Atlas / MCP servers / ktnyt / Cclsp

CclspCAUTION

mcp/ktnyt/cclsp

Claude Code LSP: enhance your Claude Code experience with non-IDE dependent LSP integration.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
12 9r · 3w · 0d
Transport
stdio
License
MIT
Stars
675
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/ktnyt-cclsp)

[](https://www.npmjs.com/package/cclsp) [](https://opensource.org/licenses/MIT) [](https://nodejs.org) [](https://github.com/ktnyt/cclsp/actions/workflows/ci.yml) [](https://www.npmjs.com/package/cclsp) [](CONTRIBUTING.md)

cclsp is a Model Context Protocol (MCP) server that seamlessly integrates LLM-based coding agents with Language Server Protocol (LSP) servers. LLM-based coding agents often struggle with providing accurate line/column numbers, which makes naive attempts to integrate with LSP servers fragile and frustrating. cclsp solves this by intelligently trying multiple position combinations and providing robust symbol resolution that just works, no matter how your AI assistant counts lines.

Setup & Usage Demo

https://github.com/user-attachments/assets/52980f32-64d6-4b78-9cbf-18d6ae120cdd

Table of Contents

  • Why cclsp?
  • Features
  • 📋 Prerequisites
  • ⚡ Setup
  • Automated Setup (Recommended)
  • Claude Code Quick Setup
  • Manual Setup
  • Language Server Installation
  • Verification
  • 🚀 Usage
  • As MCP Server
  • Configuration
  • 🛠️ Development
  • 🔧 MCP Tools
  • find_definition
  • find_references
  • [`rename_symbo
Read from source at commit 1009744ab53aOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add cclsp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "cclsp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (12)

9 read · 3 write · 0 destructive.

ToolRiskDescription
find_definitionreadFind the definition of a symbol by name and kind in a file. Returns definitions for all matching symbols.
find_implementationreadFind implementations of an interface or abstract method. Returns locations of all implementations.
find_referencesreadFind all references to a symbol across the entire workspace. Returns references for all matching symbols.
find_workspace_symbolsreadSearch for symbols across the entire workspace by name. Returns matching symbols from all files.
get_diagnosticsreadGet language diagnostics (errors, warnings, hints) for a file. Uses LSP textDocument/diagnostic to pull current diagnostics.
get_hoverreadGet hover information (documentation, type info) for a symbol at a specific position in a file.
get_incoming_callsreadFind all functions/methods that call the function at a position. Requires prepare_call_hierarchy first.
get_outgoing_callsreadFind all functions/methods called by the function at a position. Requires prepare_call_hierarchy first.
prepare_call_hierarchyreadGet call hierarchy item at a position. Use this to prepare for incoming_calls or outgoing_calls.
rename_symbolwriteRename a symbol by name and kind in a file. If multiple symbols match, returns candidate positions and suggests using rename_symbol_strict. By default, this will apply the rename to the files. Use dry_run to preview changes without applying them.
rename_symbol_strictwriteRename a symbol at a specific position in a file. Use this when rename_symbol returns multiple candidates. By default, this will apply the rename to the files. Use dry_run to preview changes without applying them.
restart_serverwriteManually restart LSP servers. Can restart servers for specific file extensions or all running servers.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/skills/security-review/SKILL.md:5
spawning, file system access, configuration loading, or environment variable
Why it matters. asks the agent to read credentials
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/lsp/adapters/pyright.ts:1
import type { LSPServerConfig } from '../../types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/lsp/adapters/registry.ts:1
import type { LSPServerConfig } from '../../types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/lsp/adapters/vue.ts:1
import { logger } from '../../logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/lsp/adapters/vue.ts:2
import type { LSPServerConfig } from '../../types.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/inquirer, ignore, inquirer, typescript-language-server, @biomejs/biome, @types/bun, @types/node
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 1009744ab53afull audit observations/trust-audit/mcp-server/ktnyt__cclsp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-281009744ab53aCAUTIONB89first audit
06

Questions

What is the Cclsp MCP server?

Claude Code LSP: enhance your Claude Code experience with non-IDE dependent LSP integration.

What tools does Cclsp expose?

12 in total: 9 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Cclsp safe to connect to an agent?

With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Cclsp need?

No credential environment variables were found in its source, so it appears to need none.

How does Cclsp run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as cclsp at 0.7.0.

How current is this page?

The grade is for one exact copy of the source (1009744ab53a), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement