Code ReasoningSAFE
A code reasoning MCP server, a fork of sequential-thinking
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that enhances Claude's ability to solve complex programming tasks through structured, step-by-step thinking.
[](https://www.npmjs.com/package/@mettamatt/code-reasoning) [](https://opensource.org/licenses/MIT) [](https://github.com/mettamatt/code-reasoning/actions/workflows/ci.yml)
Quick Installation
- Configure Claude Desktop by editing:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json - Linux:
~/.config/Claude/claude_desktop_config.json
{
"mcpServers": {
"code-reasoning": {
"command": "npx",
"args": ["-y", "@mettamatt/code-reasoning"]
}
}
}- Configure VS Code:
{
"mcp": {
"servers": {
"code-reasoning": {
"command": "npx",
"args": ["-y", "@mettamatt/code-reasoning"]
}
}
}
}Usage
- To trigger this MCP, append this to your chat messages:
Use sequential thinking to reason about this.
- Use ready-to-go prompts that trigger Code-Reasoning:
- Click the "+" icon in the Claude Desktop chat window, or in Claude Code type
/helpto see the specific commands. - Select "Add from Code Reasoning" from the available tools
- Choose a prompt template and fill in the required information
- Submit the form to add the prompt to your chat message and hit return
See the [Prompts Guide](./docs/promp
d0fda01c608aOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add code-reasoning -- npx -y @mettamatt/[email protected]
{
"mcpServers": {
"code-reasoning": {
"command": "npx",
"args": [
"-y",
"@mettamatt/[email protected]"
]
}
}
}Exposed tools (24)
23 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
affected_components | read | Primary components affected by the bug (file paths, function names, or module identifiers) |
architecture-decision | read | Framework for making and documenting architecture decisions |
brace-sample | read | Prompt to verify braces survive sanitization |
bug-analysis | read | Systematic approach to analyzing and fixing bugs |
bug_behavior | read | Description of the observed bug behavior |
code-review | read | Comprehensive template for code review |
code_path | read | File path or directory to review (will be accessed via filesystem tools) |
constraints | read | Constraints that impact the decision |
current_issues | read | Issues in the current code that prompted refactoring |
custom-no-working-dir | read | Custom prompt without working_directory argument |
decision_context | read | The architectural decision that needs to be made |
expected_behavior | read | What should happen when working correctly |
feature-planning | read | Structured approach to planning new feature implementation |
goals | read | Goals of the refactoring effort |
language | read | Programming language of the code (optional, will be inferred from file extension) |
options | read | Options being considered |
problem_statement | destructive | Clear statement of the problem this feature solves |
refactoring-plan | read | Structured approach to code refactoring |
reproduction_steps | read | Steps to reproduce the bug |
requirements | read | Requirements that the code should implement |
snippet | read | Code snippet to inject |
success_criteria | read | How we will know the feature is successful |
target_users | read | Primary users who will benefit from this feature |
working_directory | read | Path to the current project directory |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
problem_statement
@modelcontextprotocol/sdk, zod-to-json-schema, @eslint/js, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, eslint-config-prettier
Gates applied: no_behavioural_pass.
d0fda01c608afull audit observations/trust-audit/mcp-server/mettamatt__code-reasoning.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | d0fda01c608a | SAFE | B | 89 | first audit |
Questions
What is the Code Reasoning MCP server?
A code reasoning MCP server, a fork of sequential-thinking
What tools does Code Reasoning expose?
24 in total: 23 read-only, 0 that write, and 1 that can delete or overwrite (problem_statement). Every one is listed on this page with its risk.
Is Code Reasoning safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Code Reasoning need?
No credential environment variables were found in its source, so it appears to need none.
How does Code Reasoning run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mettamatt/code-reasoning at 0.8.1.
How current is this page?
The grade is for one exact copy of the source (d0fda01c608a), read on 2026-10-06. The repository is watched and re-audited when it changes.