Atlas / MCP servers / postrv / Narsil

NarsilBLOCK

mcp/postrv/narsil

Rust MCP server for comprehensive code intelligence - 90 tools, 32 languages, security scanning, call graphs, and more

Verdict
BLOCK
Grade
F
Trust score
53 /100
Exposed tools
96 84r · 12w · 0d
Transport
—
License
Apache-2.0
Stars
184
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The blazing-fast, privacy-first MCP server for deep code intelligence

[](LICENSE-MIT) [](https://www.rust-lang.org) [](https://github.com/postrv/narsil-mcp) [](https://modelcontextprotocol.io)

A Rust-powered MCP (Model Context Protocol) server providing AI assistants with deep code understanding through 90 specialized tools.

Why narsil-mcp?

Key Features

  • Code Intelligence - Symbol extraction, semantic search, call graph analysis
  • Neural Semantic Search - Find similar code using embeddings (Voyage AI, OpenAI)
  • Security Analysis - Taint analysis, vulnerability scanning, OWASP/CWE coverage
  • Supply Chain Security - SBOM generation, dependency auditing, license compliance
  • Advanced Analysis - Control flow graphs, data flow analysis, dead code detection

Why Choose narsil-mcp?

  • Written in Rust - Blazingly fast, memory-safe, single binary (~30MB)
  • Tree-sitter powered - Accurate, incremental parsing for 32 languages
  • Zero config - Point at repos and go
  • MCP compliant - Works with Claude, Cursor, VS Code Copilot, Zed, and any MCP client
  • Privacy-first - Fully local, no data leaves your machine
  • Parallel indexing - Uses all cores via Rayon
  • Smart excerpts - Expands
Read from source at commit c95b55984ca6OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add narsil-mcp --env API_KEY=${API_KEY} --env DATABASE_PASSWORD=${DATABASE_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "narsil-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "DATABASE_PASSWORD": "${DATABASE_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (96)

84 read · 12 write · 0 destructive.

ToolRiskDescription
add_remote_repowriteAdd a remote GitHub repository for indexing. Clones the repo to a temporary location.
check_cwe_top25readScan for CWE Top 25 Most Dangerous Software Weaknesses including buffer overflows, injection, improper input validation.
check_dependenciesreadCheck project dependencies for known vulnerabilities using the OSV (Open Source Vulnerabilities) database. Returns CVE/GHSA IDs and recommended upgrades.
check_licensesreadAnalyze dependency licenses for compliance issues. Detects copyleft licenses, unknown licenses, and license compatibility problems.
check_owasp_top10readScan specifically for OWASP Top 10 2021 vulnerabilities including injection, broken auth, XSS, SSRF, etc.
check_type_errorsreadFind potential type errors in Python/JavaScript/TypeScript code without running mypy/tsc. Detects type mismatches, undefined variables, etc.
discover_reposreadAuto-discover repositories in a directory by detecting VCS roots and project markers
explain_vulnerabilityreadGet detailed explanation of a security vulnerability type including examples, references, and remediation guidance.
export_ccgreadExport all CCG layers as a bundle to a directory. Generates manifest.json, architecture.json, symbol-index.nq.gz.b64, and full-detail.nq.gz.b64.
export_ccg_architecturereadExport CCG Layer 1 architecture (~10-50KB JSON-LD) with module hierarchy, public API, and dependencies.
export_ccg_fullreadExport CCG Layer 3 full detail (~1-20MB N-Quads gzipped) with complete RDF dataset including imports and security findings.
export_ccg_indexreadExport CCG Layer 2 symbol index (~100-500KB N-Quads gzipped) with all symbols and call graph edges.
export_ccg_manifestreadExport CCG Layer 0 manifest to a file. Returns content or writes to specified path.
find_call_pathreadFind the call path between two functions. Requires --call-graph flag.
find_callsreadFind what a function calls and what calls it
find_circular_importswriteDetect circular import dependencies in the codebase. Returns all cycles with the files involved.
find_dead_codereadFind unreachable code blocks in a function or file using control flow analysis.
find_dead_storesreadFind variable assignments that are never read (dead stores).
find_functionsreadFind all functions in a repository
find_functions_by_namereadFind functions matching a name pattern
find_importswriteFind import relationships for a file
find_injection_vulnerabilitiesreadFind injection vulnerabilities (SQL injection, XSS, command injection, path traversal) using taint analysis.
find_referencesreadFind all references to a symbol across the codebase
find_security_findingsreadFind security findings at or above a severity threshold
find_semantic_clonesreadFind semantically similar code (Type-3/4 clones) using neural embeddings. Detects code that does the same thing with different implementation.
find_similar_codereadFind code similar to a given snippet using TF-IDF embeddings. Good for finding duplicate or related code patterns.
find_similar_to_symbolreadFind code similar to a specific symbol (function, class, etc.). Useful for finding related implementations or potential duplicates.
find_symbol_usagesreadFind all usages of a symbol across files, including imports and re-exports. Cross-language aware for JS/TS projects.
find_symbolsreadFind data structures (structs, classes, enums, interfaces) and functions/methods in a repository. Supports filtering by type and name pattern.
find_symbols_in_filereadFind all symbols defined in a specific file
find_uninitializedreadFind variables that may be used before being initialized.
find_unused_exportsreadDetect exported symbols never imported by other files in repo. Cross-file analysis using import graph. Configurable to exclude public API surface.
find_upgrade_pathreadFind safe upgrade paths for vulnerable dependencies. Shows which versions fix known vulnerabilities and whether upgrades have breaking changes.
generate_sbomreadGenerate a Software Bill of Materials (SBOM) for a project. Supports CycloneDX and SPDX formats. Parses Cargo.toml, package.json, requirements.txt, and go.mod.
get_blamereadGet git blame information for a file. Requires --git flag.
get_branch_inforeadGet current branch name and repository status. Requires --git flag.
get_call_graphreadGet the call graph for a repository or specific function. Requires --call-graph flag.
get_calleesreadFind functions called by a given function. Requires --call-graph flag.
get_callersreadFind functions that call a given function. Requires --call-graph flag.
get_ccg_access_inforeadGet information about CCG access tiers and permissions. Explains the Triple-Heart Model and WebACL configuration.
get_ccg_aclreadGenerate WebACL access control document for CCG layers. Supports Triple-Heart Model (public/authenticated/private tiers).
get_ccg_manifestreadGet CCG Layer 0 manifest (~1-2KB JSON-LD) with repository identity, symbol counts, languages, and security summary. Always fits in AI context window.
get_chunk_statsreadGet statistics about code chunks in a repository.
get_chunksreadGet AST-aware code chunks for a file with symbol context.
get_code_graphwriteGet graph visualization data (call graph, import graph, symbols). HTTP-only tool, not available via MCP.
get_commit_diffwriteGet the diff for a specific commit. Requires --git flag.
get_complexityreadGet complexity metrics (cyclomatic, cognitive) for a function. Requires --call-graph flag.
get_contributorsreadGet contributors to a file or repository. Requires --git flag.
get_control_flowreadGet the control flow graph (CFG) for a function, showing basic blocks, branches, and loops.
get_data_flowreadGet data flow analysis for a function, showing variable definitions and uses.
get_dependenciesreadAnalyze dependencies and imports for a file or module
get_embedding_statsreadGet statistics about the embedding index.
get_excerptreadExtract code excerpts around specific lines with intelligent context expansion. Automatically expands to function/class boundaries when enabled.
get_export_mapreadGet the export map for a file or module showing all exported symbols and their types.
get_filereadGet the contents of a specific file with optional line range
get_file_historywriteGet git commit history for a file. Requires --git flag.
get_function_hotspotsreadFind highly connected functions (potential refactoring targets) based on call graph analysis. Requires --call-graph flag.
get_hotspotsreadFind code hotspots - files with high churn and complexity. Requires --git flag.
get_hover_inforeadGet hover information (type info, documentation) for a symbol at a specific position. Enhanced with LSP when available.
get_import_graphwriteBuild and analyze the import/dependency graph for a codebase. Shows which files import which other files, helps identify circular dependencies.
get_incremental_statusreadGet status of incremental indexing including Merkle tree root hash, file counts, and change statistics.
get_index_statusreadGet status of the search index and enabled features. Shows which optional features are enabled (--git, --call-graph, --persist, --watch) and index statistics.
get_metricsreadGet performance metrics including tool execution times, indexing statistics, and server uptime
get_modified_filesreadGet list of modified files in the working tree. Requires --git flag.
get_neural_statsreadGet statistics about the neural embedding index. Requires --neural flag.
get_project_structurereadGet the directory structure and key files of a repository. Returns a tree view with file types and sizes.
get_reaching_definitionsreadGet reaching definitions analysis - which variable assignments reach each point in the code.
get_recent_changesreadGet recent commits across the repository. Requires --git flag.
get_remote_filereadFetch a specific file from a remote GitHub repository via API (no clone needed).
get_security_summaryreadGet a comprehensive security summary for a repository including vulnerability counts and risk assessment.
get_symbol_definitionreadGet the full definition of a symbol with surrounding context. Returns the source code with line numbers.
get_symbol_historyreadGet commits that modified a specific symbol/function. Requires --git flag.
get_taint_sourcesreadList all identified taint sources (user inputs, file reads, network data) in the codebase.
get_type_inforeadGet precise type information for a symbol. Requires LSP to be enabled.
get_typed_taint_flowreadEnhanced taint analysis with type information. More precise than untyped taint tracking, combines data flow with type inference.
go_to_definitionreadFind the definition location of a symbol at a specific position. Enhanced with LSP when available.
hybrid_searchreadPerform hybrid search combining BM25 keyword search with TF-IDF semantic similarity using Reciprocal Rank Fusion (RRF).
import_ccgwriteImport a CCG layer from URL or local file. Supports JSON-LD (L0/L1) and gzipped N-Quads (L2/L3) formats.
import_ccg_from_registrywriteImport all CCG layers from the codecontextgraph.com registry for a repository.
infer_typesreadInfer types for variables in a Python/JavaScript/TypeScript function. Shows what types flow through the code without running external type checkers.
list_remote_filesreadList files in a remote GitHub repository via API (no clone needed). Rate limited without GITHUB_TOKEN.
list_reposreadList all indexed repositories with metadata (path, language breakdown, file count)
list_sparql_templatesreadList available SPARQL query templates for common code intelligence patterns. Requires --graph flag.
neural_searchreadSearch code using neural semantic embeddings. Finds semantically similar code even with different variable names. Requires --neural flag and EMBEDDING_API_KEY.
query_ccgreadQuery CCG Layer 3 using SPARQL. Enables rich semantic queries against the full code context graph.
reindexwriteTrigger re-indexing of a repository or all repositories
run_sparql_templatewriteExecute a predefined SPARQL query template with parameters. Requires --graph flag.
scan_securityreadScan repository for security issues using the security rules engine. Detects vulnerabilities, secrets, crypto issues, and more.
search_chunksreadSearch over AST-aware code chunks with symbol context.
search_codereadSemantic and keyword search across code. Returns ranked excerpts with surrounding context.
semantic_searchreadBM25-ranked semantic search with code-aware tokenization. Better than simple text search for natural language queries.
sparql_querywriteExecute a SPARQL query against the RDF knowledge graph. Supports SELECT and ASK queries with timeout and result limits. Requires --graph flag.
suggest_fixreadGet suggested fixes for a specific security finding.
trace_taintreadTrace how tainted data flows from a source location through the code.
validate_reporeadValidate that a path is a valid repository and can be indexed
workspace_symbol_searchreadFuzzy search for symbols across the entire workspace. Uses trigram matching for typo-tolerant search.
04

Trust audit

BLOCKgrade F · trust 53/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (14 observation(s))
Network
declared (23 observation(s))
Shell
declared (14 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
rules/secrets.yaml:230
- '-----BEGIN RSA PRIVATE KEY-----'
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
rules/secrets.yaml:231
- '-----BEGIN PRIVATE KEY-----'
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
rules/secrets.yaml:232
- '-----BEGIN EC PRIVATE KEY-----'
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
rules/secrets.yaml:233
- '-----BEGIN OPENSSH PRIVATE KEY-----'
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
rules/secrets.yaml:234
- '-----BEGIN DSA PRIVATE KEY-----'
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
test-fixtures/security/vulnerable.kt:40
val apiKey = "sk_live_1234567890abcdefghij" // BAD: Hardcoded key
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/security_rules.rs:2484
data = pickle.loads(user_input)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
test-fixtures/security/vulnerable.php:37
$obj = unserialize($data); // BAD: Unserialize user input
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
test-fixtures/security/vulnerable.php:38
return unserialize($_GET['obj']); // BAD
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/taint/patterns.rs:697
"exec(".to_string(),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/taint/patterns.rs:699
"Exec(".to_string(),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/taint/patterns.rs:720
"exec(".to_string(),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/taint/patterns.rs:783
"eval(".to_string(),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/taint/patterns.rs:784
"exec(".to_string(),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.claude/hooks/security-filter.sh:77
"$HOME/.ssh/"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.claude/hooks/security-filter.sh:78
"/home/*/.ssh/"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.claude/hooks/security-filter.sh:80
"cat.*id_rsa"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.claude/hooks/security-filter.sh:81
"cat.*id_ed25519"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
.claude/hooks/security-filter.sh:82
"cat.*id_ecdsa"
Why it matters. touches a credential store
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/ccg/import.rs:1176
validate_url_for_ssrf("http://169.254.169.254/metadata", SsrfPolicy::BlockPrivate)
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/neural.rs:1414
let result = validate_embedding_endpoint("http://169.254.169.254/latest/meta-data/");
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/neural.rs:1422
validate_embedding_endpoint("http://metadata.google.internal/computeMetadata/v1/");
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/validation.rs:196
host == "169.254.169.254"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/validation.rs:199
|| host == "metadata.google.internal"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
rules/bash.yaml:75
remediation: Remove -k/--insecure flag and ensure proper CA certificates are installed
Why it matters. certificate verification is disabled
Fix. leave verification on

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha c95b55984ca6full audit observations/trust-audit/mcp-server/postrv__narsil.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06c95b55984ca6BLOCKF53first audit
06

Questions

What is the Narsil MCP server?

Rust MCP server for comprehensive code intelligence - 90 tools, 32 languages, security scanning, call graphs, and more

What tools does Narsil expose?

96 in total: 84 read-only, 12 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Narsil safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (53/100) and found 25 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Narsil need?

It reads API_KEY and DATABASE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (c95b55984ca6), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement