Atlas / MCP servers / patricksys / Codebase Context

Codebase ContextCAUTION

mcp/patricksys/codebase-context

Codebase Context gives AI agents understanding of your codebase through semantic code search, team conventions, patterns, and memory, so they use fewer tokens, spend less time, and produce better, more familiar output.

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
12 11r · 1w · 0d
Transport
stdio · streamable-http
License
NOASSERTION
Stars
65
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/codebase-context) [](./LICENSE) [](https://github.com/PatrickSys/codebase-context/blob/master/package.json)

Your coding agent doesn't understand your codebase.

Coding agents can read files, but they still have to discover how your repository is organized, which patterns your team follows, and which examples are worth copying.

Codebase Context gives an agent a local view of that information through code search, team patterns, strong examples, and project memory. It runs as an MCP server - a local tool that your editor or command-line agent can call while it works - and keeps the index on your machine by default.

Set up your AI client

Choose your coding tool and run its command once. Use Node.js 22 or newer. These commands use published npm 2.2.0 and do not require a project folder in your configuration:

# Claude Code
claude mcp add --scope user --transport stdio codebase-context -- npx -y [email protected]

# Codex CLI
codex mcp add codebase-context -- npx -y [email protected]

# OpenCode 1.x (keep the quoted separator on Windows)
opencode mcp add codebase-context '--' npx -y [email protected]

Start a new agent session in your project, then ask:

Use Codebase Context to find [feature] in this repository. Pass this repository's absolute path as project when checking getindexingstatus and searching. Wait for indexing if needed, read codebase://context, then search_codebase and open a returned source file. Show me the relevant files.

Replace [feature] with something you want to find. The agent supplies the repository path in its tool calls, so the registration can serve different projects. Initial indexing may need a local model download. The October 6 isolated checks proved these client registration

Read from source at commit a2d12099718bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add eval-controlled-fixture --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "eval-controlled-fixture": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (12)

11 read · 1 write · 0 destructive.

ToolRiskDescription
detect_circular_dependencieswriteAnalyze the import graph to detect circular dependencies between files.
echo_searchreadEchoes the incoming query
get_codebase_healthreadGet actionable codebase health signals from the latest index. Returns the highest-risk files and their reasons, or a single file when requested.
get_codebase_metadatareadGet codebase metadata including framework information, dependencies, architecture patterns,
get_indexing_statusreadGet current indexing status: state, statistics, and progress.
get_memoryreadRetrieves team conventions, architectural decisions, and known gotchas.\n
get_style_guidereadQuery style guide rules and architectural patterns from project documentation.
get_symbol_referencesreadFind concrete references to a symbol in indexed chunks. Returns total usageCount and top usage snippets.
get_team_patternsreadGet actionable team pattern recommendations based on codebase analysis.
refresh_indexreadRe-index the codebase. Supports full re-index or incremental mode.
rememberreadCALL IMMEDIATELY when user explicitly asks to remember/record something.\n\n
search_codebasereadSearch the indexed codebase. Default compact mode returns at most 6 ranked results with
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
src/tools/search-payload-budget.ts
search-payload-budget.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/eval/harness.ts:101
return crypto.createHash('sha1').update(normalizePath(filePath)).digest('hex').slice(0, 8);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/analyzers/angular/index.ts:21
} from '../../types/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/analyzers/angular/index.ts:22
import { createChunksFromCode } from '../../utils/chunking.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/analyzers/angular/index.ts:26
} from '../../constants/codebase-context.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/analyzers/angular/index.ts:27
import { registerComplementaryPatterns } from '../../patterns/semantics.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/analyzers/generic/index.ts:18
} from '../../types/index.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/contextbench-final-lane-readiness.yml:31
OLLAMA_HOST: http://127.0.0.1:11434
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/contextbench-grepai-readiness.yml:23
OLLAMA_HOST: http://127.0.0.1:11434
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/contextbench-infra-lane-readiness.yml:31
OLLAMA_HOST: http://127.0.0.1:11434
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/capabilities.md:12
| **HTTP**            | `npx -y [email protected] --http [--port N]` | `http://127.0.0.1:3100/mcp`  |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/client-setup.md:326
The documented default endpoint is `http://127.0.0.1:3100/mcp`. Config-shape templates are available in [`templates/mcp/stdio/.mcp.json`](../templates/mcp/stdio/.mcp.json) and [`templates/mcp/http/.mc
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@huggingface/transformers, @inquirer/prompts, @lancedb/lancedb, @modelcontextprotocol/sdk, @typescript-eslint/typescript-estree, chokidar, fuse.js, glob
Why it matters. 30 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
tests/fixtures/README.md:249
curl -sSL https://raw.githubusercontent.com/yoanbernabeu/grepai/main/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
tests/fixtures/README.md:280
curl -fsSL https://raw.githubusercontent.com/DeusData/codebase-memory-mcp/main/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha a2d12099718bfull audit observations/trust-audit/mcp-server/patricksys__codebase-context.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07a2d12099718bCAUTIONB86first audit
06

Questions

What is the Codebase Context MCP server?

Codebase Context gives AI agents understanding of your codebase through semantic code search, team conventions, patterns, and memory, so they use fewer tokens, spend less time, and produce better, more familiar output.

What tools does Codebase Context expose?

12 in total: 11 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Codebase Context safe to connect to an agent?

With care. The audit graded it B (86/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Codebase Context need?

It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Codebase Context run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as eval-controlled-fixture at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (a2d12099718b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement