Atlas / MCP servers / handsomestwei / Java Class Analyzer

Java Class AnalyzerSAFE

mcp/handsomestwei/java-class-analyzer

java class反编译mcp server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
Apache-2.0
Stars
44
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

一个基于Model Context Protocol (MCP)的Java类分析服务,可以扫描Maven项目依赖、反编译Java类文件、获取class方法列表等详细信息,并提供给LLM进行代码分析。

适用场景

Cursor等AI工具直接生成调用二方(内部调用)、三方包(外部调用)接口的代码,但因AI无法读取未在当前工程中打开的依赖源码,导致生成的代码错误频出,甚至出现幻觉式编码。

为解决此问题,一般会直接拷贝源码内容喂给LLM;或者先将源码文件放到当前工程内,再在对话中引用。

而使用本地反编译MCP方案最有效,能精准解析jar包中的类与方法,显著提升代码生成的准确性和可用性。

功能特性

  • 🚀使用方便:mcp服务基于TypeScript实现,使用npm打包,方便分发和安装,弱环境依赖。
  • 🔍 依赖扫描: 自动扫描Maven项目的所有依赖JAR包
  • 📦 类索引: 建立类全名到JAR包路径的映射索引
  • 🔄 反编译: 使用CFR工具(已内置有)实时反编译.class文件为Java源码
  • 📊 类分析: 分析Java类的结构、方法、字段、继承关系等
  • 💾 智能缓存: 按包名结构缓存反编译结果,支持缓存控制
  • 🚀 自动索引: 执行分析前自动检查并创建索引
  • ⚙️ 灵活配置: 支持外部指定CFR工具路径
  • 🤖 LLM集成: 通过MCP协议为LLM提供Java代码分析能力

使用示例

在IDE中注册mcp服务

在智能体对话中使用mcp

使用说明

mcp服务安装

全局安装(推荐)

npm install -g java-class-analyzer-mcp-server

安装后可以直接使用 java-class-analyzer-mcp 命令。

本地安装

npm install java-class-analyzer-mcp-server

从源码安装

git clone https://github.com/handsomestWei/java-class-analyzer-mcp-server.git
cd java-class-analyzer-mcp-server
npm install
npm run build

MCP服务配置

方法1:使用生成的配置(推荐)

运行以下命令生成配置模板:

java-class-analyzer-mcp config -o mcp-client-config.json

然后将生成的配置内容添加到你的MCP客户端配置文件中。

方法2:手动配置

参考以下配置示例,添加到MCP客户端配置文件中:

全局安装后的配置:

{
"mcpServers": {
"java-class-analyzer": {
"command": "java-class-analyzer-mcp",
"args": ["start"],
"env": {
"NODE_ENV": "production",
"MAVEN_REPO": "D:/maven/repository",
"JAVA_HOME": "C:/Program Files/Java/jdk-11"
}
}
}
}

本地安装后的配置:

{
"mcpServers": {
"java-class-analyzer": {
"command": "node",
"args": [
"node_modules/java-class-analyzer-mcp-server/dist/index.js"
],
"env": {
"NODE_ENV": "production",
Read from source at commit 281ffd424ebaOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add java-class-analyzer-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "java-class-analyzer-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_classread分析Java类的结构、方法、字段等信息
decompile_classread反编译指定的Java类文件,返回Java源码
scan_dependenciesread扫描Maven项目的所有依赖,建立类名到JAR包的映射索引
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, commander, fs-extra, xml2js, archiver, yauzl, @types/node, @types/fs-extra
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 281ffd424ebafull audit observations/trust-audit/mcp-server/handsomestwei__java-class-analyzer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08281ffd424ebaSAFEB89first audit
06

Questions

What is the Java Class Analyzer MCP server?

java class反编译mcp server

What tools does Java Class Analyzer expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Java Class Analyzer safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Java Class Analyzer need?

No credential environment variables were found in its source, so it appears to need none.

How does Java Class Analyzer run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as java-class-analyzer-mcp-server at 1.0.2.

How current is this page?

The grade is for one exact copy of the source (281ffd424eba), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement