Codebase ContextCAUTION
Codebase Context gives AI agents understanding of your codebase through semantic code search, team conventions, patterns, and memory, so they use fewer tokens, spend less time, and produce better, more familiar output.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/codebase-context) [](./LICENSE) [](https://github.com/PatrickSys/codebase-context/blob/master/package.json)
Your coding agent doesn't understand your codebase.
Coding agents can read files, but they still have to discover how your repository is organized, which patterns your team follows, and which examples are worth copying.
Codebase Context gives an agent a local view of that information through code search, team patterns, strong examples, and project memory. It runs as an MCP server - a local tool that your editor or command-line agent can call while it works - and keeps the index on your machine by default.
Set up your AI client
Choose your coding tool and run its command once. Use Node.js 22 or newer. These commands use published npm 2.2.0 and do not require a project folder in your configuration:
# Claude Code claude mcp add --scope user --transport stdio codebase-context -- npx -y [email protected] # Codex CLI codex mcp add codebase-context -- npx -y [email protected] # OpenCode 1.x (keep the quoted separator on Windows) opencode mcp add codebase-context '--' npx -y [email protected]
Start a new agent session in your project, then ask:
Use Codebase Context to find [feature] in this repository. Pass this repository's absolute path as project when checking getindexingstatus and searching. Wait for indexing if needed, read codebase://context, then search_codebase and open a returned source file. Show me the relevant files.
Replace [feature] with something you want to find. The agent supplies the repository path in its tool calls, so the registration can serve different projects. Initial indexing may need a local model download. The October 6 isolated checks proved these client registration
a2d12099718bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add eval-controlled-fixture --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"eval-controlled-fixture": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (12)
11 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
detect_circular_dependencies | write | Analyze the import graph to detect circular dependencies between files. |
echo_search | read | Echoes the incoming query |
get_codebase_health | read | Get actionable codebase health signals from the latest index. Returns the highest-risk files and their reasons, or a single file when requested. |
get_codebase_metadata | read | Get codebase metadata including framework information, dependencies, architecture patterns, |
get_indexing_status | read | Get current indexing status: state, statistics, and progress. |
get_memory | read | Retrieves team conventions, architectural decisions, and known gotchas.\n |
get_style_guide | read | Query style guide rules and architectural patterns from project documentation. |
get_symbol_references | read | Find concrete references to a symbol in indexed chunks. Returns total usageCount and top usage snippets. |
get_team_patterns | read | Get actionable team pattern recommendations based on codebase analysis. |
refresh_index | read | Re-index the codebase. Supports full re-index or incremental mode. |
remember | read | CALL IMMEDIATELY when user explicitly asks to remember/record something.\n\n |
search_codebase | read | Search the indexed codebase. Default compact mode returns at most 6 ranked results with |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
search-payload-budget.ts
.gitmodules
.release-please-manifest.json
return crypto.createHash('sha1').update(normalizePath(filePath)).digest('hex').slice(0, 8);} from '../../types/index.js';
import { createChunksFromCode } from '../../utils/chunking.js';} from '../../constants/codebase-context.js';
import { registerComplementaryPatterns } from '../../patterns/semantics.js';} from '../../types/index.js';
OLLAMA_HOST: http://127.0.0.1:11434
OLLAMA_HOST: http://127.0.0.1:11434
OLLAMA_HOST: http://127.0.0.1:11434
| **HTTP** | `npx -y [email protected] --http [--port N]` | `http://127.0.0.1:3100/mcp` |
The documented default endpoint is `http://127.0.0.1:3100/mcp`. Config-shape templates are available in [`templates/mcp/stdio/.mcp.json`](../templates/mcp/stdio/.mcp.json) and [`templates/mcp/http/.mc
@huggingface/transformers, @inquirer/prompts, @lancedb/lancedb, @modelcontextprotocol/sdk, @typescript-eslint/typescript-estree, chokidar, fuse.js, glob
curl -sSL https://raw.githubusercontent.com/yoanbernabeu/grepai/main/install.sh | sh
curl -fsSL https://raw.githubusercontent.com/DeusData/codebase-memory-mcp/main/install.sh | bash
Gates applied: no_behavioural_pass.
a2d12099718bfull audit observations/trust-audit/mcp-server/patricksys__codebase-context.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a2d12099718b | CAUTION | B | 86 | first audit |
Questions
What is the Codebase Context MCP server?
Codebase Context gives AI agents understanding of your codebase through semantic code search, team conventions, patterns, and memory, so they use fewer tokens, spend less time, and produce better, more familiar output.
What tools does Codebase Context expose?
12 in total: 11 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Codebase Context safe to connect to an agent?
With care. The audit graded it B (86/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Codebase Context need?
It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Codebase Context run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as eval-controlled-fixture at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (a2d12099718b), read on 2026-10-07. The repository is watched and re-audited when it changes.