GdepCAUTION
Game Codebase Analysis AI Agentic Tool
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Understand a Unity/UE5/Axmol project in 0.5 seconds. Make Claude and Cursor read the actual code.
[](https://github.com/pirua-game/gdep/actions/workflows/ci.yml) [](https://pypi.org/project/gdep/) [](https://www.npmjs.com/package/gdep-mcp)
"If I modify this class, what breaks?" — answered in 3 seconds, grounded in source. Source-grounded: structural facts from C++ source and binary assets. Confidence tier (HIGH/MEDIUM/LOW) reported on every result.
Read this in other languages: 한국어 · 日本語 · 简体中文 · 繁體中文
✨ Why gdep?
Large game codebases are brutal:
- UE5 with 300+ Blueprints → "Where is this Ability actually called?" — half a day gone
- Unity with 50 Managers + Prefab refs → refactor triggers circular dep explosion
- "What breaks if I change this class?" → open files manually for 30 minutes
gdep answers all of this in under 0.5 seconds.
Measured Performance
Full details → docs/BENCHMARK.md · docs/mcp-benchmark.md
🤖 MCP Integration — Make AI Read Real Code
gdep ships an MCP server for Claude Desktop, Cursor, and any MCP-compatible agent.
Install in 1 line
npm install -g gdep-mcp
Configure your agent (copy-paste)
{
"mcpServers": {
"gdep": {
"command": "gdep-mcp",
"env": { "PYTHONUTF8": "1" }
}
}
}That's it. Your AI now has 30 game-engine-aware tools available
85ce73c46493OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add frontend -- npx -y [email protected]
{
"mcpServers": {
"frontend": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (30)
27 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_axmol_events | read | |
analyze_impact_and_risk | read | |
analyze_ue5_animation | read | |
analyze_ue5_behavior_tree | read | |
analyze_ue5_blueprint_mapping | read | |
analyze_ue5_gas | read | |
analyze_ue5_state_tree | read | |
analyze_unity_animator | read | |
detect_patterns | read | |
execute_gdep_cli | write | |
explain_method_logic | read | |
explore_class_semantics | read | |
find_call_path | read | |
find_class_hierarchy | read | |
find_method_callers | read | |
find_unity_event_bindings | read | |
find_unused_assets | read | |
get_architecture_advice | read | |
get_project_context | read | |
inspect_architectural_health | read | |
query_project_api | read | |
read_class_source | read | |
suggest_lint_fixes | write | Run linter and return actionable code fix suggestions for detected anti-patterns. |
suggest_test_scope | read | |
summarize_project_diff | read | |
trace_gameplay_flow | read | |
wiki_get | read | |
wiki_list | read | |
wiki_save_conversation | write | |
wiki_search | read |
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
Spectre.Console.dll
System.Collections.Immutable.dll
System.Reflection.Metadata.dll
gdep.dll
Spectre.Console.dll
_sig = hashlib.md5(
h = hashlib.md5()
return hashlib.md5("\n".join(mtimes).encode()).hexdigest()h = hashlib.md5()
h = hashlib.md5()
requests, click, fastapi, uvicorn, pydantic, tree-sitter, tree-sitter-c, tree-sitter-cpp
fastapi, uvicorn, pydantic, requests
@dagrejs/dagre, @types/dagre, @xyflow/react, axios, lucide-react, react, react-dom, @eslint/js
gdep-cli/gdep/bin/Microsoft.CodeAnalysis.CSharp.dll
gdep-cli/gdep/bin/Microsoft.CodeAnalysis.dll
gdep_logo.png
publish/Microsoft.CodeAnalysis.CSharp.dll
publish/Microsoft.CodeAnalysis.dll
Gates applied: no_behavioural_pass.
85ce73c46493full audit observations/trust-audit/mcp-server/pirua-game__gdep.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 85ce73c46493 | CAUTION | B | 81 | first audit |
Questions
What is the Gdep MCP server?
Game Codebase Analysis AI Agentic Tool
What tools does Gdep expose?
30 in total: 27 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Gdep safe to connect to an agent?
With care. The audit graded it B (81/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Gdep need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (85ce73c46493), read on 2026-10-07. The repository is watched and re-audited when it changes.