CicadaSAFE
AI Coders search blindly. Be their guide.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!WARNING] ⚠️ Disclaimer — Today's AI agents operate completely differently from when this project was conceived. In current benchmarks, using a code intelligence tool yields little to no advantage for frontier models. CICADA is discontinued, and I'd advise against using it or any other "code intelligence" tool.
Code Intelligence: Contextual Analysis, Discovery, and Attribution
Context compaction for AI code assistants – Give your AI structured, token-efficient access to 17+ languages including Elixir, Python, TypeScript, JavaScript, Rust, and more.
**Up to 50% less waiting · Up to 70% less tokens · Up to 99% less explanations to do** Tighter context = Better Quality
[](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT) [](https://codecov.io/gh/wende/cicada) [](https://modelcontextprotocol.io)
[](https://elixir-lang.org/) [](https://www.python.org/) [](https://www.typescriptlang.org/) [](https://www.javascript.com/) [](https://www.rust-lang.org/) [](#)
[ | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (16)
module = __import__(module_path, fromlist=[class_name])
cochange_test_repo.bundle
module = __import__(module_path, fromlist=[class_name])
hash_md5 = hashlib.md5()
cd ../../..
cd ../../..
assert is_test_file("../../test_baz.ex")mcp, tree-sitter, tree-sitter-elixir, pyyaml
@sourcegraph/scip-typescript, typescript
# Add to PATH (if needed)
# curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh && \
run: curl -LsSf https://astral.sh/uv/install.sh | sh
public/cicada-demo-extended-clean-trimmed copy.gif
public/no-cicada-demo-trimmed.gif
Gates applied: no_behavioural_pass.
abe48acebbf4full audit observations/trust-audit/mcp-server/wende__cicada.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | abe48acebbf4 | SAFE | B | 86 | first audit |
Questions
What is the Cicada MCP server?
AI Coders search blindly. Be their guide.
Is Cicada safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (86/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Cicada need?
No credential environment variables were found in its source, so it appears to need none.
How does Cicada run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as sample-typescript at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (abe48acebbf4), read on 2026-10-08. The repository is watched and re-audited when it changes.