CodegraphBLOCK
Code intelligence CLI — function-level dependency graph across 34 languages, 34-tool MCP server for AI agents, complexity metrics, architecture boundary enforcement, CI quality gates, git diff impact with co-change analysis, hybrid semantic search. Fully local, zero API keys required.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
codegraph
Give your AI the map before it starts exploring.
= 22.12.0" />
The Problem · What It Does · Quick Start · Commands · Languages · AI Integration · How It Works · Practices · Roadmap
The Problem
AI agents face an impossible trade-off. They either spend thousands of tokens reading files to understand a codebase's structure — blowing up their context window until quality degrades — or they assume how things work, and the assumptions are often wrong. Either way, things break. The larger the codebase, the worse i
f3a3aaadf990OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add lib --env CODEGRAPH_LLM_API_KEY=${CODEGRAPH_LLM_API_KEY} -- npx -y @myorg/[email protected]{
"mcpServers": {
"lib": {
"command": "npx",
"args": [
"-y",
"@myorg/[email protected]"
],
"env": {
"CODEGRAPH_LLM_API_KEY": "${CODEGRAPH_LLM_API_KEY}"
}
}
}
}Exposed tools (49)
42 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
ast_query | read | Search stored AST nodes (calls, literals, new, throw, await) by pattern. Requires a prior build. |
audit | read | Composite report combining explain, fn-impact, and health metrics for a file or function. Returns structure, blast radius, complexity, and threshold breaches in one call. |
batch_query | write | Run a query command against multiple targets in one call. Returns all results in a single JSON payload — ideal for multi-agent dispatch. |
branch_compare | write | Compare code structure between two git refs (branches, tags, commits). Shows added/removed/changed symbols and transitive caller impact using temporary git worktrees. |
brief | read | Token-efficient file summary: symbols with roles and transitive caller counts, importer counts, and file risk tier (high/medium/low). Designed for context injection. |
cfg | read | Show intraprocedural control flow graph for a function. |
check | write | CI gate: run manifesto rules (no args), diff predicates (with ref/staged), or both (with rules flag). Returns pass/fail verdicts. |
co_changes | write | Find files that historically change together based on git commit history. Requires prior |
code_owners | read | Show CODEOWNERS mapping for files and functions. Shows ownership coverage, per-owner breakdown, and cross-owner boundary edges. |
communities | read | Detect natural module boundaries using Leiden community detection |
complexity | read | Show per-function complexity metrics (cognitive, cyclomatic, nesting, Halstead, Maintainability Index). Sorted by most complex first. |
config | read | Show or manage codegraph configuration (project + user-level global config) |
context | read | Full context for a function: source code, dependencies with summaries, callers, signature, and related tests — everything needed to understand or modify a function in one call |
cycles | read | Detect circular dependencies in the codebase |
dataflow | read | Show data flow edges or data-dependent blast radius. |
diff_impact | read | Analyze git diff to find which functions changed and their transitive callers |
execution_flow | read | Trace execution flow forward from an entry point through callees to leaves, or list all entry points with list=true |
export | read | Export dependency graph as DOT, Mermaid, JSON, GraphML, GraphSON, or Neo4j CSV |
export_graph | read | Export the dependency graph in DOT, Mermaid, JSON, GraphML, GraphSON, or Neo4j CSV format |
file_deps | read | Show what a file imports and what imports it |
file_exports | read | Show exported symbols of a file with per-symbol consumers — who calls each export and from where |
find_cycles | read | Detect circular dependencies in the codebase |
fn_impact | read | Show function-level blast radius: all functions transitively affected by changes to a function |
impact_analysis | read | Show files affected by changes to a given file (transitive) |
implementations | read | List all concrete types (classes, structs, records) that implement a given interface or trait |
info | read | Show codegraph engine info and diagnostics |
interfaces | read | List all interfaces and traits that a given class, struct, or record implements |
list | read | List all registered repositories |
list_functions | read | List functions, methods, classes, structs, enums, traits, records, and modules in the codebase, optionally filtered by file or name pattern |
list_repos | read | List all repositories registered in the codegraph registry |
map | read | High-level module overview with most-connected nodes |
mcp | write | Start MCP (Model Context Protocol) server for AI assistant integration |
models | read | List available embedding models |
module_map | read | Get high-level overview of most-connected files |
node_roles | read | Show node role classification (entry, core, utility, adapter, dead [dead-leaf, dead-entry, dead-ffi, dead-unresolved], leaf) based on connectivity patterns |
path | read | Find shortest path between two symbols (or files with file_mode) in the dependency graph |
plot | read | Generate an interactive HTML dependency graph viewer |
prune | destructive | Remove stale registry entries (missing directories or idle beyond TTL) |
query | read | Query the call graph: find callers/callees with transitive chain, or find shortest path between two symbols |
registry | read | Manage the multi-repo project registry |
roles | read | Show node role classification: entry, core, utility, adapter, dead (dead-leaf, dead-entry, dead-ffi, dead-unresolved), leaf |
semantic_search | read | Search code symbols by meaning using embeddings and/or keyword matching (requires prior |
sequence | read | Generate a Mermaid sequence diagram from call graph edges. Participants are files, messages are function calls between them. |
snapshot | write | Save and restore graph database snapshots |
stats | read | Show graph health overview: nodes, edges, languages, cycles, hotspots, embeddings |
structure | read | Show project structure with directory hierarchy, cohesion scores, and per-file metrics. Per-file details are capped at 25 files by default; use full=true to show all. |
symbol_children | read | List sub-declaration children of a symbol: parameters, properties, constants. Answers |
triage | read | Ranked audit queue by composite risk score (connectivity + complexity + churn + role) |
where | read | Find where a symbol is defined and used, or list symbols/imports/exports for a file. Minimal, fast lookup. |
Trust audit
BLOCKgrade F · trust 38/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (16 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
All subagents in this sweep — and any other concurrent session — share one authenticated `gh` identity's rate limit (5000 REST requests/hour). Polling too tightly, or re-fetching every endpoint on eve
pub fn exec(&self, sql: String) -> napi::Result<()> {exec(sql: string): this {| 'eval' // eval() / new Function() — undecidable; always flagged
exec(sql: string): this;
exec(sql: string): void;
### 11. Seven-Step Permission Pipeline with Bypass-Immune Safety Checks
4-7. **Bypass-immune safety guardrails** — fire even in `bypassPermissions` mode
tree-sitter-erlang.wasm
let s = parse_js("const conn = Ωmega.create();");assert_eq!(tm.unwrap().type_name, "Ωmega");
prune
.codegraphrc.example.json
.codegraphrc.json
.versionrc.json
process.stdout.write(crypto.createHash('sha1').update(d.trim()).digest('hex').slice(0,8));process.stdout.write(crypto.createHash('sha1').update(d.trim()).digest('hex').slice(0,8));process.stdout.write(crypto.createHash('sha1').update(d.trim()).digest('hex').slice(0,8));process.stdout.write(crypto.createHash('sha1').update(d.trim()).digest('hex').slice(0,8));//! Note: Uses SHA-256 (not MD5). The JS pipeline uses MD5 via `createHash('md5')`,clean_path(Path::new("src/cli/commands/../../domain/graph/builder.js")),assert_eq!(clean_path(Path::new("../../foo")), PathBuf::from("foo"));"const { buildDataflowVerticesFromMap, buildDataflowEdges } = (await import('../../../../features/dataflow.js')) as { buildDataflowVerticesFromMap: Fn; buildDataflowEdges: Fn };",assert_eq!(dyn_imports[0].source, "../../../../features/dataflow.js");
const SCHEMA = '../../../expected-edges.schema.json';
Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.
f3a3aaadf990full audit observations/trust-audit/mcp-server/optave__codegraph-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f3a3aaadf990 | BLOCK | F | 38 | first audit |
Questions
What is the Codegraph MCP server?
Code intelligence CLI — function-level dependency graph across 34 languages, 34-tool MCP server for AI agents, complexity metrics, architecture boundary enforcement, CI quality gates, git diff impact with co-change analysis, hybrid semantic search. Fully local, zero API keys required.
What tools does Codegraph expose?
49 in total: 42 read-only, 6 that write, and 1 that can delete or overwrite (prune). Every one is listed on this page with its risk.
Is Codegraph safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (38/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Codegraph need?
It reads CODEGRAPH_LLM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Codegraph run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @myorg/lib at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (f3a3aaadf990), read on 2026-10-08. The repository is watched and re-audited when it changes.