Atlas / MCP servers / optave / Codegraph

CodegraphBLOCK

mcp/optave/codegraph-5

Code intelligence CLI — function-level dependency graph across 34 languages, 34-tool MCP server for AI agents, complexity metrics, architecture boundary enforcement, CI quality gates, git diff impact with co-change analysis, hybrid semantic search. Fully local, zero API keys required.

Verdict
BLOCK
Grade
F
Trust score
38 /100
Exposed tools
49 42r · 6w · 1d
Transport
stdio
License
Apache-2.0
Stars
98
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

codegraph

Give your AI the map before it starts exploring.

= 22.12.0" />

The Problem · What It Does · Quick Start · Commands · Languages · AI Integration · How It Works · Practices · Roadmap

The Problem

AI agents face an impossible trade-off. They either spend thousands of tokens reading files to understand a codebase's structure — blowing up their context window until quality degrades — or they assume how things work, and the assumptions are often wrong. Either way, things break. The larger the codebase, the worse i

Read from source at commit f3a3aaadf990OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add lib --env CODEGRAPH_LLM_API_KEY=${CODEGRAPH_LLM_API_KEY} -- npx -y @myorg/[email protected]
claude-desktop
{
  "mcpServers": {
    "lib": {
      "command": "npx",
      "args": [
        "-y",
        "@myorg/[email protected]"
      ],
      "env": {
        "CODEGRAPH_LLM_API_KEY": "${CODEGRAPH_LLM_API_KEY}"
      }
    }
  }
}
03

Exposed tools (49)

42 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ast_queryreadSearch stored AST nodes (calls, literals, new, throw, await) by pattern. Requires a prior build.
auditreadComposite report combining explain, fn-impact, and health metrics for a file or function. Returns structure, blast radius, complexity, and threshold breaches in one call.
batch_querywriteRun a query command against multiple targets in one call. Returns all results in a single JSON payload — ideal for multi-agent dispatch.
branch_comparewriteCompare code structure between two git refs (branches, tags, commits). Shows added/removed/changed symbols and transitive caller impact using temporary git worktrees.
briefreadToken-efficient file summary: symbols with roles and transitive caller counts, importer counts, and file risk tier (high/medium/low). Designed for context injection.
cfgreadShow intraprocedural control flow graph for a function.
checkwriteCI gate: run manifesto rules (no args), diff predicates (with ref/staged), or both (with rules flag). Returns pass/fail verdicts.
co_changeswriteFind files that historically change together based on git commit history. Requires prior
code_ownersreadShow CODEOWNERS mapping for files and functions. Shows ownership coverage, per-owner breakdown, and cross-owner boundary edges.
communitiesreadDetect natural module boundaries using Leiden community detection
complexityreadShow per-function complexity metrics (cognitive, cyclomatic, nesting, Halstead, Maintainability Index). Sorted by most complex first.
configreadShow or manage codegraph configuration (project + user-level global config)
contextreadFull context for a function: source code, dependencies with summaries, callers, signature, and related tests — everything needed to understand or modify a function in one call
cyclesreadDetect circular dependencies in the codebase
dataflowreadShow data flow edges or data-dependent blast radius.
diff_impactreadAnalyze git diff to find which functions changed and their transitive callers
execution_flowreadTrace execution flow forward from an entry point through callees to leaves, or list all entry points with list=true
exportreadExport dependency graph as DOT, Mermaid, JSON, GraphML, GraphSON, or Neo4j CSV
export_graphreadExport the dependency graph in DOT, Mermaid, JSON, GraphML, GraphSON, or Neo4j CSV format
file_depsreadShow what a file imports and what imports it
file_exportsreadShow exported symbols of a file with per-symbol consumers — who calls each export and from where
find_cyclesreadDetect circular dependencies in the codebase
fn_impactreadShow function-level blast radius: all functions transitively affected by changes to a function
impact_analysisreadShow files affected by changes to a given file (transitive)
implementationsreadList all concrete types (classes, structs, records) that implement a given interface or trait
inforeadShow codegraph engine info and diagnostics
interfacesreadList all interfaces and traits that a given class, struct, or record implements
listreadList all registered repositories
list_functionsreadList functions, methods, classes, structs, enums, traits, records, and modules in the codebase, optionally filtered by file or name pattern
list_reposreadList all repositories registered in the codegraph registry
mapreadHigh-level module overview with most-connected nodes
mcpwriteStart MCP (Model Context Protocol) server for AI assistant integration
modelsreadList available embedding models
module_mapreadGet high-level overview of most-connected files
node_rolesreadShow node role classification (entry, core, utility, adapter, dead [dead-leaf, dead-entry, dead-ffi, dead-unresolved], leaf) based on connectivity patterns
pathreadFind shortest path between two symbols (or files with file_mode) in the dependency graph
plotreadGenerate an interactive HTML dependency graph viewer
prunedestructiveRemove stale registry entries (missing directories or idle beyond TTL)
queryreadQuery the call graph: find callers/callees with transitive chain, or find shortest path between two symbols
registryreadManage the multi-repo project registry
rolesreadShow node role classification: entry, core, utility, adapter, dead (dead-leaf, dead-entry, dead-ffi, dead-unresolved), leaf
semantic_searchreadSearch code symbols by meaning using embeddings and/or keyword matching (requires prior
sequencereadGenerate a Mermaid sequence diagram from call graph edges. Participants are files, messages are function calls between them.
snapshotwriteSave and restore graph database snapshots
statsreadShow graph health overview: nodes, edges, languages, cycles, hotspots, embeddings
structurereadShow project structure with directory hierarchy, cohesion scores, and per-file metrics. Per-file details are capped at 25 files by default; use full=true to show all.
symbol_childrenreadList sub-declaration children of a symbol: parameters, properties, constants. Answers
triagereadRanked audit queue by composite risk score (connectivity + complexity + churn + role)
wherereadFind where a symbol is defined and used, or list symbols/imports/exports for a file. Minimal, fast lookup.
04

Trust audit

BLOCKgrade F · trust 38/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (16 observation(s))
Network
declared (3 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.claude/skills/sweep/SKILL.md:88
All subagents in this sweep — and any other concurrent session — share one authenticated `gh` identity's rate limit (5000 REST requests/hour). Polling too tightly, or re-fetching every endpoint on eve
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
crates/codegraph-core/src/db/connection.rs:807
pub fn exec(&self, sql: String) -> napi::Result<()> {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/domain/graph/builder/native-db-proxy.ts:60
exec(sql: string): this {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/types.ts:608
| 'eval' // eval() / new Function() — undecidable; always flagged
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/types.ts:2766
exec(sql: string): this;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/types.ts:3150
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/reports/claude-code-architecture-lessons.md:164
### 11. Seven-Step Permission Pipeline with Bypass-Immune Safety Checks
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/reports/claude-code-architecture-lessons.md:171
4-7. **Bypass-immune safety guardrails** — fire even in `bypassPermissions` mode
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.binary · CWE-1104
grammars/tree-sitter-erlang.wasm
tree-sitter-erlang.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/codegraph-core/src/extractors/javascript.rs:12038
let s = parse_js("const conn = Ωmega.create();");
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/codegraph-core/src/extractors/javascript.rs:12045
assert_eq!(tm.unwrap().type_name, "Ωmega");
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
prune
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codegraphrc.example.json
.codegraphrc.example.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codegraphrc.json
.codegraphrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.versionrc.json
.versionrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
.claude/hooks/snapshot-pre-bash.sh:52
process.stdout.write(crypto.createHash('sha1').update(d.trim()).digest('hex').slice(0,8));
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
.claude/hooks/snapshot-pre-bash.sh:61
process.stdout.write(crypto.createHash('sha1').update(d.trim()).digest('hex').slice(0,8));
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
.claude/hooks/track-bash-writes.sh:39
process.stdout.write(crypto.createHash('sha1').update(d.trim()).digest('hex').slice(0,8));
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
.claude/hooks/track-bash-writes.sh:48
process.stdout.write(crypto.createHash('sha1').update(d.trim()).digest('hex').slice(0,8));
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
crates/codegraph-core/src/domain/graph/builder/stages/detect_changes.rs:8
//! Note: Uses SHA-256 (not MD5). The JS pipeline uses MD5 via `createHash('md5')`,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/codegraph-core/src/domain/graph/resolve.rs:1780
clean_path(Path::new("src/cli/commands/../../domain/graph/builder.js")),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/codegraph-core/src/domain/graph/resolve.rs:1812
assert_eq!(clean_path(Path::new("../../foo")), PathBuf::from("foo"));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/codegraph-core/src/extractors/javascript.rs:9530
"const { buildDataflowVerticesFromMap, buildDataflowEdges } = (await import('../../../../features/dataflow.js')) as { buildDataflowVerticesFromMap: Fn; buildDataflowEdges: Fn };",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/codegraph-core/src/extractors/javascript.rs:9538
assert_eq!(dyn_imports[0].source, "../../../../features/dataflow.js");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/import-jelly-micro.mjs:83
const SCHEMA = '../../../expected-edges.schema.json';

Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-07 · audit v0.4.1 · source sha f3a3aaadf990full audit observations/trust-audit/mcp-server/optave__codegraph-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07f3a3aaadf990BLOCKF38first audit
06

Questions

What is the Codegraph MCP server?

Code intelligence CLI — function-level dependency graph across 34 languages, 34-tool MCP server for AI agents, complexity metrics, architecture boundary enforcement, CI quality gates, git diff impact with co-change analysis, hybrid semantic search. Fully local, zero API keys required.

What tools does Codegraph expose?

49 in total: 42 read-only, 6 that write, and 1 that can delete or overwrite (prune). Every one is listed on this page with its risk.

Is Codegraph safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (38/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Codegraph need?

It reads CODEGRAPH_LLM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Codegraph run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @myorg/lib at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (f3a3aaadf990), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement