Atlas / MCP servers / xieyuschen / Gopls

GoplsBLOCK

mcp/xieyuschen/gopls-1

MCP server for golang projects development: Expand AI Code Agent ability boundary to have a semantic understanding and determinisic information for golang projects.

Verdict
BLOCK
Grade
F
Trust score
47 /100
Exposed tools
—
Transport
streamable-http
License
BSD-3-Clause
Stars
59
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Give your AI Agent the compiler's brain, not a text searcher.

Documentation: https://gopls-mcp.org

gopls-mcp delivers type-checker-level semantic analysis directly to your LLM. Unlike text search, it resolves Go's type system — interface satisfaction, cross-package identity, and shadowed scopes — with the same precision as the compiler.

Where it pays off most is on semantic tasks: finding all concrete types that implement an interface, tracing call hierarchies, and mapping package dependencies. A benchmark over 11 tasks shows gopls-mcp uses 2–4× fewer tool calls and finishes faster than grep-based navigation on those tasks. For simple same-file lookups, plain bash/grep remains equally effective and carries less overhead.

Install

Claude Code (plugin — recommended)

/plugin marketplace add https://github.com/xieyuschen/gopls-mcp.git
/plugin install gopls-mcp

The plugin automatically installs the binary and injects the routing skill — no manual setup required.

Codex (plugin — recommended)

codex plugin marketplace add https://github.com/xieyuschen/gopls-mcp.git
codex plugin add gopls-mcp

Manual install (all clients)

Linux / macOS:

curl -sSL https://gopls-mcp.org/install.sh | bash

Windows (PowerShell):

irm https://gopls-mcp.org/install.ps1 | iex

Then follow the per-client setup at https://gopls-mcp.org/quick-start.

Contribute

The project is actively developing, and feel free to raise PRs or issues if you find anything to improve. AI generated code will also be accepted but do remember to narrow the change to a specific feature for reviewer to quickly review them.

Disclaimer: gopls-mcp is a fork of gopls and is a community-driven project. It is not an official Go team product and is not affiliated with or endorsed by Google LLC. This project is licensed under the same BSD license as its [upstream](https://go.googlesou

Read from source at commit c7889aa51893OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add gopls-mcp-docs -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "gopls-mcp-docs": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Trust audit

BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (7 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
tools/go/internal/gccgoimporter/backdoor.go
backdoor.go
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
gopls/internal/cache/analysis.go:904
func (act *action) exec(ctx context.Context) (any, *actionSummary, error) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/cmd/splitdwarf/internal/macho/testdata/clang-386-darwin-exec-with-rpath
clang-386-darwin-exec-with-rpath
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/cmd/splitdwarf/internal/macho/testdata/clang-386-darwin.obj
clang-386-darwin.obj
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/cmd/splitdwarf/internal/macho/testdata/clang-amd64-darwin-exec-with-rpath
clang-amd64-darwin-exec-with-rpath
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/cmd/splitdwarf/internal/macho/testdata/clang-amd64-darwin.obj
clang-amd64-darwin.obj
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/cmd/splitdwarf/internal/macho/testdata/fat-gcc-386-amd64-darwin-exec
fat-gcc-386-amd64-darwin-exec
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
gopls/internal/server/server.go:227
addr   url.URL // "http://127.0.0.1:PORT/gopls/SECRET"
MEDIUMObfuscation / stealth · obf.anti_debug · CWE-506, CWE-94
tools/internal/stdlib/manifest.go:16621
{"SysProcAttr.Ptrace", Field, 0, ""},
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
tools/internal/pkgbits/syncmarker_string.go:82
const _SyncMarker_name = "EOFBoolInt64Uint64StringValueValRelocsRelocUseRelocPublicPosPosBaseObjectObject1PkgPkgDefMethodTypeTypeIdxTypeParamNamesSignatureParamsParamCodeObjSymLocalIdentSelectorPrivat
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
tools/internal/typesinternal/errorcode_string.go:162
_ErrorCode_name_1 = "TestBlankPkgNameMismatchedPkgNameInvalidPkgUseBadImportPathBrokenImportImportCRenamedUnusedImportInvalidInitCycleDuplicateDeclInvalidDeclCycleInvalidTypeCycleInvalidConstInitInval
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
site/src/content/docs/index.mdx:23
<div style="color: #6a737d; font-size: 0.8em; margin-bottom: 8px; display:flex; justify-content:space-between;">
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
site/src/content/docs/index.mdx:31
&nbsp;&nbsp;r := <span style="background: #e6ffec; border: 1px dashed #28a745; padding: 0 2px; border-radius: 2px;">gin.Default</span>() <span style="color:#6a737d; font-family: sans-serif; font-size:
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
site/src/content/docs/index.mdx:38
<div style="color: #6a737d; font-size: 0.8em; margin-bottom: 10px; font-weight:bold; letter-spacing:0.05em;">
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
gopls/CLAUDE.md
gopls/CLAUDE.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
gopls/README.md
gopls/README.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
gopls/mcpbridge/README.md
gopls/mcpbridge/README.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
site/public/gopls-mcp.prompt
site/public/gopls-mcp.prompt
Why it matters. link not followed
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
gopls/internal/fuzzy/matcher_test.go:45
func (c comparator) eval(val, ref float32) bool {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tools/cmd/bisect/main_test.go:88
if eval(rnd, expr, have) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tools/cmd/bisect/main_test.go:124
func eval(rnd *rand.Rand, z constraint.Expr, have map[string]bool) bool {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tools/cmd/bisect/main_test.go:129
return !eval(rnd, z.X, have)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c7889aa51893full audit observations/trust-audit/mcp-server/xieyuschen__gopls-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c7889aa51893BLOCKF47first audit
05

Questions

What is the Gopls MCP server?

MCP server for golang projects development: Expand AI Code Agent ability boundary to have a semantic understanding and determinisic information for golang projects.

Is Gopls safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (47/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Gopls need?

No credential environment variables were found in its source, so it appears to need none.

How does Gopls run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as gopls-mcp-docs at 1.0.4.

How current is this page?

The grade is for one exact copy of the source (c7889aa51893), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement