Atlas / MCP servers / sudocode-ai / Sudocode

SudocodeBLOCK

mcp/sudocode-ai/sudocode

Lightweight agent orchestration dev tool that lives in your repo

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
11 8r · 3w · 0d
Transport
stdio
License
Apache-2.0
Stars
293
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

sudocode

npm install -g sudocode

Automate the logistics of managing context and agents. Direct the work instead of babysitting agents.

sudocode is a lightweight agent orchestration system that lives in your repo. Adding sudocode into your repo adds instant organizational capabilities to your coding agents. They'll gain the ability to track context over long-horizon tasks and work collaboratively on complex tasks.

Key capabilities

  • Automate context handoff for complex tasks with sudocode's git-native agent memory system
  • Bring order to chaos by organizing your requirements, background context, and implementation plans into structured, executable issue graphs
  • Visualize outputs and execution feedback in real-time
  • Run as many Claude Co
Read from source at commit 7d9363245950OBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add types --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y @sudocode-ai/[email protected]
claude-desktop
{
  "mcpServers": {
    "types": {
      "command": "npx",
      "args": [
        "-y",
        "@sudocode-ai/[email protected]"
      ],
      "env": {
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (11)

8 read · 3 write · 0 destructive.

ToolRiskDescription
await_eventsreadPause execution and wait for specific events. Your session will end here.
escalate_to_userreadRequest user input for a decision. Returns immediately with
execute_issuewriteStart an execution for an issue. Returns immediately with execution ID.
execution_cancelreadCancel a running execution.
execution_changesreadGet code changes made by an execution including files modified and commits.
execution_statusreadGet status of an execution including exit code, summary, and files changed.
execution_trajectoryreadGet agent actions and tool calls from an execution.
merge_branchwriteMerge a branch into the workflow
notify_userwriteSend a non-blocking notification to the user. Does not wait for response.
workflow_completereadMark workflow as complete or failed with a summary.
workflow_statusreadGet current workflow state including steps, active executions, and ready issues.
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (6 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
cli/src/yaml-converter.ts:103
return yaml.load(yamlString, {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cli/src/remote/spawn-service.ts:63
exec(command, (error) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/auth/status.ts:106
console.log(`  Token: ${maskToken(credentials.claudeToken)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/auth/status.ts:129
console.log(`  API Key: ${maskToken(credentials.litellmCredentials.api_key)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/remote/spawn-service.ts:101
console.log(chalk.gray(`  Token length: ${claudeToken.length} characters\n`));
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
cli/tests/unit/auth/status.test.ts:52
claudeCodeOAuthToken: 'sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz',
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
cli/tests/unit/auth/status.test.ts:107
claudeCodeOAuthToken: 'sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz'
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
cli/tests/unit/auth/status.test.ts:132
claudeCodeOAuthToken: 'sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz'
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
cli/tests/unit/auth/status.test.ts:146
expect(output).not.toContain('sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz');
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
cli/tests/unit/auth/status.test.ts:158
claudeCodeOAuthToken: 'sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/tests/unit/auth/status.test.ts:56
api_key: 'sk-litellm-1234567890abcdefghijklmnopqrstuvwxyz'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/tests/unit/auth/status.test.ts:201
api_key: 'sk-litellm-1234567890abcdefghijklmnopqrstuvwxyz'
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
frontend/.eslintrc.cjs
.eslintrc.cjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.specify/scripts/bash/common.sh:11
(cd "$script_dir/../../.." && pwd)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/tests/e2e/remote-spawn.test.ts:23
import { RemoteSpawnService } from '../../src/remote/spawn-service.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/tests/e2e/remote-spawn.test.ts:24
import { getClaudeToken } from '../../src/auth/credentials.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/tests/e2e/remote-spawn.test.ts:25
import type { DeploymentInfo } from '../../src/remote/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/tests/integration/entity-level-conflict-detection.test.ts:13
import { handleResolveConflicts, type CommandContext } from '../../src/cli/merge-commands.js';
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
frontend/playwright-report/index.html:85
<script id="playwrightReportBase64" type="application/zip">data:application/zip;base64,UEsDBBQAAAgIAOZZIVxZqW6YNAkAACZFAAAZAAAAYmE4YTNiNzI3N2ExZjI1YmY4ODAuanNvbu2bb2/jNhKHvwrBe2EH0Dr6L0rAHnDJ5nBBt4ui8
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
frontend/src/lib/streamingAudioPlayer.ts:51
const binaryString = atob(base64);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
cli/package.json
@sudocode-ai/types, better-sqlite3, chalk, chokidar, cli-table3, commander, gray-matter, js-yaml
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
frontend/package.json
@codemirror/lang-json, @codemirror/state, @codemirror/view, @dnd-kit/core, @dnd-kit/sortable, @dnd-kit/utilities, @git-diff-view/react, @lexical/react
Why it matters. 105 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp/package.json
@modelcontextprotocol/sdk, @sudocode-ai/cli, @sudocode-ai/types, vite, @types/node, esbuild, typescript, vitest
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
typescript
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 7d9363245950full audit observations/trust-audit/mcp-server/sudocode-ai__sudocode.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-057d9363245950BLOCKF55first audit
06

Questions

What is the Sudocode MCP server?

Lightweight agent orchestration dev tool that lives in your repo

What tools does Sudocode expose?

11 in total: 8 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Sudocode safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Sudocode need?

It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Sudocode run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @sudocode-ai/types at 0.2.0.

How current is this page?

The grade is for one exact copy of the source (7d9363245950), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement