Atlas / MCP servers / gulp-ai / CodeMerge

CodeMergeSAFE

mcp/gulp-ai/codemerge

A mcp server that uses the Osmosis-Apply-1.7B model to apply code merges

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 0r · 1w · 0d
Transport
stdio
License
—
Stars
52
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that uses the Osmosis-Apply-1.7B model to merge code edits.

  • Code Merging: Uses the Osmosis/Osmosis-Apply-1.7B model to apply edits
  • MCP Integration: Works as a Model Context Protocol server to integrate into existing AI IDE solutions
  • File Operations: Can directly edit files in place or return edited code

Installation

Prerequisites

  • Python 3.10 or higher
  • Ollama installed and running
  • The Osmosis model pulled: ollama pull Osmosis/Osmosis-Apply-1.7B

Setup

  1. Clone the repository:
git clone 
cd codemerge
  1. Install dependencies using uv:
uv sync
  1. Run:
uv run python codemerge.py

Usage

As an MCP Server

CodeMerge can be used as an MCP server. Configure it in your MCP client:

{
"mcpServers": {
"codemerge": {
"command": "uv",
"args": [
"--directory",
"/path/to/codemerge",
"run",
"codemerge.py"
]
}
}
}

Direct Usage

You can also use CodeMerge directly in Python:

from call_snippet import apply_code_edit

# Original code
original_code = """def hello():
print('Hello, World!')
print('Some code')
print('Some more code')
return 'success'"""

# Edit to apply
edit_snippet = """def hello():
print('Hello, Universe!')
print('Some code')
# ... existing code ...
return 'success'"""

# Apply the edit
result = apply_code_edit(original_code, edit_snippet)
print(result)

MCP Tool Usage

The MCP server provides an edit_snippet tool with the following parameters:

  • original_code: The exact original code to be edited
  • edit_snippet: The edit to apply, using // ... existing code ... markers
  • file_path: Absolute path to a file to update in place

Example tool call:

{
"name": "edit_snippet",
"arguments": {
"original_code": "def hello():\n    print('Hello, World!')",
Read from source at commit a49f4c92565fOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add codemerge -- uvx codemerge
claude-desktop
{
  "mcpServers": {
    "codemerge": {
      "command": "uvx",
      "args": [
        "codemerge"
      ]
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
edit_snippetwriteApply an edit to a code snippet using the Osmosis model
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha a49f4c92565ffull audit observations/trust-audit/mcp-server/gulp-ai__codemerge.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a49f4c92565fSAFEB89first audit
06

Questions

What is the CodeMerge MCP server?

A mcp server that uses the Osmosis-Apply-1.7B model to apply code merges

What tools does CodeMerge expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CodeMerge safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does CodeMerge need?

No credential environment variables were found in its source, so it appears to need none.

How does CodeMerge run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as codemerge.

How current is this page?

The grade is for one exact copy of the source (a49f4c92565f), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement