Atlas / MCP servers / kandrwmrtn / C++ Analyzer

C++ AnalyzerBLOCK

mcp/kandrwmrtn/c-analyzer

An MCP (Model Context Protocol) server for analyzing C++ codebases using libclang.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
14 13r · 1w · 0d
Transport
stdio
License
MIT
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server for analyzing C++ codebases using libclang.

Why Use This?

Instead of having Claude grep through your C++ codebase trying to understand the structure, this server provides semantic understanding of your code. Claude can instantly find classes, functions, and their relationships without getting lost in thousands of files. It understands C++ syntax, inheritance hierarchies, and call graphs - giving Claude the ability to navigate your codebase like an IDE would.

Features

Context-efficient C++ code analysis:

  • search_classes - Find classes by name pattern
  • search_functions - Find functions by name pattern
  • get_class_info - Get detailed class information (methods, members, inheritance)
  • get_function_signature - Get function signatures and parameters
  • find_in_file - Search symbols within specific files
  • get_class_hierarchy - Get complete inheritance hierarchy for a class
  • get_derived_classes - Find all classes that inherit from a base class
  • find_callers - Find all functions that call a specific function
  • find_callees - Find all functions called by a specific function
  • get_call_path - Find call paths from one function to another

Prerequisites

  • Python 3.9 or higher
  • pip (Python package manager)
  • Git (for cloning the repository)
  • LLVM's libclang (the setup scripts will attempt to download a portable build)

Setup

  1. Clone the repository:
git clone 
cd CPlusPlus-MCP-Server
  1. Run the setup script for your platform (this creates a virtual environment, installs dependencies, and fetches libclang if possible):
  2. Windows
server_setup.bat
  • Linux/macOS
./server_setup.sh
  1. Test the installation (recommended):
# Activate the virtual environment first
mcp_env\Scripts\activate

# Run the installation test
python scripts\test_installation.py

This

Read from source at commit 06e16193f526OBSERVED · 2026-10-08
02

Exposed tools (14)

13 read · 1 write · 0 destructive.

ToolRiskDescription
find_calleesreadFind all functions called by a specific function
find_callersreadFind all functions that call a specific function
find_in_filereadSearch for symbols within a specific file
get_call_pathreadFind call paths from one function to another
get_class_hierarchyreadGet complete inheritance hierarchy for a C++ class
get_class_inforeadGet detailed information about a specific class
get_derived_classesreadGet all classes that inherit from a given base class
get_function_signaturereadGet signature and details for functions with given name
get_server_statusreadGet MCP server status including parsing progress and index stats
refresh_projectreadManually refresh/re-parse project files to detect changes
search_classesreadSearch for C++ classes by name pattern (regex supported)
search_functionsreadSearch for C++ functions by name pattern (regex supported)
search_symbolsreadSearch for all symbols (classes and functions) matching a pattern
set_project_directorywriteSet the project directory to analyze (use this first before other commands)
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
mcp_server/cpp_mcp_server.py:161
print("  Linux: sudo apt install libclang-dev", file=sys.stderr)
Why it matters. asks for elevated privileges
MEDIUMInventory / provenance · inv.binary · CWE-1104
lib/linux/libtinfo.so.5.9
libtinfo.so.5.9
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
lib/linux/libtinfo.so.5
lib/linux/libtinfo.so.5
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
lib/linux/libtinfo.so.6
lib/linux/libtinfo.so.6
Why it matters. link not followed
MEDIUMPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
mcp_server/cache_manager.py:29
project_hash = hashlib.md5(str(self.project_root).encode()).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
mcp_server/cache_manager.py:37
return hashlib.md5(f.read()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
mcp_server/cache_manager.py:111
cache_filename = hashlib.md5(file_path.encode()).hexdigest() + ".json"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, libclang
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 06e16193f526full audit observations/trust-audit/mcp-server/kandrwmrtn__c-analyzer.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0806e16193f526BLOCKD69first audit
05

Questions

What is the C++ Analyzer MCP server?

An MCP (Model Context Protocol) server for analyzing C++ codebases using libclang.

What tools does C++ Analyzer expose?

14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is C++ Analyzer safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does C++ Analyzer need?

No credential environment variables were found in its source, so it appears to need none.

How does C++ Analyzer run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (06e16193f526), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement