CclspCAUTION
Claude Code LSP: enhance your Claude Code experience with non-IDE dependent LSP integration.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/ktnyt-cclsp)
[](https://www.npmjs.com/package/cclsp) [](https://opensource.org/licenses/MIT) [](https://nodejs.org) [](https://github.com/ktnyt/cclsp/actions/workflows/ci.yml) [](https://www.npmjs.com/package/cclsp) [](CONTRIBUTING.md)
cclsp is a Model Context Protocol (MCP) server that seamlessly integrates LLM-based coding agents with Language Server Protocol (LSP) servers. LLM-based coding agents often struggle with providing accurate line/column numbers, which makes naive attempts to integrate with LSP servers fragile and frustrating. cclsp solves this by intelligently trying multiple position combinations and providing robust symbol resolution that just works, no matter how your AI assistant counts lines.
Setup & Usage Demo
https://github.com/user-attachments/assets/52980f32-64d6-4b78-9cbf-18d6ae120cdd
Table of Contents
- Why cclsp?
- Features
- 📋 Prerequisites
- ⚡ Setup
- Automated Setup (Recommended)
- Claude Code Quick Setup
- Manual Setup
- Language Server Installation
- Verification
- 🚀 Usage
- As MCP Server
- Configuration
- 🛠️ Development
- 🔧 MCP Tools
find_definitionfind_references- [`rename_symbo
1009744ab53aOBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add cclsp -- npx -y [email protected]
{
"mcpServers": {
"cclsp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (12)
9 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
find_definition | read | Find the definition of a symbol by name and kind in a file. Returns definitions for all matching symbols. |
find_implementation | read | Find implementations of an interface or abstract method. Returns locations of all implementations. |
find_references | read | Find all references to a symbol across the entire workspace. Returns references for all matching symbols. |
find_workspace_symbols | read | Search for symbols across the entire workspace by name. Returns matching symbols from all files. |
get_diagnostics | read | Get language diagnostics (errors, warnings, hints) for a file. Uses LSP textDocument/diagnostic to pull current diagnostics. |
get_hover | read | Get hover information (documentation, type info) for a symbol at a specific position in a file. |
get_incoming_calls | read | Find all functions/methods that call the function at a position. Requires prepare_call_hierarchy first. |
get_outgoing_calls | read | Find all functions/methods called by the function at a position. Requires prepare_call_hierarchy first. |
prepare_call_hierarchy | read | Get call hierarchy item at a position. Use this to prepare for incoming_calls or outgoing_calls. |
rename_symbol | write | Rename a symbol by name and kind in a file. If multiple symbols match, returns candidate positions and suggests using rename_symbol_strict. By default, this will apply the rename to the files. Use dry_run to preview changes without applying them. |
rename_symbol_strict | write | Rename a symbol at a specific position in a file. Use this when rename_symbol returns multiple candidates. By default, this will apply the rename to the files. Use dry_run to preview changes without applying them. |
restart_server | write | Manually restart LSP servers. Can restart servers for specific file extensions or all running servers. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
spawning, file system access, configuration loading, or environment variable
import type { LSPServerConfig } from '../../types.js';import type { LSPServerConfig } from '../../types.js';import { logger } from '../../logger.js';import type { LSPServerConfig } from '../../types.js';@modelcontextprotocol/sdk, @types/inquirer, ignore, inquirer, typescript-language-server, @biomejs/biome, @types/bun, @types/node
Gates applied: no_behavioural_pass.
1009744ab53afull audit observations/trust-audit/mcp-server/ktnyt__cclsp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 1009744ab53a | CAUTION | B | 89 | first audit |
Questions
What is the Cclsp MCP server?
Claude Code LSP: enhance your Claude Code experience with non-IDE dependent LSP integration.
What tools does Cclsp expose?
12 in total: 9 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Cclsp safe to connect to an agent?
With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Cclsp need?
No credential environment variables were found in its source, so it appears to need none.
How does Cclsp run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as cclsp at 0.7.0.
How current is this page?
The grade is for one exact copy of the source (1009744ab53a), read on 2026-09-28. The repository is watched and re-audited when it changes.