ADR AnalysisBLOCK
Your ADRs are lying to you. MCP server with live drift detection, content safety, and decision memory — validates architectural decisions against your actual code.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/tosin2013/mcp-adr-analysis-server) [](LICENSE) [](https://www.npmjs.com/package/mcp-adr-analysis-server) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://github.com/tosin2013/mcp-adr-analysis-server/issues?q=is%3Aissue+is%3Aopen+label%3A%22good+first+issue%22)
Your ADRs are lying to you. This MCP server catches it — live drift detection validates architectural decisions against your actual code. Plus content safety, decision memory, and 63 tools powered by your host LLM via CE-MCP.
Table of contents
- What is MCP?
- Prerequisites
- Quick Installation
- Quick Setup
- Usage Examples
- Use Cases
- Technology Stack
- Project Structure
- Testing
- ADR Aggregator Integration
- Development
- Troubleshooting
- Security & Performance
- Contributing
- Resources
- License
What is MCP?
The Model Context Protocol (MCP) is an open standard that enables seamless integration between AI assistants and external tools and data sources. Think of it as a universal adapter that lets AI assistant
1060b7a805c7OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-adr-analysis-server --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- npx -y [email protected]Exposed tools (115)
101 read · 13 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
CQRS | read | Command Query Responsibility Segregation |
MVC | read | Model-View-Controller |
Microservices | read | Distributed architecture |
MongoDB | read | Document database with horizontal scaling capabilities |
Node.js | read | Backend runtime |
Observer | read | Observer pattern |
PostgreSQL | read | Relational database system |
React | read | UI Library |
Redis | read | In-memory data store |
Test | read | Test |
action | read | Description of the action to be performed |
action_confirmation | read | Confirm actions before writing files to disk |
adrDirectory | read | Directory containing ADR files |
ambiguity_resolution | read | Resolve ambiguities in project analysis or requirements |
ambiguous_items | read | List of ambiguous items that need clarification |
analysisDepth | read | Analysis depth: shallow, deep |
analyze_adr_timeline | read | Analyze ADR timeline with smart time tracking, adaptive thresholds, and actionable recommendations. Auto-detects project context (startup/growth/mature) and generates prioritized work queue based on staleness, implementation lag, and technical debt. |
analyze_content_security | read | Analyze content for sensitive information using AI-powered detection with optional memory integration for security pattern learning |
analyze_deployment_progress | read | Analyze deployment progress and verify completion with outcome rules |
analyze_environment | read | Analyze environment context and provide optimization recommendations with optional memory integration for environment snapshot tracking |
analyze_gaps | read | Scan local codebase and compare with ADRs to detect bi-directional gaps. Finds: (1) ADR-to-code gaps: file references in ADRs that do not exist, (2) Code-to-ADR gaps: technologies in package.json and architectural patterns without ADR coverage. Reports gaps to ADR Aggregator for tracking. |
analyze_project_ecosystem | read | Comprehensive recursive project ecosystem analysis with advanced prompting techniques (Knowledge Generation + Reflexion) |
apply_basic_content_masking | write | Apply basic content masking (fallback when AI is not available) |
architecture | read | Architecture rules |
args | read | Analysis arguments including code patterns and context |
baseline_analysis | read | Generate comprehensive baseline analysis for existing projects |
bootstrap_validation_loop | read | Bootstrap self-learning validation and deployment workflow |
compare_adr_progress | read | Compare TODO.md progress against ADRs and current environment to validate implementation status |
configure_custom_patterns | read | Configure custom sensitive patterns for a project |
configure_output_masking | read | Configure content masking for all MCP outputs |
content_type | read | Type of content being created (code, documentation, configuration) |
context | read | Context where ambiguity was detected |
create_research_template | write | Create a research template file for documenting findings |
create_rule_set | write | Create machine-readable rule set in JSON/YAML format |
custom_rule_definition | read | Define custom architectural rules and validation criteria |
deployment_readiness | write | Comprehensive deployment readiness validation with test failure tracking, deployment history analysis, and hard blocking for unsafe deployments. Integrates with smart_git_push for deployment gating. |
discover_existing_adrs | read | Discover and catalog existing ADRs in the project |
estimationType | read | Type of estimation: effort, duration, resources |
existing_rules | read | Existing rules in the project (JSON array) |
expand_analysis_section | read | Retrieve full analysis content from tiered responses. Expand entire analysis or specific sections stored in memory. Use this when a tool returns a summary with an expandable ID. |
expand_memory | read | Phase 3: Retrieve and expand stored content from a tiered response using its expandable ID |
files | read | List of files that will be affected (JSON array) |
filters | read | Filters for list action (JSON array) |
focus_areas | read | Specific areas to focus on (comma-separated) |
generate_adr_bootstrap | read | Bootstrap ADR structure for a project |
generate_adr_from_decision | read | Generate a complete ADR from decision data. TIP: Reference @.mcp-server-context.md to align with existing architectural patterns and decisions. |
generate_adrs_from_prd | read | Generate Architectural Decision Records from a Product Requirements Document with advanced prompting techniques (APE + Knowledge Generation) |
generate_content_masking | read | Generate masking instructions for detected sensitive content |
generate_deployment_guidance | read | Generate deployment guidance and instructions from ADRs with environment-specific configurations |
generate_research_questions | write | Generate context-aware research questions and create research tracking system |
generate_rules | read | Generate architectural rules from ADRs and code patterns |
get_adr_context | read | Fetch ADR context from ADR Aggregator including summaries, diagrams, timeline data, and code links. Useful for getting a consolidated view of architectural decisions. |
get_adr_diagrams | read | Get Mermaid diagrams for ADRs from ADR Aggregator. Includes workflow, relationship, and impact diagrams. Requires Pro+ tier. |
get_adr_priorities | read | Get ADR priorities for roadmap and backlog planning from ADR Aggregator. Returns prioritized ADRs with scores, dependencies, blockers, implementation status, and gap counts. |
get_adr_templates | read | Get domain-specific ADR templates and anti-patterns from ADR Aggregator. Includes best practices for web applications, microservices, APIs, and more. No authentication required. |
get_architectural_context | read | Get detailed architectural context for specific files or the entire project, automatically sets up ADR infrastructure if missing, and provides outcome-focused workflow for project success |
get_conversation_snapshot | read | Phase 3: Get current conversation context snapshot for resumption or analysis |
get_development_guidance | read | Get comprehensive development guidance that translates architectural decisions and workflow recommendations into specific coding tasks, implementation patterns, and development roadmap |
get_gaps | read | Get current code gaps from ADR Aggregator. Returns gaps with their status (open, dismissed, resolved) for tracking and management. |
get_knowledge_graph | read | Get cross-repository knowledge graph from ADR Aggregator with analytics and insights. Visualize ADR relationships across repositories. Requires Team tier. |
get_memory_stats | read | Phase 3: Get statistics about stored conversation memory |
get_server_context | read | Generate a comprehensive context file showing the server |
get_staleness_report | read | Get ADR staleness report from ADR Aggregator with review compliance metrics. Identifies stale ADRs that need attention and provides governance insights. |
get_workflow_guidance | read | Get intelligent workflow guidance and tool recommendations based on your goals and project context to achieve expected outcomes efficiently |
goal_specification | read | Specify project goals and requirements for comprehensive analysis |
granularity | read | Estimation granularity: high, medium, low |
includeDownstream | read | Include downstream dependencies (true/false) |
includeUncertainty | read | Include uncertainty analysis (true/false) |
includeUpstream | read | Include upstream dependencies (true/false) |
incorporate_research | read | Incorporate research findings into architectural decisions |
interactive_adr_planning | read | Interactive guided ADR planning and creation tool - walks users through structured decision-making process with research integration, option evaluation, and automatic ADR generation. TIP: Start by reading @.mcp-server-context.md to understand project context and previous decisions. |
manage_cache | destructive | Manage MCP resource cache (clear, stats, cleanup) |
mcp_planning | read | Enhanced project planning and workflow management tool - phase-based project management, team resource allocation, progress tracking, risk analysis, and executive reporting |
memory_loading | read | Advanced memory loading tool for the memory-centric architecture. Query, explore, and manage memory entities and relationships. Load ADRs into memory system and perform intelligent queries. |
newStatus | write | New status for update action |
perform_research | read | Perform research using cascading sources: project files → session/tool-usage tracker → environment resources → web search (fallback) |
phase | read | Development phase: both, test, production |
preview | read | Preview of changes to be made |
projectContext | read | Project context for technology detection |
projectPath | read | Path to the project directory |
project_path | read | Path to the project directory |
project_type | read | Type of project (web, mobile, api, library, tool, etc.) |
query_conversation_history | read | Phase 3: Search and retrieve conversation sessions based on filters |
release_tracking | read | Track releases mapped to ADR decisions. Generates changelogs, manages milestones, compares releases, and assesses release readiness. Supports greenfield and brownfield projects. Writes CHANGELOG.md, creates GitHub Releases and Milestones. |
request_action_confirmation | read | Request confirmation before applying research-based changes |
review_existing_adrs | read | Review existing ADRs against actual code implementation with cloud/DevOps expertise. TIP: After review, call get_server_context to update @.mcp-server-context.md with findings. |
rule_category | read | Category of rule (architectural, coding, security, performance, documentation) |
scale_requirements | read | Expected scale and performance requirements |
scope | read | Task scope: all, pending, in_progress |
search_codebase | read | Atomic tool for searching codebase files based on query patterns. Returns raw file matches with relevance scores. Extracted from ResearchOrchestrator per ADR-018. |
search_tools | read | [DEPRECATED host-native, ADR-023] Search and discover available tools by category, keyword, or capability. Use this to find the right tool for a task without loading all tool schemas. Returns lightweight tool metadata by default; use includeSchema:true for full schemas. |
secret_prevention_guidance | read | Proactive guidance to prevent secret exposure in code and documentation |
set_project_path | write | Dynamically set the active project path for the current session. Call this at the start of a session to switch between projects without restarting the server or modifying environment variables. All subsequent tool calls will use this path as the default. |
smart_git_push | write | AI-driven security-focused git push with credential detection, file filtering, and deployment metrics tracking. Tests should be run by calling AI and results provided. |
smart_score | write | Central coordination for project health scoring system - recalculate, sync, diagnose, optimize, and reset scores across all MCP tools |
suggest_adrs | read | Suggest architectural decisions with advanced prompting techniques (Knowledge Generation + Reflexion). TIP: Read @.mcp-server-context.md first for project history, patterns, and previous ADRs to ensure consistency. |
suggestions | read | Suggested interpretations or options |
sync_to_aggregator | write | Sync ADRs to ADR Aggregator platform (https://adraggregator.com) for centralized tracking, visualization, and team collaboration. Supports incremental and full sync modes with optional metadata. |
target_audience | read | Target audience or users of the project |
target_location | read | Where the content will be stored/committed |
taskId | write | Specific task ID (for update/complete actions) |
test | read | Test profile |
todo_dependency_analysis | read | Analyze task dependencies and critical path optimization |
todo_estimation | read | Provide accurate task estimation and timeline planning |
todo_status_management | read | Manage task status, priorities, and progress tracking |
todo_task_generation | read | Generate comprehensive development task list from ADRs with cloud/DevOps expertise |
tool_chain_orchestrator | read | AI-powered dynamic tool sequencing - intelligently analyze user requests and generate structured tool execution plans |
troubleshoot_guided_workflow | read | Structured failure analysis and test plan generation with memory integration for troubleshooting session tracking and intelligent ADR/research suggestion capabilities - provide JSON failure info to get specific test commands |
update_implementation_status | write | Update the implementation status of synced ADRs directly from the IDE. Supports statuses: not_started, in_progress, implemented, deprecated, blocked. Requires Pro+ tier. |
update_knowledge | write | ADR-018: Simple CRUD operations for project session state. Not a graph database — keyword retrieval over local JSON snapshots. Add/remove entities (intents, ADRs, tools, code) and relationships. Use knowledge://graph resource to read current state (zero token cost). |
validate_adr | read | Validate an existing ADR against actual infrastructure reality using research-driven analysis. TIP: Compare findings against patterns in @.mcp-server-context.md for consistency checks. |
validate_adr_compliance | read | Validate ADR compliance against implementation via ADR Aggregator. Checks that code actually implements documented decisions. Requires Pro+ tier. |
validate_all_adrs | read | Validate all ADRs in a directory against actual infrastructure reality |
validate_content_masking | read | Validate that content masking was applied correctly |
validate_rules | read | Validate code against architectural rules |
Trust audit
BLOCKgrade F · trust 37/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
/id_rsa$/,
/id_ed25519$/,
"As an enterprise architect, I need to assess [SYSTEM] for compliance and modernization. Please use analyze_project_ecosystem with enterprise focus, then suggest_adrs for governance patterns, and gene
7fa6effa7f205c0354d1cff1aa5983d58a996b7ed716da0642f6aefd9e0342280791fd7de070475740797828d5d5fb7c20209d423e4250dc81ccea572cc8
7f10aaee348a897ff41a86fc704195caca0390db9ea6c9e37f130f931dc01ae6af8f8f24d330c78d402e03670e40c1fbde96c52b03a07aecd28ca970dbcd
43b4d472f80b30589102c80d7baa1503bebac267acd73827e4418e734a66fde815546e9540bf4dd6a5c8dcc2d0b088b6c800dc7781e6c739c5d89f5107a3
ac5238b13c5752f8d2a4ca9732c8de4f9a0f373a5b2dd3e73abc6a2fd1d8b04c4a3a9a076a551ea1c5c12016e87842b02ced173ef4ab8627d4d50a3d19ce
d5d99176af6ffadd5fad2bc850beb4766469f5d2cac76d7be24e572fecaa73c3c8d688d4ea6d58233b7218f11c6bace505f153cc410172b18618bf4619c7
'database-url': 'postgres://user:p@ss@host:5432/db',
- Database URLs with special chars: mongodb://user:p@ss@host:27017/db
- Redis connection: redis://user:p@ss@host:6379
'const token = "IST_a1b2c3d4e5f6789012345678901234567890abcd";',
'const token = "DIFFERENT_FORMAT_123";',
password: 'super_secret_password_123',
apiKey: 'sk-1234567890abcdefghijklmnopqrstuvwxyz',
token: 'jwt_token_abcdef123456'
'github_token=ghp_1234567890abcdef1234567890abcdef12345678',
Match: '-----BEGIN PRIVATE KEY-----',
Secret: '-----BEGIN PRIVATE KEY-----',
'const key = "-----BEGIN PRIVATE KEY-----";'
'private_key="-----BEGIN RSA PRIVATE KEY-----"',
API_KEY: "sk_live_1234567890abcdef"
manage_cache
.adr-drift-baseline
.commitlintrc.json
Gates applied: no_behavioural_pass.
1060b7a805c7full audit observations/trust-audit/mcp-server/tosin2013__adr-analysis.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 1060b7a805c7 | BLOCK | F | 37 | first audit |
Questions
What is the ADR Analysis MCP server?
Your ADRs are lying to you. MCP server with live drift detection, content safety, and decision memory — validates architectural decisions against your actual code.
What tools does ADR Analysis expose?
115 in total: 101 read-only, 13 that write, and 1 that can delete or overwrite (manage_cache). Every one is listed on this page with its risk.
Is ADR Analysis safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (37/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does ADR Analysis need?
It reads API_KEY, DB_PASSWORD, JWT_SECRET, OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ADR Analysis run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as sample-api-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (1060b7a805c7), read on 2026-10-08. The repository is watched and re-audited when it changes.