GographCAUTION
Local-only Go static analysis engine with a built-in MCP server. Gives AI coding agents deterministic structural awareness: call graphs, impact analysis, symbol search, and more.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Symbol queries accept path/to/file.go:Name, including path/to/file.go:Receiver.Method, or an import-qualified file path when a short name is ambiguous. source prints exact selectors for ambiguous matches. Precise indexes include package-level constant references in usages, and review uses the same test attribution as context. Rebuild after upgrading.
review --uncommitted includes deleted declarations from changes --git HEAD and explicitly leaves historical callers, tests and risk unevaluated. Other current-graph traversal commands retain their deletion refusal. Builds explain when an enclosing Git repository ignores the requested directory.
Session audits list invocation errors separately from operational failures and exclude them from compliance scoring. Composability measures the mix of composed and raw query commands; it does not measure answer correctness or token savings.
[](https://goreportcard.com/report/github.com/ozgurcd/gograph) [](https://opensource.org/licenses/MIT) [](https://github.com/ozgurcd/gograph) [](https://github.com/ozgurcd/homebrew-tap) [](https://gograph.identuum.ai)
Give Go coding agents a compiler-aware map for safer refactors.
gograph builds a local structural graph of your Go repository, with optional type-checked CHA/SSA enrichment. Its CLI and MCP workflows help coding agents trace callers and interface implementations, plan change impact, and enforce architecture without embeddings or a hosted code index.
[Explore the interactive no-install demo](https://gograph.identuum.ai/demo/) · Review the reproducible benchmark
3275c3d5f884OBSERVED · 2026-10-06Trust audit
CAUTIONgrade C · trust 78/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (21)
precise targets; it does not hide imported dependency errors or bypass safety
.bumpversion.cfg
.goreleaser.yaml
.gitmodules
.hugo_build.lock
func handle(r *http.Request, body []byte, db interface{ Exec(string, ...any) error }) {func localConst(db interface{ Exec(string, ...any) }) {func localVar(db interface{ Exec(string, ...any) }) {func shortDeclaration(db interface{ Exec(string, ...any) }) {func ordinaryAssignment(db interface{ Exec(string, ...any) }) {if err := os.WriteFile(filepath.Join(analysisRoot, "go.work"), []byte("go 1.26\n\nuse (\n\t.\n\t../../mesa2/core\n)\n"), 0o644); err != nil {if err := os.WriteFile(filepath.Join(analysisRoot, "go.work"), []byte("go 1.26\n\nuse (\n\t.\n\t../../sibling\n)\n"), 0o644); err != nil {if err := os.CopyFS(root, os.DirFS("../../testdata/answers1710")); err != nil {if err := os.CopyFS(snapshot, os.DirFS("../../testdata/answers1710")); err != nil {if err := os.CopyFS(root, os.DirFS("../../testdata/answers177")); err != nil {**Native MCP Server** — all 64 repository query, analysis, and workflow capabilities have project-MCP equivalents for Claude, Cursor, Copilot, and other MCP clients; four additional endpoints cover se
"articleBody": "Claims you can reproduce gograph’s checked-in benchmark uses a controlled Go fixture with manually reviewable ground truth. It verifies implicit interface implementations, interface-di
All 64 repository query, analysis, and workflow capabilities must remain semantically equivalent across CLI and the project MCP server; four additional project-MCP endpoints implement session lifecycl
`gograph` is a local Go repository indexer for coding agents. CLI and the project MCP server share 64 repository query, analysis, and workflow capabilities; four additional session tools make 68 proje
- **Project metadata reads** — in addition to `.go` files, gograph reads regular `go.mod`, `go.sum`, `go.work`, `go.work.sum`, and `vendor/modules.txt` metadata, `.gitignore`, Git state, `.gograph/gra
Gates applied: instruction_override, no_behavioural_pass.
3275c3d5f884full audit observations/trust-audit/mcp-server/ozgurcd__gograph.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 3275c3d5f884 | CAUTION | C | 78 | first audit |
Questions
What is the Gograph MCP server?
Local-only Go static analysis engine with a built-in MCP server. Gives AI coding agents deterministic structural awareness: call graphs, impact analysis, symbol search, and more.
Is Gograph safe to connect to an agent?
With care. The audit graded it C (78/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Gograph need?
No credential environment variables were found in its source, so it appears to need none.
How does Gograph run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (3275c3d5f884), read on 2026-10-06. The repository is watched and re-audited when it changes.