Atlas / MCP servers / thinkyminer / CodeTree

CodeTreeSAFE

mcp/thinkyminer/codetree

MCP server with 23 tools for structured code understanding via tree-sitter. 10 languages. 999 tests. One-command install.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
23 22r · 1w · 0d
Transport
—
License
MIT
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/ThinkyMiner/codeTree/actions/workflows/test.yml) [](https://pypi.org/project/mcp-server-codetree/) [](https://pypi.org/project/mcp-server-codetree/) [](LICENSE)

Stop feeding entire files to your AI agent.

codetree is an MCP server that gives coding agents structured code understanding via tree-sitter — so they ask precise questions instead of reading thousands of lines. 23 tools, 11 languages, ~1 second startup. No vector DB, no embedding model, no config.

Quick Start

Prerequisite: Install uv if you don't have it (curl -LsSf https://astral.sh/uv/install.sh | sh).

Then cd into any project and run:

claude mcp add codetree -- uvx --from mcp-server-codetree codetree --root .

That's it. The . means "this project." Your agent now has structured code understanding.

Not using Claude Code? See Editor Setup for Cursor, VS Code, Windsurf, and Claude Desktop.

Before / After

Before codetree — agent reads the raw file:

$ cat calculator.py
import math
from typing import Optional

class Calculator:
"""A scientific calculator with memory."""

def __init__(self):
self.memory = 0
self.history = []

def add(self, a: float, b: float) -> float:
"""Add two numbers."""
result = a + b
self.history.append(('add', a, b, result))
return result

def divide(self, a: float, b: float) -> Optional[float]:
"""Divide a by b, returns None on zero division."""
if b == 0:
return None
result = a / 
Read from source at commit ffd017b8e557OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-server-codetree -- uvx mcp-server-codetree
claude-desktop
{
  "mcpServers": {
    "mcp-server-codetree": {
      "command": "uvx",
      "args": [
        "mcp-server-codetree"
      ]
    }
  }
}
03

Exposed tools (23)

22 read · 1 write · 0 destructive.

ToolRiskDescription
analyze_dataflowreadAnalyze variable dataflow and security taint paths in a function.
detect_clonesreadFind duplicate or near-duplicate functions in the repo.
find_dead_codereadFind symbols that are defined but never referenced elsewhere in the repo.
find_hot_pathsreadFind high-leverage optimization targets by combining complexity and call frequency.
find_referencesreadFind all usages of a symbol across the entire repo.
find_testsreadFind test functions associated with a symbol.
get_blast_radiusreadFind all functions transitively affected if a symbol is changed.
get_call_graphreadGet what a function calls and what calls it across the repo.
get_change_impactreadAnalyze impact of a change — by explicit symbol or git diff.
get_complexityreadGet cyclomatic complexity of a function.
get_dependency_graphreadGet the file dependency graph as Mermaid syntax or a list.
get_file_skeletonreadGet all classes and function signatures in a source file without their bodies.
get_importswriteGet import/use statements from a source file.
get_repository_mapreadGet a compact overview of the repository for onboarding.
get_skeletonsreadGet skeletons for multiple files in one call.
get_symbolreadGet the full source code of a specific function or class by name.
get_symbolsreadGet the full source code of multiple symbols in one call.
git_historyreadAnalyze git history: blame, churn, or change coupling.
index_statusreadReport on graph index freshness and stats.
resolve_symbolreadDisambiguate a short symbol name into ranked qualified matches.
search_graphreadSearch the code graph with flexible filters and pagination.
search_symbolsreadSearch for symbols across the repo with flexible filters.
suggest_docsreadFind undocumented functions and assemble context for writing docs.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (7)

LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/test_path_security.py:28
"/root/.ssh/id_rsa",
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_path_security.py:19
"../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_path_security.py:20
"../../secret.txt",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_path_security.py:22
"src/../../etc/shadow",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_path_security.py:126
result = server_and_tools["find_dead_code"]("../../../etc/passwd")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_path_security.py:146
result = server_and_tools["analyze_dataflow"]("../../../etc/passwd", "main")
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:14
**Prerequisite:** Install [uv](https://docs.astral.sh/uv/getting-started/installation/) if you don't have it (`curl -LsSf https://astral.sh/uv/install.sh | sh`).

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha ffd017b8e557full audit observations/trust-audit/mcp-server/thinkyminer__codetree.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08ffd017b8e557SAFEB89first audit
06

Questions

What is the CodeTree MCP server?

MCP server with 23 tools for structured code understanding via tree-sitter. 10 languages. 999 tests. One-command install.

What tools does CodeTree expose?

23 in total: 22 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CodeTree safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does CodeTree need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (ffd017b8e557), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement