Code-Graph-RAGCAUTION
The ultimate RAG for your monorepo. Query, understand, and edit multi-language codebases with the power of AI and knowledge graphs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
a0c8e5ec3cc0OBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add code-graph-rag --env ORCHESTRATOR_API_KEY=${ORCHESTRATOR_API_KEY} --env CYPHER_API_KEY=${CYPHER_API_KEY} -- uvx code-graph-rag==0.0.973 mcp-serverTrust audit
CAUTIONgrade F · trust 44/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
append_call.bin
delete.bin
delete_recreate.bin
empty_file.bin
multi_edit.bin
vendored = importlib.import_module(cs.TYPER_VENDORED_CLICK_EXCEPTIONS_MODULE)
module = importlib.import_module(module_name)
module = importlib.import_module(module_path)
module = importlib.import_module(module_name)
module = importlib.import_module(module_path)
logger.warning(ls.CAPTURE_UNKNOWN_TOKEN.format(token=token))
url = f"http://127.0.0.1:{port}/readyz"sys.settrace(tracer)
sys.settrace(previous)
"bom": "def f():\n return 1\n",
SECRET = "-----BEGIN OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEAAAAA"
.coderabbit.yaml
.gitmodules
.pre-commit-config.yaml
" yaml.load(u); pickle.loads(u)\n"
" eval(u); exec(u)\n"
"eval(userInput);\n"
" eval($code);\n"
" eval(code)\n"
exec(compile(source, str(path), "exec"), namespace)
Gates applied: no_behavioural_pass.
a0c8e5ec3cc0full audit observations/trust-audit/mcp-server/vitali87__code-graph-rag-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | a0c8e5ec3cc0 | CAUTION | F | 44 | source changed, verdict held |
| 2026-09-18 | 876d15073a6f | CAUTION | F | 44 | first audit |
Questions
What is the Code-Graph-RAG MCP server?
The ultimate RAG for your monorepo. Query, understand, and edit multi-language codebases with the power of AI and knowledge graphs
Is Code-Graph-RAG safe to connect to an agent?
With care. The audit graded it F (44/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Code-Graph-RAG need?
It reads CYPHER_API_KEY, GITHUB_TOKEN, GOOGLE_API_KEY, JWT_SECRET_KEY, KEY, MY_KEY, ORCHESTRATOR_API_KEY, READ_KEY, SECRET and TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Code-Graph-RAG run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as ts_oracle at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (a0c8e5ec3cc0), read on 2026-09-23. The repository is watched and re-audited when it changes.