CodeGraphContextBLOCK
An MCP server plus a CLI tool that indexes local code into a graph database to provide context to AI assistants.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Turn code repositories into a queryable graph for AI agents.
🌐 Languages:
- 🇬🇧 English
- 🇨🇳 中文
- 🇰🇷 한국어
- 🇺🇦 Українська
- 🇷🇺 Русский
- 🇯🇵 日本語
- 🇮🇳 தமிழ்
- 🇪🇸 Español (Soon)
🌍 Help translate CodeGraphContext to your language by raising an issue & PR on [GitHub Issues](https://github.com/CodeGraphContext/CodeGraphContext/issues)!
Bridge the gap between deep code graphs and AI context.
407160b67728OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add vite_react_shadcn_ts --env ATLASCLOUD_API_KEY=${ATLASCLOUD_API_KEY} --env ATLAS_CLOUD_API_KEY=${ATLAS_CLOUD_API_KEY} --env BUNDLE_TRIGGER_API_KEY=${BUNDLE_TRIGGER_API_KEY} --env CGC_BUNDLE_PASSWORD=${CGC_BUNDLE_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"vite_react_shadcn_ts": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ATLASCLOUD_API_KEY": "${ATLASCLOUD_API_KEY}",
"ATLAS_CLOUD_API_KEY": "${ATLAS_CLOUD_API_KEY}",
"BUNDLE_TRIGGER_API_KEY": "${BUNDLE_TRIGGER_API_KEY}",
"CGC_BUNDLE_PASSWORD": "${CGC_BUNDLE_PASSWORD}"
}
}
}
}Exposed tools (10)
10 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Classic | read | Standard colored circles |
Flowchart | read | SVG diagram with Bezier edges |
Galaxy | read | Orbital rings by connections |
Icon | read | Emoji icons by node type |
analyze_code_relationships | read | Inspects coupling references, inherits, imports, and calls between symbols. |
calculate_cyclomatic_complexity | read | Computes cyclomatic complexity scores for all functions in the codebase. |
find_dead_code | read | Locates unreferenced classes and functions inside the repository codebase. |
find_most_complex_functions | read | Retrieves the functions with the highest cyclomatic complexity scores. |
get_repository_stats | read | Retrieves general repository graph statistics (counts of files, classes, methods, and relationship linkages). |
list_indexed_repositories | read | Lists all repositories indexed in the user |
Trust audit
BLOCKgrade F · trust 51/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(cmd, async (error: any, stdout: string, stderr: string) => {module = importlib.import_module(_LAZY_IMPORTS[name], __package__)
backend = importlib.import_module(spec.python_module)
importlib.import_module(spec.python_module)
detected, pattern = is_likely_secret("api_key = 'sk-1234567890abcdef1234567890abcdef'")props = {"value": "ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefgh"}assert result["value"] == "ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefgh"
props = {"value": "ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefgh"}props = {"value": "ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefgh"}props = {"value": "ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefgh"}detected, pattern = is_likely_secret("-----BEGIN RSA PRIVATE KEY-----")cgc_sample
main.exe
sample_project.exe
Main.class
Logged.class
.vscodeignore
.cgcignore
.cgc_compile_commands.json
.cgcignore
.cgc_compile_commands.json
mod = importlib.import_module(mod_name)
mod = __import__(name)
ASM_CONSTS[start] = eval(func);
moduleExports[name] = eval(func);
Gates applied: no_behavioural_pass.
407160b67728full audit observations/trust-audit/mcp-server/shashankss1205__codegraphcontext.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 407160b67728 | BLOCK | F | 51 | first audit |
Questions
What is the CodeGraphContext MCP server?
An MCP server plus a CLI tool that indexes local code into a graph database to provide context to AI assistants.
What tools does CodeGraphContext expose?
10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CodeGraphContext safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (51/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does CodeGraphContext need?
It reads ATLASCLOUD_API_KEY, ATLAS_CLOUD_API_KEY, BUNDLE_TRIGGER_API_KEY, CGC_BUNDLE_PASSWORD, CGC_BUNDLE_VERIFY_KEY, FALKORDB_PASSWORD, GEMINI_API_KEY, GH_TOKEN, GITHUB_TOKEN, HF_ADMIN_WRITE_TOKEN, HF_TOKEN and HUGGING_FACE_HUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (407160b67728), read on 2026-10-03. The repository is watched and re-audited when it changes.