Atlas / MCP servers / raymondchins / Agentmap

AgentmapBLOCK

mcp/raymondchins/agentmap-1

Stop your coding agent reading the wrong files. Compiler-grade TS/JS repo map — 100% precision on blast radius vs grep's 60%, measured on public repos. CLI + MCP server, fully local, no vector DB.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
14 13r · 1w · 0d
Transport
stdio
License
MIT
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

= 20">

Your agent burns most of its context just finding code. This gives it the answer in one line.

npx @raymondchins/agentmap --relates lib/db/schema.ts
relates: lib/db/schema.ts  (pr 0.073744)
dependents (21): lib/types.ts, lib/utils.ts, lib/db/queries.ts,
components/chat/message.tsx, app/(chat)/api/chat/route.ts, ...

Every file on that list really imports it. grep gets 40% of them wrong.

💸 What it saves

Token cost of the hidden first step in every agent task — find the relevant code — on a real 154-file Next.js app (vercel/ai-chatbot, sha 2becdb4):

Read from source at commit 27d033393e28OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add agentmap -- npx -y @raymondchins/[email protected]
03

Exposed tools (14)

13 read · 1 write · 0 destructive.

ToolRiskDescription
affectedwriteWhich test files cover a source file, following import edges transitively — and, just as usefully, whether ANY do. Answers
anyreadUnified router: resolve a query against the repo map (file → symbol → feature) then fall back to a live git-grep for string/copy/data literals. Best default for
callersreadCompiler-accurate call graph: every call site that INVOKES a symbol, resolved by the TypeScript language service (not tree-sitter name-matching) — so a type-position mention, a re-export, or a same-named local in another file is never mis-attributed. Symbol-level blast radius:
callsreadCompiler-accurate OUTGOING call graph: every in-project symbol that a given symbol INVOKES, resolved by the TypeScript language service (not tree-sitter name-matching) — callee resolution follows real bindings (imports/re-exports) through to the actual declaration. Answers
featurereadList all files belonging to a named feature plus its external dependents.
featuresreadList every detected feature (top-level app/ route segment) with its file count.
findreadFind every symbol whose name matches (substring, case-insensitive) — exported symbols plus non-exported top-level declarations. Use to locate a function/class/type before rebuilding it. A match reached through a re-export barrel carries
hubsreadList the most important files in the repo by PageRank (the hubs everything imports). Read these first to understand a codebase.
mapreadToken-budgeted ranked digest of the codebase (PageRank + Aider-style symbol ranking). Optionally focus toward a file and/or set a token budget.
relatesreadBlast radius for a file: its exports, imports, direct dependents, and the files most related to it by random-walk relevance. Use before editing to see who breaks.
routereadResolve one URL path (e.g.
routesreadThe Next.js App Router route table: every URL path the repo serves, with the file that serves it. Next.js only — on any other repo this returns an explicit
searchreadRank symbols by BM25 lexical relevance for a VAGUE natural-language query (e.g.
symbolsreadTop N globally ranked symbols (Aider-style importance). Defaults to 30.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (18)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
agentmap.mjs:274
":!*.pem", ":!*.key", ":!*.p12", ":!*.pfx", ":!*.crt", ":!id_rsa*",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
agentmap.mjs:276
":!*.p8", ":!*.jks", ":!*.keystore", ":!id_ed25519*", ":!id_ecdsa*",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
agentmap.mjs:280
":!.npmrc", ":!**/.npmrc", ":!.netrc", ":!**/.netrc",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
agentmap.mjs:281
":!.git-credentials", ":!**/.git-credentials", ":!.pgpass", ":!**/.pgpass",
Why it matters. touches a credential store
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/injection-safety.test.mjs:51
const SECRET = "SUPER_SECRET_VALUE_ZZQ";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/injection-safety.test.mjs:67
const SECRET = "EXPANDED_SECRET_VALUE_ZZQ";
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
agentmap.mjs:495
return createHash("sha1").update(entries.join("\n")).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
agentmap.mjs:519
return createHash("sha1").update("HEAD:" + sha + "\n" + toks.join("\n")).digest("hex");
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
benchmark/bench.mjs:244
console.log(`agentmap token-savings benchmark`);
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
test/injection-safety.test.mjs:72
".git-credentials": `https://user:${SECRET}@github.com\n`,
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/batch5-correctness.test.mjs:68
"apps/web/tsconfig.json": '{"extends":"../../packages/shared-config/tsconfig.base.json","compilerOptions":{"allowJs":true},"include":["src/**/*.ts"]}\n',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/batch5-correctness.test.mjs:84
"apps/web/tsconfig.json": '{"extends":"../../packages/shared-config/tsconfig.base.json","compilerOptions":{"allowJs":true},"include":["src/**/*.ts"]}\n',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/mcp-inprocess.test.mjs:37
"app/dashboard/page.ts": 'import { run } from "../../src/main";\nexport const page = run();\nexport const MAGIC_TOKEN = "zephyr-42";\n',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/monorepo-shapes.test.mjs:31
'import { helper } from "../../core/src/index";\nexport const v = helper();\n',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/vue-sfc/import-resolution.test.mjs:59
`import { FORMAT_VERSION } from "../../lib/format";`,
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
CHANGELOG.md:989
byte-identical to the CLI) so a planted "ignore previous instructions" in an
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
SECURITY.md:62
- **Over MCP, the lines are fenced as data.** The `any` tool appends a second content block marking the result as raw untrusted repository content, so a planted "ignore previous instructions" in an or
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 27d033393e28full audit observations/trust-audit/mcp-server/raymondchins__agentmap-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0827d033393e28BLOCKD69first audit
06

Questions

What is the Agentmap MCP server?

Stop your coding agent reading the wrong files. Compiler-grade TS/JS repo map — 100% precision on blast radius vs grep's 60%, measured on public repos. CLI + MCP server, fully local, no vector DB.

What tools does Agentmap expose?

14 in total: 13 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Agentmap safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Agentmap need?

No credential environment variables were found in its source, so it appears to need none.

How does Agentmap run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @raymondchins/agentmap at 0.22.0.

How current is this page?

The grade is for one exact copy of the source (27d033393e28), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement