CodeTreeSAFE
MCP server with 23 tools for structured code understanding via tree-sitter. 10 languages. 999 tests. One-command install.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/ThinkyMiner/codeTree/actions/workflows/test.yml) [](https://pypi.org/project/mcp-server-codetree/) [](https://pypi.org/project/mcp-server-codetree/) [](LICENSE)
Stop feeding entire files to your AI agent.
codetree is an MCP server that gives coding agents structured code understanding via tree-sitter — so they ask precise questions instead of reading thousands of lines. 23 tools, 11 languages, ~1 second startup. No vector DB, no embedding model, no config.
Quick Start
Prerequisite: Install uv if you don't have it (curl -LsSf https://astral.sh/uv/install.sh | sh).
Then cd into any project and run:
claude mcp add codetree -- uvx --from mcp-server-codetree codetree --root .
That's it. The . means "this project." Your agent now has structured code understanding.
Not using Claude Code? See Editor Setup for Cursor, VS Code, Windsurf, and Claude Desktop.
Before / After
Before codetree — agent reads the raw file:
$ cat calculator.py
import math
from typing import Optional
class Calculator:
"""A scientific calculator with memory."""
def __init__(self):
self.memory = 0
self.history = []
def add(self, a: float, b: float) -> float:
"""Add two numbers."""
result = a + b
self.history.append(('add', a, b, result))
return result
def divide(self, a: float, b: float) -> Optional[float]:
"""Divide a by b, returns None on zero division."""
if b == 0:
return None
result = a / ffd017b8e557OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-server-codetree -- uvx mcp-server-codetree
{
"mcpServers": {
"mcp-server-codetree": {
"command": "uvx",
"args": [
"mcp-server-codetree"
]
}
}
}Exposed tools (23)
22 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_dataflow | read | Analyze variable dataflow and security taint paths in a function. |
detect_clones | read | Find duplicate or near-duplicate functions in the repo. |
find_dead_code | read | Find symbols that are defined but never referenced elsewhere in the repo. |
find_hot_paths | read | Find high-leverage optimization targets by combining complexity and call frequency. |
find_references | read | Find all usages of a symbol across the entire repo. |
find_tests | read | Find test functions associated with a symbol. |
get_blast_radius | read | Find all functions transitively affected if a symbol is changed. |
get_call_graph | read | Get what a function calls and what calls it across the repo. |
get_change_impact | read | Analyze impact of a change — by explicit symbol or git diff. |
get_complexity | read | Get cyclomatic complexity of a function. |
get_dependency_graph | read | Get the file dependency graph as Mermaid syntax or a list. |
get_file_skeleton | read | Get all classes and function signatures in a source file without their bodies. |
get_imports | write | Get import/use statements from a source file. |
get_repository_map | read | Get a compact overview of the repository for onboarding. |
get_skeletons | read | Get skeletons for multiple files in one call. |
get_symbol | read | Get the full source code of a specific function or class by name. |
get_symbols | read | Get the full source code of multiple symbols in one call. |
git_history | read | Analyze git history: blame, churn, or change coupling. |
index_status | read | Report on graph index freshness and stats. |
resolve_symbol | read | Disambiguate a short symbol name into ranked qualified matches. |
search_graph | read | Search the code graph with flexible filters and pagination. |
search_symbols | read | Search for symbols across the repo with flexible filters. |
suggest_docs | read | Find undocumented functions and assemble context for writing docs. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
"/root/.ssh/id_rsa",
"../../../etc/passwd",
"../../secret.txt",
"src/../../etc/shadow",
result = server_and_tools["find_dead_code"]("../../../etc/passwd")result = server_and_tools["analyze_dataflow"]("../../../etc/passwd", "main")**Prerequisite:** Install [uv](https://docs.astral.sh/uv/getting-started/installation/) if you don't have it (`curl -LsSf https://astral.sh/uv/install.sh | sh`).
Gates applied: no_behavioural_pass.
ffd017b8e557full audit observations/trust-audit/mcp-server/thinkyminer__codetree.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ffd017b8e557 | SAFE | B | 89 | first audit |
Questions
What is the CodeTree MCP server?
MCP server with 23 tools for structured code understanding via tree-sitter. 10 languages. 999 tests. One-command install.
What tools does CodeTree expose?
23 in total: 22 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CodeTree safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does CodeTree need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (ffd017b8e557), read on 2026-10-08. The repository is watched and re-audited when it changes.