Smart CodingBLOCK
An extensible Model Context Protocol (MCP-Local-MRL-RAG-AST) server that provides intelligent semantic code search for AI assistants. Built with local AI models, inspired by Cursor's semantic search.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/smart-coding-mcp) [](https://www.npmjs.com/package/smart-coding-mcp) [](https://opensource.org/licenses/MIT) [](https://nodejs.org/)
An extensible Model Context Protocol (MCP) server that provides intelligent semantic code search for AI assistants. Built with local AI models using Matryoshka Representation Learning (MRL) for flexible embedding dimensions (64-768d).
What This Does
AI coding assistants work better when they can find relevant code quickly. Traditional keyword search falls short - if you ask "where do we handle authentication?" but your code uses "login" and "session", keyword search misses it.
This MCP server solves that by indexing your codebase with AI embeddings. Your AI assistant can search by meaning instead of exact keywords, finding relevant code even when the terminology differs.
Available Tools
🔍 a_semantic_search - Find Code by Meaning
The primary tool for codebase exploration. Uses AI embeddings to understand what you're looking for, not just match keywords.
How it works: Converts your natural language query into a vector, then finds code chunks with similar meaning using cosine similarity + exact match boosting.
Best for:
- Exploring unfamiliar codebases:
"How does authentication work?" - Finding related code:
"Where do we validate user input?" - Conceptual searches:
"error handling patterns" - Works even with typos:
"embeding modle initializashun"still finds embedding code
Example queries:
"Where do we handle cache persistence?" "How is the database connection managed?" "Find all API endpoint definitions"
📦 d_check_last_version - Package Ve
ccdad0e06af1OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add smart-coding-mcp -- npx -y [email protected]
{
"mcpServers": {
"smart-coding-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (5)
2 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
a_semantic_search | read | Performs intelligent hybrid code search combining semantic understanding with exact text matching. Ideal for finding code by meaning (e.g., |
b_index_codebase | write | Manually trigger a full reindex of the codebase. This will scan all files and update the embeddings cache. Useful after large code changes or if the index seems out of date. |
c_clear_cache | destructive | Clears the embeddings cache, forcing a complete reindex on next search or manual index operation. Useful when encountering cache corruption or after major codebase changes. |
e_set_workspace | write | Change the project workspace path at runtime. Use this when you detect the current workspace is incorrect or you need to switch to a different project directory. Creates cache folder automatically and optionally re-indexes the new workspace. |
f_get_status | read | Get comprehensive status information about the Smart Coding MCP server. Returns version, workspace path, model configuration, indexing status, and cache information. Useful for understanding the current state of the semantic search system. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
"**/.aws/**",
"**/.kube/**",
"**/id_rsa*",
"**/id_ed25519*",
"**/id_ecdsa*",
c_clear_cache
return crypto.createHash("md5").update(content).digest("hex");@huggingface/transformers, @modelcontextprotocol/sdk, better-sqlite3, chokidar, fastembed, fdir, glob, web-tree-sitter
Gates applied: no_behavioural_pass.
ccdad0e06af1full audit observations/trust-audit/mcp-server/omar-haris__smart-coding.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | ccdad0e06af1 | BLOCK | D | 69 | first audit |
Questions
What is the Smart Coding MCP server?
An extensible Model Context Protocol (MCP-Local-MRL-RAG-AST) server that provides intelligent semantic code search for AI assistants. Built with local AI models, inspired by Cursor's semantic search.
What tools does Smart Coding expose?
5 in total: 2 read-only, 2 that write, and 1 that can delete or overwrite (c_clear_cache). Every one is listed on this page with its risk.
Is Smart Coding safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Smart Coding need?
No credential environment variables were found in its source, so it appears to need none.
How does Smart Coding run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as smart-coding-mcp at 2.3.3.
How current is this page?
The grade is for one exact copy of the source (ccdad0e06af1), read on 2026-10-06. The repository is watched and re-audited when it changes.