
sdl.symbol.getCard | read | |
sdl.symbol.search | read | |
sdl.test.status | read | test tool |
sdl.test.tool | read | A test tool |
sdl.test.wire | read | desc |
sdl.usage.stats | read | |
sdl.workflow | read | |
sdl_test_status | read | safe test tool |
tool-a | read | desc-a |
tool-b | read | desc-b |
tool-x | read | desc |
Trust audit
BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
await exec(
await exec(
await exec(
compiled = new Function(`return (${match[1]});`)();await exec(
".netrc",
/^(id_rsa|id_ed25519|id_ecdsa|id_dsa)(\.pub)?$|^\.(htpasswd|htaccess)$/;
sdl-mcp-vscode-0.10.0.vsix
console.log(`Average token reduction: ${summary.avgReductionPct.toFixed(2)}%`);console.log(`Token Efficiency:`);
console.log(`SDLBench viewer: http://127.0.0.1:${addressPort}`);const baseUrl = "http://127.0.0.1:" + port;
import { createReadStream, existsSync, statSync } from "fs";import { z } from "zod";import { createHash } from "node:crypto";export function fnv1a32(input: string): number {export const LAYOUT_SCHEMA_VERSION = 1;
const input = "const aws = 'AKIA1234567890ABCDEF';";
const order = placeOrder(cart, { token: "tok_live_secret_123456" });{ stepIndex: 0, fn: "okStep", status: "ok", result: { secret: "serialized-step-result" }, tokens: 1, durationMs: 1 },const secret = "private-compact-omission".repeat(200);
const input = 'api_key = "abcdefghijklmnopqrstuvwx"';
const input = "const gh = 'ghp_abcdefghijklmnopqrstuvwxyz0123456789';";
const content = "auth ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij end";
const input = "-----BEGIN RSA PRIVATE KEY-----\n...";
Gates applied: no_behavioural_pass.
7a124b0ea950full audit observations/trust-audit/mcp-server/glitterkill__sdl.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 7a124b0ea950 | BLOCK | F | 40 | first audit |
Questions
What is the SDL MCP server?
Symbol Delta Ledger (SDL-MCP) is a policy-centered context budget layer for coding agents: Symbol-graph intelligence combined with precision tools. It turns sprawling codebases into compact, high-signal context that saves tokens, speeds up workflows, and improves agent output.
What tools does SDL expose?
52 in total: 47 read-only, 4 that write, and 1 that can delete or overwrite (sdl.memory.remove). Every one is listed on this page with its risk.
Is SDL safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (40/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does SDL need?
It reads ANTHROPIC_API_KEY, GITHUB_TOKEN, NEURALWATT_API_KEY, SDLBENCH_TIKTOKEN_SPEC, SDL_LADYBUG_QUALIFICATION_AUTHORITY_NONCE, SDL_LADYBUG_QUALIFICATION_AUTHORITY_PATH, SDL_MCP_PASS1_STABLE_DB_WRITES, SDL_PACKED_TOKEN_THRESHOLD, SDL_TEST_SECRET and SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SDL run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as sdl-mcp-watchman at 0.13.7.
How current is this page?
The grade is for one exact copy of the source (7a124b0ea950), read on 2026-09-30. The repository is watched and re-audited when it changes.