TypeScriptBLOCK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/mizchi/lsmcp/actions/workflows/ci.yml) [](https://github.com/mizchi/lsmcp/actions/workflows/language-tests.yml) [](https://www.npmjs.com/package/@mizchi/lsmcp) [](https://opensource.org/licenses/MIT)
A unified MCP (Model Context Protocol) server that provides advanced code manipulation and analysis capabilities for multiple programming languages through Language Server Protocol integration.
- 🌍 Multi-Language Support
- 🔍 Semantic Code Analysis
- 🤖 AI-Optimized
See examples/ for working examples of each supported language configuration.
Requirements
- Node.js 22.0.0 or higher (required for built-in SQLite support)
Quick Start
# tsgo (reccommended) npm add -D @mizchi/lsmcp @typescript/native-preview npx @mizchi/lsmcp init -p tsgo claude mcp add lsmcp npx -- -y @mizchi/lsmcp -p tsgo # with manual --bin claude mcp add lsmcp npx -- -y @mizchi/lsmcp --bin=""
📖 Example Usage with Claude
RECOMMENDED WORKFLOW
🎯 Core Flow: Overview → Search → Details
1. get_project_overview # Understand the codebase 2. search_symbols # Find what you need 3. get_symbol_details # Deep dive into symbols
📋 When to Use Each Tool
Initial Exploration:
get_project_overview- First tool to understand any codebaselist_dir- Browse directory structureget_symbols_overview- High-level view of file symbols
Finding Code:
search_symbols- Primary search for functions, classes, interfaceslsp_get_document_symbols- List all symbols in a specific filelsp_get_workspace_symbols
677f25c033eaOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add types -- npx -y @internal/[email protected]
{
"mcpServers": {
"types": {
"command": "npx",
"args": [
"-y",
"@internal/[email protected]"
]
}
}
}Exposed tools (37)
30 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Pyright | read | Microsoft |
another_tool | read | Another tool |
delete_memory | destructive | Delete a memory from the project |
get_available_external_symbols | read | Get all symbols available from external libraries imported in a file. Shows what symbols are imported and from which modules they come from. |
get_compression_guidance | read | Get guidance on token compression analysis |
get_project_overview | read | Get a quick overview of the project structure, key components, and statistics. |
get_symbol_details | read | Get comprehensive details about a symbol including type information, definition, and references. |
get_symbol_search_guidance | read | Get guidance on how to effectively search symbols in the index |
get_typescript_dependencies | read | List all TypeScript dependencies available in the project (from package.json and node_modules). Shows which external libraries have TypeScript declarations that can be indexed. |
index_external_libraries | write | Index TypeScript declaration files from node_modules to enable symbol search in external dependencies. This tool scans node_modules for .d.ts files and indexes their symbols for fast searching. |
index_onboarding | read | Get instructions for onboarding the symbol index for a project |
list_dir | read | Lists all non-gitignored files and directories in the given directory (optionally with recursion). Returns a JSON object with the names of directories and files within the given directory. |
list_memories | read | List available memories for the current project |
lsp_check_capabilities | read | Check the capabilities of the current LSP server. Shows which features are supported. |
lsp_delete_symbol | destructive | Delete a symbol and optionally all its references using LSP. Requires exact line:column position of the symbol. |
lsp_find_references | read | Find all references to a symbol at a specific position using LSP. Requires exact line:column coordinates. |
lsp_format_document | read | Format an entire document using LSP |
lsp_get_code_actions | read | Get available code actions (quick fixes, refactorings) for a specific range using LSP. Requires line range specification. |
lsp_get_completion | read | Get code completion suggestions at a specific position using LSP. Requires exact line:column coordinates. |
lsp_get_definitions | read | Get the definition(s) of a symbol at a specific position using LSP. Requires exact line:column coordinates. |
lsp_get_diagnostics | read | Get diagnostics (errors, warnings) for a specific file using LSP. Provides detailed error and warning information. |
lsp_get_document_symbols | read | Get all symbols in a document using LSP. Returns structured symbol hierarchy for the entire file. |
lsp_get_hover | read | Get hover information (type signature, documentation) at a specific position using LSP. Requires exact line:column coordinates. |
lsp_get_signature_help | read | Get signature help (parameter hints) for function calls using LSP. Requires exact line:column position within a function call. |
lsp_get_workspace_symbols | read | Search for symbols across the entire workspace using LSP. |
lsp_rename_symbol | write | Rename a symbol across the codebase using LSP. Requires exact position or text target in the specified line. |
my_tool | read | My tool |
parse_imports | write | Parse and analyze import statements in a TypeScript/JavaScript file. Shows all imports, their sources, and any aliases used. |
read_memory | read | Read a specific memory from the project |
replace_range | read | Replace a specific range of text in a file. |
replace_regex | read | Replace content using regular expressions with dotall and multiline flags |
resolve_symbol | write | Resolve a symbol to its definition in external libraries by analyzing import statements. For example, if a file imports { ok, Ok, Err } from |
rust-analyzer | read | Language Server for Rust |
search_external_library_symbols | read | Search for symbols in indexed external libraries (node_modules). Requires running index_external_libraries first. |
search_symbols | read | Search for symbols (functions, classes, variables, etc.) in the codebase using an indexed search. |
test_tool | read | Test tool |
write_memory | write | Write or update a memory for the project |
Trust audit
BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
IMPORTANT: Always use the symbol indexing tools to minimize code reading:
* - `{}` to group sub patterns into an OR expression. (e.g. `**/*.{ts,js}`* - `{}` to group sub patterns into an OR expression. (e.g. `**/*.{ts,js}`* - `{}` to group conditions (e.g. `**/*.{ts,js}` matches all TypeScriptdelete_memory, lsp_delete_symbol
check.moon_db
single.blackbox_test.mi
single.mi
symbols.db
dep-test-bin-rust-project
.versionrc.json
.moon-lock
.rustc_info.json
.cargo-lock
return createHash("sha1").update(content).digest("hex");return createHash("sha1").update(content).digest("hex");crypto.createHash("sha1").update("const x = 1;").digest("hex");crypto.createHash("sha1").update("x".repeat(100000)).digest("hex");crypto.createHash("sha1").update("x".repeat(1000000)).digest("hex");import { debugLogWithPrefix } from "../../../../src/utils/debugLog.ts";import { debugLogWithPrefix } from "../../../../src/utils/debugLog.ts";import { errorLog } from "../../../../src/utils/debugLog.ts";import { debugLogWithPrefix } from "../../../../src/utils/debugLog.ts";import { globalPresetRegistry } from "../../../../src/config/loader.ts";gitaware-glob, glob, minimatch, uuid, zod, @biomejs/biome, @modelcontextprotocol/sdk, @moonbit/moonbit-lsp
Gates applied: no_behavioural_pass.
677f25c033eafull audit observations/trust-audit/mcp-server/mizchi__typescript.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 677f25c033ea | BLOCK | F | 59 | first audit |
Questions
What tools does TypeScript expose?
37 in total: 30 read-only, 5 that write, and 2 that can delete or overwrite (delete_memory, lsp_delete_symbol). Every one is listed on this page with its risk.
Is TypeScript safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (59/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does TypeScript need?
No credential environment variables were found in its source, so it appears to need none.
How does TypeScript run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @internal/types at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (677f25c033ea), read on 2026-10-08. The repository is watched and re-audited when it changes.