Atlas / MCP servers / omar-haris / Smart Coding

Smart CodingBLOCK

mcp/omar-haris/smart-coding

An extensible Model Context Protocol (MCP-Local-MRL-RAG-AST) server that provides intelligent semantic code search for AI assistants. Built with local AI models, inspired by Cursor's semantic search.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
5 2r · 2w · 1d
Transport
stdio
License
MIT
Stars
199
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/smart-coding-mcp) [](https://www.npmjs.com/package/smart-coding-mcp) [](https://opensource.org/licenses/MIT) [](https://nodejs.org/)

An extensible Model Context Protocol (MCP) server that provides intelligent semantic code search for AI assistants. Built with local AI models using Matryoshka Representation Learning (MRL) for flexible embedding dimensions (64-768d).

What This Does

AI coding assistants work better when they can find relevant code quickly. Traditional keyword search falls short - if you ask "where do we handle authentication?" but your code uses "login" and "session", keyword search misses it.

This MCP server solves that by indexing your codebase with AI embeddings. Your AI assistant can search by meaning instead of exact keywords, finding relevant code even when the terminology differs.

Available Tools

🔍 a_semantic_search - Find Code by Meaning

The primary tool for codebase exploration. Uses AI embeddings to understand what you're looking for, not just match keywords.

How it works: Converts your natural language query into a vector, then finds code chunks with similar meaning using cosine similarity + exact match boosting.

Best for:

  • Exploring unfamiliar codebases: "How does authentication work?"
  • Finding related code: "Where do we validate user input?"
  • Conceptual searches: "error handling patterns"
  • Works even with typos: "embeding modle initializashun" still finds embedding code

Example queries:

"Where do we handle cache persistence?"
"How is the database connection managed?"
"Find all API endpoint definitions"

📦 d_check_last_version - Package Ve

Read from source at commit ccdad0e06af1OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add smart-coding-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "smart-coding-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (5)

2 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
a_semantic_searchreadPerforms intelligent hybrid code search combining semantic understanding with exact text matching. Ideal for finding code by meaning (e.g.,
b_index_codebasewriteManually trigger a full reindex of the codebase. This will scan all files and update the embeddings cache. Useful after large code changes or if the index seems out of date.
c_clear_cachedestructiveClears the embeddings cache, forcing a complete reindex on next search or manual index operation. Useful when encountering cache corruption or after major codebase changes.
e_set_workspacewriteChange the project workspace path at runtime. Use this when you detect the current workspace is incorrect or you need to switch to a different project directory. Creates cache folder automatically and optionally re-indexes the new workspace.
f_get_statusreadGet comprehensive status information about the Smart Coding MCP server. Returns version, workspace path, model configuration, indexing status, and cache information. Useful for understanding the current state of the semantic search system.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
lib/config.js:645
"**/.aws/**",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
lib/config.js:647
"**/.kube/**",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
lib/config.js:649
"**/id_rsa*",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
lib/config.js:650
"**/id_ed25519*",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
lib/config.js:651
"**/id_ecdsa*",
Why it matters. touches a credential store
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
c_clear_cache
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
lib/utils.js:25
return crypto.createHash("md5").update(content).digest("hex");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@huggingface/transformers, @modelcontextprotocol/sdk, better-sqlite3, chokidar, fastembed, fdir, glob, web-tree-sitter
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha ccdad0e06af1full audit observations/trust-audit/mcp-server/omar-haris__smart-coding.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06ccdad0e06af1BLOCKD69first audit
06

Questions

What is the Smart Coding MCP server?

An extensible Model Context Protocol (MCP-Local-MRL-RAG-AST) server that provides intelligent semantic code search for AI assistants. Built with local AI models, inspired by Cursor's semantic search.

What tools does Smart Coding expose?

5 in total: 2 read-only, 2 that write, and 1 that can delete or overwrite (c_clear_cache). Every one is listed on this page with its risk.

Is Smart Coding safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Smart Coding need?

No credential environment variables were found in its source, so it appears to need none.

How does Smart Coding run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as smart-coding-mcp at 2.3.3.

How current is this page?

The grade is for one exact copy of the source (ccdad0e06af1), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement