Atlas / MCP servers / glitterkill / SDL

SDLBLOCK

mcp/glitterkill/sdl

Symbol Delta Ledger (SDL-MCP) is a policy-centered context budget layer for coding agents: Symbol-graph intelligence combined with precision tools. It turns sprawling codebases into compact, high-signal context that saves tokens, speeds up workflows, and improves agent output.

Verdict
BLOCK
Grade
F
Trust score
40 /100
Exposed tools
52 47r · 4w · 1d
Transport
sse · stdio · streamable-http
License
NOASSERTION
Stars
490
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Cards-first code context for AI coding agents.

Get started · Documentation · MCP tools · npm

[](https://roastmycode.ai/roast/latest/GlitterKill/sdl-mcp) [](https://github.com/GlitterKill/sdl-mcp/actions/workflows/ci.yml)

Work from the symbols that matter

SDL-MCP indexes a repository into a symbol graph and gives coding agents a controlled path from compact metadata to source code. Instead of starting with full files, an agent can search symbols, inspect cards, build a task-scoped slice, and request a bounded code window only when it needs one.

The result is a smaller, more deliberate context surface for debugging, reviews, implementation work, and repository exploration. SDL-MCP runs locally and supports the Model Context Protocol over stdio or HTTP.

Start in a few minutes

SDL-MCP requires Node.js 24 or later. For an interactive first install, run the wrapper package from the repository you want to index:

npx create-sdl-mcp

For a standard global install, initialize the repository, verify it, then start the stdio server:

npm install -g sdl-mcp
cd 
Read from source at commit 7a124b0ea950OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add sdl-mcp-watchman --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env NEURALWATT_API_KEY=${NEURALWATT_API_KEY} --env SDLBENCH_TIKTOKEN_SPEC=${SDLBENCH_TIKTOKEN_SPEC} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "sdl-mcp-watchman": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}",
        "NEURALWATT_API_KEY": "${NEURALWATT_API_KEY}",
        "SDLBENCH_TIKTOKEN_SPEC": "${SDLBENCH_TIKTOKEN_SPEC}"
      }
    }
  }
}
03

Exposed tools (52)

47 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
sdl.action.searchread
sdl.agentread
sdl.agent.feedbackread
sdl.agent.feedback.queryread
sdl.buffer.checkpointread
sdl.buffer.pushwrite
sdl.buffer.statusread
sdl.coderead
sdl.code.getHotPathread
sdl.code.getSkeletonread
sdl.code.needWindowread
sdl.contextread
sdl.context.summaryreadGenerate token-bounded context summary for a symbol, file, or task query
sdl.delta.getread
sdl.examplereadUnknown profile test
sdl.fileread
sdl.file.readreadRead a non-indexed file
sdl.file.writewriteFile write visibility test tool
sdl.index.refreshread
sdl.inforeadGet unified SDL-MCP runtime, config, logging, Ladybug, and native-addon status.
sdl.manualread
sdl.memory.queryread
sdl.memory.removedestructive
sdl.memory.storeread
sdl.memory.surfaceread
sdl.policy.getread
sdl.policy.setwrite
sdl.pr.risk.analyzeread
sdl.qualifiedreadQualified registration
sdl.queryread
sdl.reporead
sdl.repo.overviewread
sdl.repo.registerread
sdl.repo.statusread
sdl.repo.unregisterread
sdl.response.getread
sdl.retrieveread
sdl.runtime.executewrite
sdl.slice.buildread
sdl.slice.refreshread
sdl.slice.spillover.getread
sdl.symbol.getCardread
sdl.symbol.searchread
sdl.test.statusreadtest tool
sdl.test.toolreadA test tool
sdl.test.wirereaddesc
sdl.usage.statsread
sdl.workflowread
sdl_test_statusreadsafe test tool
tool-areaddesc-a
tool-breaddesc-b
tool-xreaddesc
04

Trust audit

BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/benchmark-hnsw-efc.ts:331
await exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/benchmark-hnsw-efc.ts:341
await exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/benchmark-hnsw-efc.ts:384
await exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/check-skin-template-sync.mjs:23
compiled = new Function(`return (${match[1]});`)();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/qualify-ladybug-driver.mjs:912
await exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/mcp/tools/search-edit/planner.ts:414
".netrc",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/mcp/tools/search-edit/planner.ts:420
/^(id_rsa|id_ed25519|id_ecdsa|id_dsa)(\.pub)?$|^\.(htpasswd|htaccess)$/;
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.binary · CWE-1104
sdl-mcp-vscode/sdl-mcp-vscode-0.10.0.vsix
sdl-mcp-vscode-0.10.0.vsix
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/benchmark.ts:279
console.log(`Average token reduction:   ${summary.avgReductionPct.toFixed(2)}%`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/benchmark.ts:564
console.log(`Token Efficiency:`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sdlbench/src/cli.mjs:76
console.log(`SDLBench viewer: http://127.0.0.1:${addressPort}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
sdlbench/src/sdlbench.mjs:1050
const baseUrl = "http://127.0.0.1:" + port;
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/cli/transport/http.ts:1
import { createReadStream, existsSync, statSync } from "fs";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/config/types.ts:1
import { z } from "zod";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/graph/layout/force-layout.ts:1
import { createHash } from "node:crypto";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/graph/layout/prng.ts:1
export function fnv1a32(input: string): number {
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/graph/layout/types.ts:1
export const LAYOUT_SCHEMA_VERSION = 1;
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
tests/unit/redact.test.ts:86
const input = "const aws = 'AKIA1234567890ABCDEF';";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
sdlbench/tests/fixtures/repo/tests/order-audit.test.mjs:7
const order = placeOrder(cart, { token: "tok_live_secret_123456" });
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/integration/workflow-projection.test.ts:486
{ stepIndex: 0, fn: "okStep", status: "ok", result: { secret: "serialized-step-result" }, tokens: 1, durationMs: 1 },
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/code-mode-workflow-executor.test.ts:1408
const secret = "private-compact-omission".repeat(200);
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/redact.test.ts:98
const input = 'api_key = "abcdefghijklmnopqrstuvwx"';
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/unit/redact.test.ts:92
const input = "const gh = 'ghp_abcdefghijklmnopqrstuvwxyz0123456789';";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/unit/runtime-artifacts.test.ts:139
const content = "auth ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij end";
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/unit/redact.test.ts:122
const input = "-----BEGIN RSA PRIVATE KEY-----\n...";

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 7a124b0ea950full audit observations/trust-audit/mcp-server/glitterkill__sdl.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-307a124b0ea950BLOCKF40first audit
06

Questions

What is the SDL MCP server?

Symbol Delta Ledger (SDL-MCP) is a policy-centered context budget layer for coding agents: Symbol-graph intelligence combined with precision tools. It turns sprawling codebases into compact, high-signal context that saves tokens, speeds up workflows, and improves agent output.

What tools does SDL expose?

52 in total: 47 read-only, 4 that write, and 1 that can delete or overwrite (sdl.memory.remove). Every one is listed on this page with its risk.

Is SDL safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (40/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does SDL need?

It reads ANTHROPIC_API_KEY, GITHUB_TOKEN, NEURALWATT_API_KEY, SDLBENCH_TIKTOKEN_SPEC, SDL_LADYBUG_QUALIFICATION_AUTHORITY_NONCE, SDL_LADYBUG_QUALIFICATION_AUTHORITY_PATH, SDL_MCP_PASS1_STABLE_DB_WRITES, SDL_PACKED_TOKEN_THRESHOLD, SDL_TEST_SECRET and SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SDL run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as sdl-mcp-watchman at 0.13.7.

How current is this page?

The grade is for one exact copy of the source (7a124b0ea950), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement