NarsilBLOCK
Rust MCP server for comprehensive code intelligence - 90 tools, 32 languages, security scanning, call graphs, and more
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The blazing-fast, privacy-first MCP server for deep code intelligence
[](LICENSE-MIT) [](https://www.rust-lang.org) [](https://github.com/postrv/narsil-mcp) [](https://modelcontextprotocol.io)
A Rust-powered MCP (Model Context Protocol) server providing AI assistants with deep code understanding through 90 specialized tools.
Why narsil-mcp?
Key Features
- Code Intelligence - Symbol extraction, semantic search, call graph analysis
- Neural Semantic Search - Find similar code using embeddings (Voyage AI, OpenAI)
- Security Analysis - Taint analysis, vulnerability scanning, OWASP/CWE coverage
- Supply Chain Security - SBOM generation, dependency auditing, license compliance
- Advanced Analysis - Control flow graphs, data flow analysis, dead code detection
Why Choose narsil-mcp?
- Written in Rust - Blazingly fast, memory-safe, single binary (~30MB)
- Tree-sitter powered - Accurate, incremental parsing for 32 languages
- Zero config - Point at repos and go
- MCP compliant - Works with Claude, Cursor, VS Code Copilot, Zed, and any MCP client
- Privacy-first - Fully local, no data leaves your machine
- Parallel indexing - Uses all cores via Rayon
- Smart excerpts - Expands
c95b55984ca6OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add narsil-mcp --env API_KEY=${API_KEY} --env DATABASE_PASSWORD=${DATABASE_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"narsil-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"DATABASE_PASSWORD": "${DATABASE_PASSWORD}"
}
}
}
}Exposed tools (96)
84 read · 12 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_remote_repo | write | Add a remote GitHub repository for indexing. Clones the repo to a temporary location. |
check_cwe_top25 | read | Scan for CWE Top 25 Most Dangerous Software Weaknesses including buffer overflows, injection, improper input validation. |
check_dependencies | read | Check project dependencies for known vulnerabilities using the OSV (Open Source Vulnerabilities) database. Returns CVE/GHSA IDs and recommended upgrades. |
check_licenses | read | Analyze dependency licenses for compliance issues. Detects copyleft licenses, unknown licenses, and license compatibility problems. |
check_owasp_top10 | read | Scan specifically for OWASP Top 10 2021 vulnerabilities including injection, broken auth, XSS, SSRF, etc. |
check_type_errors | read | Find potential type errors in Python/JavaScript/TypeScript code without running mypy/tsc. Detects type mismatches, undefined variables, etc. |
discover_repos | read | Auto-discover repositories in a directory by detecting VCS roots and project markers |
explain_vulnerability | read | Get detailed explanation of a security vulnerability type including examples, references, and remediation guidance. |
export_ccg | read | Export all CCG layers as a bundle to a directory. Generates manifest.json, architecture.json, symbol-index.nq.gz.b64, and full-detail.nq.gz.b64. |
export_ccg_architecture | read | Export CCG Layer 1 architecture (~10-50KB JSON-LD) with module hierarchy, public API, and dependencies. |
export_ccg_full | read | Export CCG Layer 3 full detail (~1-20MB N-Quads gzipped) with complete RDF dataset including imports and security findings. |
export_ccg_index | read | Export CCG Layer 2 symbol index (~100-500KB N-Quads gzipped) with all symbols and call graph edges. |
export_ccg_manifest | read | Export CCG Layer 0 manifest to a file. Returns content or writes to specified path. |
find_call_path | read | Find the call path between two functions. Requires --call-graph flag. |
find_calls | read | Find what a function calls and what calls it |
find_circular_imports | write | Detect circular import dependencies in the codebase. Returns all cycles with the files involved. |
find_dead_code | read | Find unreachable code blocks in a function or file using control flow analysis. |
find_dead_stores | read | Find variable assignments that are never read (dead stores). |
find_functions | read | Find all functions in a repository |
find_functions_by_name | read | Find functions matching a name pattern |
find_imports | write | Find import relationships for a file |
find_injection_vulnerabilities | read | Find injection vulnerabilities (SQL injection, XSS, command injection, path traversal) using taint analysis. |
find_references | read | Find all references to a symbol across the codebase |
find_security_findings | read | Find security findings at or above a severity threshold |
find_semantic_clones | read | Find semantically similar code (Type-3/4 clones) using neural embeddings. Detects code that does the same thing with different implementation. |
find_similar_code | read | Find code similar to a given snippet using TF-IDF embeddings. Good for finding duplicate or related code patterns. |
find_similar_to_symbol | read | Find code similar to a specific symbol (function, class, etc.). Useful for finding related implementations or potential duplicates. |
find_symbol_usages | read | Find all usages of a symbol across files, including imports and re-exports. Cross-language aware for JS/TS projects. |
find_symbols | read | Find data structures (structs, classes, enums, interfaces) and functions/methods in a repository. Supports filtering by type and name pattern. |
find_symbols_in_file | read | Find all symbols defined in a specific file |
find_uninitialized | read | Find variables that may be used before being initialized. |
find_unused_exports | read | Detect exported symbols never imported by other files in repo. Cross-file analysis using import graph. Configurable to exclude public API surface. |
find_upgrade_path | read | Find safe upgrade paths for vulnerable dependencies. Shows which versions fix known vulnerabilities and whether upgrades have breaking changes. |
generate_sbom | read | Generate a Software Bill of Materials (SBOM) for a project. Supports CycloneDX and SPDX formats. Parses Cargo.toml, package.json, requirements.txt, and go.mod. |
get_blame | read | Get git blame information for a file. Requires --git flag. |
get_branch_info | read | Get current branch name and repository status. Requires --git flag. |
get_call_graph | read | Get the call graph for a repository or specific function. Requires --call-graph flag. |
get_callees | read | Find functions called by a given function. Requires --call-graph flag. |
get_callers | read | Find functions that call a given function. Requires --call-graph flag. |
get_ccg_access_info | read | Get information about CCG access tiers and permissions. Explains the Triple-Heart Model and WebACL configuration. |
get_ccg_acl | read | Generate WebACL access control document for CCG layers. Supports Triple-Heart Model (public/authenticated/private tiers). |
get_ccg_manifest | read | Get CCG Layer 0 manifest (~1-2KB JSON-LD) with repository identity, symbol counts, languages, and security summary. Always fits in AI context window. |
get_chunk_stats | read | Get statistics about code chunks in a repository. |
get_chunks | read | Get AST-aware code chunks for a file with symbol context. |
get_code_graph | write | Get graph visualization data (call graph, import graph, symbols). HTTP-only tool, not available via MCP. |
get_commit_diff | write | Get the diff for a specific commit. Requires --git flag. |
get_complexity | read | Get complexity metrics (cyclomatic, cognitive) for a function. Requires --call-graph flag. |
get_contributors | read | Get contributors to a file or repository. Requires --git flag. |
get_control_flow | read | Get the control flow graph (CFG) for a function, showing basic blocks, branches, and loops. |
get_data_flow | read | Get data flow analysis for a function, showing variable definitions and uses. |
get_dependencies | read | Analyze dependencies and imports for a file or module |
get_embedding_stats | read | Get statistics about the embedding index. |
get_excerpt | read | Extract code excerpts around specific lines with intelligent context expansion. Automatically expands to function/class boundaries when enabled. |
get_export_map | read | Get the export map for a file or module showing all exported symbols and their types. |
get_file | read | Get the contents of a specific file with optional line range |
get_file_history | write | Get git commit history for a file. Requires --git flag. |
get_function_hotspots | read | Find highly connected functions (potential refactoring targets) based on call graph analysis. Requires --call-graph flag. |
get_hotspots | read | Find code hotspots - files with high churn and complexity. Requires --git flag. |
get_hover_info | read | Get hover information (type info, documentation) for a symbol at a specific position. Enhanced with LSP when available. |
get_import_graph | write | Build and analyze the import/dependency graph for a codebase. Shows which files import which other files, helps identify circular dependencies. |
get_incremental_status | read | Get status of incremental indexing including Merkle tree root hash, file counts, and change statistics. |
get_index_status | read | Get status of the search index and enabled features. Shows which optional features are enabled (--git, --call-graph, --persist, --watch) and index statistics. |
get_metrics | read | Get performance metrics including tool execution times, indexing statistics, and server uptime |
get_modified_files | read | Get list of modified files in the working tree. Requires --git flag. |
get_neural_stats | read | Get statistics about the neural embedding index. Requires --neural flag. |
get_project_structure | read | Get the directory structure and key files of a repository. Returns a tree view with file types and sizes. |
get_reaching_definitions | read | Get reaching definitions analysis - which variable assignments reach each point in the code. |
get_recent_changes | read | Get recent commits across the repository. Requires --git flag. |
get_remote_file | read | Fetch a specific file from a remote GitHub repository via API (no clone needed). |
get_security_summary | read | Get a comprehensive security summary for a repository including vulnerability counts and risk assessment. |
get_symbol_definition | read | Get the full definition of a symbol with surrounding context. Returns the source code with line numbers. |
get_symbol_history | read | Get commits that modified a specific symbol/function. Requires --git flag. |
get_taint_sources | read | List all identified taint sources (user inputs, file reads, network data) in the codebase. |
get_type_info | read | Get precise type information for a symbol. Requires LSP to be enabled. |
get_typed_taint_flow | read | Enhanced taint analysis with type information. More precise than untyped taint tracking, combines data flow with type inference. |
go_to_definition | read | Find the definition location of a symbol at a specific position. Enhanced with LSP when available. |
hybrid_search | read | Perform hybrid search combining BM25 keyword search with TF-IDF semantic similarity using Reciprocal Rank Fusion (RRF). |
import_ccg | write | Import a CCG layer from URL or local file. Supports JSON-LD (L0/L1) and gzipped N-Quads (L2/L3) formats. |
import_ccg_from_registry | write | Import all CCG layers from the codecontextgraph.com registry for a repository. |
infer_types | read | Infer types for variables in a Python/JavaScript/TypeScript function. Shows what types flow through the code without running external type checkers. |
list_remote_files | read | List files in a remote GitHub repository via API (no clone needed). Rate limited without GITHUB_TOKEN. |
list_repos | read | List all indexed repositories with metadata (path, language breakdown, file count) |
list_sparql_templates | read | List available SPARQL query templates for common code intelligence patterns. Requires --graph flag. |
neural_search | read | Search code using neural semantic embeddings. Finds semantically similar code even with different variable names. Requires --neural flag and EMBEDDING_API_KEY. |
query_ccg | read | Query CCG Layer 3 using SPARQL. Enables rich semantic queries against the full code context graph. |
reindex | write | Trigger re-indexing of a repository or all repositories |
run_sparql_template | write | Execute a predefined SPARQL query template with parameters. Requires --graph flag. |
scan_security | read | Scan repository for security issues using the security rules engine. Detects vulnerabilities, secrets, crypto issues, and more. |
search_chunks | read | Search over AST-aware code chunks with symbol context. |
search_code | read | Semantic and keyword search across code. Returns ranked excerpts with surrounding context. |
semantic_search | read | BM25-ranked semantic search with code-aware tokenization. Better than simple text search for natural language queries. |
sparql_query | write | Execute a SPARQL query against the RDF knowledge graph. Supports SELECT and ASK queries with timeout and result limits. Requires --graph flag. |
suggest_fix | read | Get suggested fixes for a specific security finding. |
trace_taint | read | Trace how tainted data flows from a source location through the code. |
validate_repo | read | Validate that a path is a valid repository and can be indexed |
workspace_symbol_search | read | Fuzzy search for symbols across the entire workspace. Uses trigram matching for typo-tolerant search. |
Trust audit
BLOCKgrade F · trust 53/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (14 observation(s))
- Network
- declared (23 observation(s))
- Shell
- declared (14 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
- '-----BEGIN RSA PRIVATE KEY-----'
- '-----BEGIN PRIVATE KEY-----'
- '-----BEGIN EC PRIVATE KEY-----'
- '-----BEGIN OPENSSH PRIVATE KEY-----'
- '-----BEGIN DSA PRIVATE KEY-----'
val apiKey = "sk_live_1234567890abcdefghij" // BAD: Hardcoded key
data = pickle.loads(user_input)
$obj = unserialize($data); // BAD: Unserialize user input
return unserialize($_GET['obj']); // BAD
"exec(".to_string(),"Exec(".to_string(),"exec(".to_string(),"eval(".to_string(),"exec(".to_string(),"$HOME/.ssh/"
"/home/*/.ssh/"
"cat.*id_rsa"
"cat.*id_ed25519"
"cat.*id_ecdsa"
validate_url_for_ssrf("http://169.254.169.254/metadata", SsrfPolicy::BlockPrivate)let result = validate_embedding_endpoint("http://169.254.169.254/latest/meta-data/");validate_embedding_endpoint("http://metadata.google.internal/computeMetadata/v1/");host == "169.254.169.254"
|| host == "metadata.google.internal"
remediation: Remove -k/--insecure flag and ensure proper CA certificates are installed
Gates applied: critical_finding, no_behavioural_pass.
c95b55984ca6full audit observations/trust-audit/mcp-server/postrv__narsil.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | c95b55984ca6 | BLOCK | F | 53 | first audit |
Questions
What is the Narsil MCP server?
Rust MCP server for comprehensive code intelligence - 90 tools, 32 languages, security scanning, call graphs, and more
What tools does Narsil expose?
96 in total: 84 read-only, 12 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Narsil safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (53/100) and found 25 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Narsil need?
It reads API_KEY and DATABASE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (c95b55984ca6), read on 2026-10-06. The repository is watched and re-audited when it changes.