Atlas / MCP servers / muvon / Octocode

OctocodeCAUTION

mcp/muvon/octocode

Structural code intelligence for AI agents — semantic search, knowledge graphs, and a built-in MCP server in one Rust binary. Give Claude, Cursor, and any MCP client a deep understanding of your codebase.

Verdict
CAUTION
Grade
C
Trust score
75 /100
Exposed tools
—
Transport
streamable-http
License
Apache-2.0
Stars
477
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Structural Code Intelligence for AI Agents — MCP Server + Knowledge Graph + Semantic Search

[](https://github.com/Muvon/octocode/actions/workflows/ci.yml) [](https://github.com/Muvon/octocode/actions/workflows/ci.yml) [](https://crates.io/crates/octocode) [](https://github.com/Muvon/octocode/stargazers) [](https://opensource.org/licenses/Apache-2.0) [](https://www.rust-lang.org) [](https://github.com/Muvon/octocode/releases)

Give your AI assistant a brain for your codebase. Octocode transforms your project into a navigable knowledge graph that Claude, Cursor, and other AI agents can search, understand, and navigate.

🚀 Quick Start • 🤖 MCP Integration • 📖 Documentation • 🌐 Website

🤖 Built for AI Agents

The Problem: AI assistants are blind to your codebase. They can't search your files, understand dependencies, or remember context across sessions.

The Solution: Octocode's MCP server gives AI agents:

  • 🔍 Semantic search — Find code by meaning, not keywords
  • 🕸️ Knowledge graph — Navigate imports, c
Read from source at commit d9d963e145a3OBSERVED · 2026-09-30
02

Trust audit

CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (7 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (24)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/mcp/lsp/client_tests.rs:472
format!("{PYTHON} -c __import__(\"sys\").stdin.read()"),
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
scripts/install-completions.sh:45
"/etc/bash_completion.d"
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.noindex
.noindex
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:286
tar czf ../../../dist/octocode-${{ inputs.tag || github.ref_name }}-${{ matrix.target }}.tar.gz octocode.exe
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:289
tar czf ../../../dist/octocode-${{ inputs.tag || github.ref_name }}-${{ matrix.target }}.tar.gz octocode
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:298
7z a ../../../dist/octocode-${{ inputs.tag || github.ref_name }}-${{ matrix.target }}.zip octocode.exe
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/indexer/languages/markdown_test.rs:99
Markdown.resolve_import("../../outside.md", "docs/guide.md", &registry),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/lsp/protocol_tests.rs:207
assert!(resolve_relative_path(dir.path(), "../../etc/passwd").is_err());
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
doc/API_KEYS.md:225
export LOCAL_API_URL="http://127.0.0.1:8000/v1/chat/completions"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
doc/CONFIGURATION.md:198
export LOCAL_API_URL="http://127.0.0.1:8000/v1/chat/completions"
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/dependencies.yml:27
sudo apt-get update
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/dependencies.yml:28
sudo apt-get install -y protobuf-compiler
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:84
sudo swapoff "$EXISTING" || true
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:85
sudo rm -f "$EXISTING"
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:90
sudo fallocate -l 16G "$SWAP_PATH" 2>/dev/null || \
Why it matters. asks for elevated privileges
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:1104
- **config**: load environment variables from .env file on startup `f3c50bbc`
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:7
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:19
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh -s -- --version 0.1.0
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:22
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh -s -- --install-dir /usr/local/bin
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:25
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh -s -- --target x86_64-unknown-linux-musl
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:29
curl -fsSL https://raw.githubusercontent.com/muvon/octocode/master/install.sh | sh
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha d9d963e145a3full audit observations/trust-audit/mcp-server/muvon__octocode.json · Report an issue / request a re-scan
03

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-30d9d963e145a3CAUTIONC75first audit
04

Questions

What is the Octocode MCP server?

Structural code intelligence for AI agents — semantic search, knowledge graphs, and a built-in MCP server in one Rust binary. Give Claude, Cursor, and any MCP client a deep understanding of your codebase.

Is Octocode safe to connect to an agent?

With care. The audit graded it C (75/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Octocode need?

No credential environment variables were found in its source, so it appears to need none.

How does Octocode run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (d9d963e145a3), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement