OctocodeCAUTION
Structural code intelligence for AI agents — semantic search, knowledge graphs, and a built-in MCP server in one Rust binary. Give Claude, Cursor, and any MCP client a deep understanding of your codebase.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Structural Code Intelligence for AI Agents — MCP Server + Knowledge Graph + Semantic Search
[](https://github.com/Muvon/octocode/actions/workflows/ci.yml) [](https://github.com/Muvon/octocode/actions/workflows/ci.yml) [](https://crates.io/crates/octocode) [](https://github.com/Muvon/octocode/stargazers) [](https://opensource.org/licenses/Apache-2.0) [](https://www.rust-lang.org) [](https://github.com/Muvon/octocode/releases)
Give your AI assistant a brain for your codebase. Octocode transforms your project into a navigable knowledge graph that Claude, Cursor, and other AI agents can search, understand, and navigate.
🚀 Quick Start • 🤖 MCP Integration • 📖 Documentation • 🌐 Website
🤖 Built for AI Agents
The Problem: AI assistants are blind to your codebase. They can't search your files, understand dependencies, or remember context across sessions.
The Solution: Octocode's MCP server gives AI agents:
- 🔍 Semantic search — Find code by meaning, not keywords
- 🕸️ Knowledge graph — Navigate imports, c
d9d963e145a3OBSERVED · 2026-09-30Trust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (24)
format!("{PYTHON} -c __import__(\"sys\").stdin.read()"),"/etc/bash_completion.d"
streamable-http
.noindex
.pre-commit-config.yaml
tar czf ../../../dist/octocode-${{ inputs.tag || github.ref_name }}-${{ matrix.target }}.tar.gz octocode.exetar czf ../../../dist/octocode-${{ inputs.tag || github.ref_name }}-${{ matrix.target }}.tar.gz octocode7z a ../../../dist/octocode-${{ inputs.tag || github.ref_name }}-${{ matrix.target }}.zip octocode.exeMarkdown.resolve_import("../../outside.md", "docs/guide.md", ®istry),assert!(resolve_relative_path(dir.path(), "../../etc/passwd").is_err());
export LOCAL_API_URL="http://127.0.0.1:8000/v1/chat/completions"
export LOCAL_API_URL="http://127.0.0.1:8000/v1/chat/completions"
sudo apt-get update
sudo apt-get install -y protobuf-compiler
sudo swapoff "$EXISTING" || true
sudo rm -f "$EXISTING"
sudo fallocate -l 16G "$SWAP_PATH" 2>/dev/null || \
- **config**: load environment variables from .env file on startup `f3c50bbc`
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh -s -- --version 0.1.0
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh -s -- --install-dir /usr/local/bin
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh -s -- --target x86_64-unknown-linux-musl
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh
Gates applied: no_behavioural_pass.
d9d963e145a3full audit observations/trust-audit/mcp-server/muvon__octocode.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | d9d963e145a3 | CAUTION | C | 75 | first audit |
Questions
What is the Octocode MCP server?
Structural code intelligence for AI agents — semantic search, knowledge graphs, and a built-in MCP server in one Rust binary. Give Claude, Cursor, and any MCP client a deep understanding of your codebase.
Is Octocode safe to connect to an agent?
With care. The audit graded it C (75/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Octocode need?
No credential environment variables were found in its source, so it appears to need none.
How does Octocode run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (d9d963e145a3), read on 2026-09-30. The repository is watched and re-audited when it changes.