Atlas / MCP servers / haasonsaas / Deep Code Reasoning

Deep Code ReasoningSAFE

mcp/haasonsaas/deep-code-reasoning

A Model Context Protocol (MCP) server that provides advanced code analysis and reasoning capabilities powered by Google's Gemini AI

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
10 8r · 2w · 0d
Transport
stdio
License
MIT
Stars
109
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.com) [](https://nodejs.org)

An MCP server that pairs Claude Code with Google's Gemini AI for complementary code analysis. This server enables a multi-model workflow where Claude Code handles tight terminal integration and multi-file refactoring, while Gemini leverages its massive context window (1M tokens) and code execution capabilities for distributed system debugging and long-trace analysis.

Core Value

Both Claude and Gemini can handle deep semantic reasoning and distributed system bugs. This server enables an intelligent routing strategy where:

  • Claude Code excels at local-context operations, incremental patches, and CLI-native workflows
  • Gemini 2.5 Pro shines with huge-context sweeps, synthetic test execution, and analyzing failures that span logs + traces + code

The "escalation" model treats LLMs like heterogeneous microservices - route to the one that's most capable for each sub-task.

Features

  • Gemini 2.5 Pro Preview: Uses Google's latest Gemini 2.5 Pro Preview (05-06) model with 1M token context window
  • Conversational Analysis: NEW! AI-to-AI dialogues between Claude and Gemini for iterative problem-solving
  • Execution Flow Tracing: Understands data flow and state transformations, not just function calls
  • Cross-System Impact Analysis: Models how changes propagate across service boundaries
  • Performance Modeling: Identifies N+1 patterns, memory leaks, and algorithmic bottlenecks
  • Hypothesis Testing: Tests theories about code behavior with evidence-based validation
  • Long Context Support: Leverages Gemini 2.5 Pro Preview's 1M token context for analyzing large codebases

Prerequisites

Read from source at commit fc7f12d7bb69OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add deep-code-reasoning-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "deep-code-reasoning-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (10)

8 read · 2 write · 0 destructive.

ToolRiskDescription
continue_conversationreadContinue an ongoing analysis conversation
cross_system_impactreadUse Gemini to analyze changes across service boundaries
escalate_analysisreadHand off complex analysis to Gemini when Claude Code hits reasoning limits. Gemini will perform deep semantic analysis beyond syntactic patterns.
finalize_conversationreadComplete the conversation and get final analysis results
get_conversation_statusreadCheck the status and progress of an ongoing conversation
hypothesis_testreadUse Gemini to test specific theories about code behavior
performance_bottleneckreadUse Gemini for deep performance analysis with execution modeling
run_hypothesis_tournamentwriteRun a competitive hypothesis tournament to find root causes. Multiple AI conversations test different theories in parallel, with evidence-based scoring and elimination rounds.
start_conversationwriteStart a conversational analysis session between Claude and Gemini
trace_execution_pathreadUse Gemini to perform deep execution analysis with semantic understanding
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google/generative-ai, @modelcontextprotocol/sdk, @types/node, dotenv, zod, @types/jest, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
SECURITY.md:69
**Attack Example**: A file named `auth.ts --- IGNORE ALL PREVIOUS INSTRUCTIONS ---` would break out of the file content context.
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
SECURITY.md:148
- Include "ignore all previous instructions" in various fields
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fc7f12d7bb69full audit observations/trust-audit/mcp-server/haasonsaas__deep-code-reasoning.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fc7f12d7bb69SAFEB89first audit
06

Questions

What is the Deep Code Reasoning MCP server?

A Model Context Protocol (MCP) server that provides advanced code analysis and reasoning capabilities powered by Google's Gemini AI

What tools does Deep Code Reasoning expose?

10 in total: 8 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Deep Code Reasoning safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Deep Code Reasoning need?

It reads ANTHROPIC_API_KEY and GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Deep Code Reasoning run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as deep-code-reasoning-mcp at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (fc7f12d7bb69), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement