SudocodeBLOCK
Lightweight agent orchestration dev tool that lives in your repo
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
sudocode
npm install -g sudocode
Automate the logistics of managing context and agents. Direct the work instead of babysitting agents.
sudocode is a lightweight agent orchestration system that lives in your repo. Adding sudocode into your repo adds instant organizational capabilities to your coding agents. They'll gain the ability to track context over long-horizon tasks and work collaboratively on complex tasks.
Key capabilities
- Automate context handoff for complex tasks with sudocode's git-native agent memory system
- Bring order to chaos by organizing your requirements, background context, and implementation plans into structured, executable issue graphs
- Visualize outputs and execution feedback in real-time
- Run as many Claude Co
7d9363245950OBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add types --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y @sudocode-ai/[email protected]{
"mcpServers": {
"types": {
"command": "npx",
"args": [
"-y",
"@sudocode-ai/[email protected]"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (11)
8 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
await_events | read | Pause execution and wait for specific events. Your session will end here. |
escalate_to_user | read | Request user input for a decision. Returns immediately with |
execute_issue | write | Start an execution for an issue. Returns immediately with execution ID. |
execution_cancel | read | Cancel a running execution. |
execution_changes | read | Get code changes made by an execution including files modified and commits. |
execution_status | read | Get status of an execution including exit code, summary, and files changed. |
execution_trajectory | read | Get agent actions and tool calls from an execution. |
merge_branch | write | Merge a branch into the workflow |
notify_user | write | Send a non-blocking notification to the user. Does not wait for response. |
workflow_complete | read | Mark workflow as complete or failed with a summary. |
workflow_status | read | Get current workflow state including steps, active executions, and ready issues. |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
return yaml.load(yamlString, {exec(command, (error) => {console.log(` Token: ${maskToken(credentials.claudeToken)}`);console.log(` API Key: ${maskToken(credentials.litellmCredentials.api_key)}`);console.log(chalk.gray(` Token length: ${claudeToken.length} characters\n`));claudeCodeOAuthToken: 'sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz',
claudeCodeOAuthToken: 'sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz'
claudeCodeOAuthToken: 'sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz'
expect(output).not.toContain('sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz');claudeCodeOAuthToken: 'sk-ant-api03-1234567890abcdefghijklmnopqrstuvwxyz'
api_key: 'sk-litellm-1234567890abcdefghijklmnopqrstuvwxyz'
api_key: 'sk-litellm-1234567890abcdefghijklmnopqrstuvwxyz'
.gitmodules
.eslintrc.cjs
(cd "$script_dir/../../.." && pwd)
import { RemoteSpawnService } from '../../src/remote/spawn-service.js';import { getClaudeToken } from '../../src/auth/credentials.js';import type { DeploymentInfo } from '../../src/remote/types.js';import { handleResolveConflicts, type CommandContext } from '../../src/cli/merge-commands.js';<script id="playwrightReportBase64" type="application/zip">data:application/zip;base64,UEsDBBQAAAgIAOZZIVxZqW6YNAkAACZFAAAZAAAAYmE4YTNiNzI3N2ExZjI1YmY4ODAuanNvbu2bb2/jNhKHvwrBe2EH0Dr6L0rAHnDJ5nBBt4ui8
const binaryString = atob(base64);
@sudocode-ai/types, better-sqlite3, chalk, chokidar, cli-table3, commander, gray-matter, js-yaml
@codemirror/lang-json, @codemirror/state, @codemirror/view, @dnd-kit/core, @dnd-kit/sortable, @dnd-kit/utilities, @git-diff-view/react, @lexical/react
@modelcontextprotocol/sdk, @sudocode-ai/cli, @sudocode-ai/types, vite, @types/node, esbuild, typescript, vitest
typescript
Gates applied: no_behavioural_pass.
7d9363245950full audit observations/trust-audit/mcp-server/sudocode-ai__sudocode.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 7d9363245950 | BLOCK | F | 55 | first audit |
Questions
What is the Sudocode MCP server?
Lightweight agent orchestration dev tool that lives in your repo
What tools does Sudocode expose?
11 in total: 8 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Sudocode safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Sudocode need?
It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Sudocode run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @sudocode-ai/types at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (7d9363245950), read on 2026-10-05. The repository is watched and re-audited when it changes.