SqryBLOCK
Semantic code search engine - by Verivus (sqry.dev)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://registry.modelcontextprotocol.io/v0.1/servers/io.github.verivus-oss%2Fsqry/versions/latest) [](https://crates.io/crates/sqry-cli) [](https://opensource.org/licenses/MIT)
sqry is a local semantic code search tool. It parses source code into AST-backed symbol and relationship graphs so you can ask code questions that text search cannot answer reliably.
Everything runs on your machine. Indexing and querying make no network calls, and sqry sends no telemetry.
Website: https://sqry.dev
Current Capabilities
- 37 language plugins, 28 with full relation support and 9 with symbol extraction plus imports. By build cost, 29 are on the default fast path,
jsonis compiled but excluded by default as high-wall-clock, and 7 specialty plugins sit behind Cargo features. Thesqry://meta/manifestMCP resource reports these counts for the binary you have installed. - Structural queries over symbol kind, language, visibility, names, return types, references, and relations.
- Graph analysis for callers, callees, imports, exports, call paths, cycles, unused symbols, duplicates, impact, semantic diff, and focused subgraphs.
- Edge-backed
returns:and resolution-awareresolved_via:predicates for supported graph paths. See Call resolution predicates. - Cross-language FFI edges. The C, C++, C#, Elixir, Haskell, Kotlin, Lua, PHP, R, Ruby, and Rust plugins emit
FfiCalledges from mechanisms such asextern "C",DllImport/ P/Invoke, JNI, Ruby FFIattach_function, and R.Call/Rcpp. Query them withsqry graph cross-languageor thecross_language_edgesMCP tool. - Structural shape matching with
sqry shape-match, which finds functions with similar body structure independently of their identifiers. - A declarative
7a01572113d1OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add sqry-mcp:v33.0.1 -- docker run -i --rm ghcr.io/verivus-oss/sqry-mcp:v33.0.1:None
Trust audit
BLOCKgrade F · trust 58/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
&["api_key=sk_live_abc123def456ghi789".to_string()],
"/root/.ssh/id_ed25519",
"/root/.ssh/id_ed25519",
fuzz-crash-703-multibyte-selector.css
.lsp.json
.clangd
.vscodeignore
.cargo_vcs_info.json
.cargo_vcs_info.json
"expected at least one Rust function ('main' or 'process') in results; got: {names:?}""expected at least one Python function ('handle_request' or 'transform') in results; got: {names:?}""/root/.ssh/id_ed25519",
target.symlink_to("../../../agent-skills/skills/alpha/SKILL.md")target.symlink_to("../../../agent-skills/skills/alpha/SKILL.md")target.symlink_to("../../../agent-skills/skills/alpha/SKILL.md")target.symlink_to("../../../.claude/skills/alpha/SKILL.md")os.symlink("../../stale/gamma", repo / ".claude/skills/gamma")IyBIb21lYnJldyBUYXAgZm9yIHNxcnkKCltzcXJ5XShodHRwczovL3NxcnkuZGV2KSBpcyBhIGxlYW4sIGZvY3VzZWQgKipzZW1hbnRpYyBjb2RlIHNlYXJjaCB0b29sKioKYnVpbHQgaW4gUnVzdC4gSXQgdW5kZXJzdGFuZHMgY29kZSBzdHJ1Y3R1cmUgdGhyb3Vn
package Café::Ωmega;
assert!(has_function_suffix(&staging, "Café::Ωmega::función"));
assert!(has_function_suffix(&staging, "Café::Ωmega::precißión"));
assert!(has_module_node(&staging, "Café::Ωmega"));
elkjs, fflate, https-proxy-agent, sigstore, vscode-languageclient, which, @types/chai, @types/mocha
- *(session)* harden graph cache semantics- *(session)* use session graph cache for queries- *(graph)* clarify detailed stats and sync 25.0.2 metadata## [25.0.2](https://github.com/verivus-oss/sqry/co
Gates applied: critical_finding, no_behavioural_pass.
7a01572113d1full audit observations/trust-audit/mcp-server/verivus-oss__sqry.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7a01572113d1 | BLOCK | F | 58 | first audit |
Questions
What is the Sqry MCP server?
Semantic code search engine - by Verivus (sqry.dev)
Is Sqry safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (58/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Sqry need?
No credential environment variables were found in its source, so it appears to need none.
How does Sqry run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as sqry-vscode at 33.0.1.
How current is this page?
The grade is for one exact copy of the source (7a01572113d1), read on 2026-10-08. The repository is watched and re-audited when it changes.