GoplsBLOCK
MCP server for golang projects development: Expand AI Code Agent ability boundary to have a semantic understanding and determinisic information for golang projects.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Give your AI Agent the compiler's brain, not a text searcher.
Documentation: https://gopls-mcp.org
gopls-mcp delivers type-checker-level semantic analysis directly to your LLM. Unlike text search, it resolves Go's type system — interface satisfaction, cross-package identity, and shadowed scopes — with the same precision as the compiler.
Where it pays off most is on semantic tasks: finding all concrete types that implement an interface, tracing call hierarchies, and mapping package dependencies. A benchmark over 11 tasks shows gopls-mcp uses 2–4× fewer tool calls and finishes faster than grep-based navigation on those tasks. For simple same-file lookups, plain bash/grep remains equally effective and carries less overhead.
Install
Claude Code (plugin — recommended)
/plugin marketplace add https://github.com/xieyuschen/gopls-mcp.git /plugin install gopls-mcp
The plugin automatically installs the binary and injects the routing skill — no manual setup required.
Codex (plugin — recommended)
codex plugin marketplace add https://github.com/xieyuschen/gopls-mcp.git codex plugin add gopls-mcp
Manual install (all clients)
Linux / macOS:
curl -sSL https://gopls-mcp.org/install.sh | bash
Windows (PowerShell):
irm https://gopls-mcp.org/install.ps1 | iex
Then follow the per-client setup at https://gopls-mcp.org/quick-start.
Contribute
The project is actively developing, and feel free to raise PRs or issues if you find anything to improve. AI generated code will also be accepted but do remember to narrow the change to a specific feature for reviewer to quickly review them.
Disclaimer: gopls-mcp is a fork of gopls and is a community-driven project. It is not an official Go team product and is not affiliated with or endorsed by Google LLC. This project is licensed under the same BSD license as its [upstream](https://go.googlesou
c7889aa51893OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add gopls-mcp-docs -- npx -y [email protected]
{
"mcpServers": {
"gopls-mcp-docs": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Trust audit
BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
backdoor.go
func (act *action) exec(ctx context.Context) (any, *actionSummary, error) {clang-386-darwin-exec-with-rpath
clang-386-darwin.obj
clang-amd64-darwin-exec-with-rpath
clang-amd64-darwin.obj
fat-gcc-386-amd64-darwin-exec
addr url.URL // "http://127.0.0.1:PORT/gopls/SECRET"
{"SysProcAttr.Ptrace", Field, 0, ""},const _SyncMarker_name = "EOFBoolInt64Uint64StringValueValRelocsRelocUseRelocPublicPosPosBaseObjectObject1PkgPkgDefMethodTypeTypeIdxTypeParamNamesSignatureParamsParamCodeObjSymLocalIdentSelectorPrivat
_ErrorCode_name_1 = "TestBlankPkgNameMismatchedPkgNameInvalidPkgUseBadImportPathBrokenImportImportCRenamedUnusedImportInvalidInitCycleDuplicateDeclInvalidDeclCycleInvalidTypeCycleInvalidConstInitInval
<div style="color: #6a737d; font-size: 0.8em; margin-bottom: 8px; display:flex; justify-content:space-between;">
r := <span style="background: #e6ffec; border: 1px dashed #28a745; padding: 0 2px; border-radius: 2px;">gin.Default</span>() <span style="color:#6a737d; font-family: sans-serif; font-size:
<div style="color: #6a737d; font-size: 0.8em; margin-bottom: 10px; font-weight:bold; letter-spacing:0.05em;">
streamable-http
.goreleaser.yaml
CLAUDE.md
gopls/CLAUDE.md
gopls/README.md
gopls/mcpbridge/README.md
site/public/gopls-mcp.prompt
func (c comparator) eval(val, ref float32) bool {if eval(rnd, expr, have) {func eval(rnd *rand.Rand, z constraint.Expr, have map[string]bool) bool {return !eval(rnd, z.X, have)
Gates applied: no_behavioural_pass.
c7889aa51893full audit observations/trust-audit/mcp-server/xieyuschen__gopls-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | c7889aa51893 | BLOCK | F | 47 | first audit |
Questions
What is the Gopls MCP server?
MCP server for golang projects development: Expand AI Code Agent ability boundary to have a semantic understanding and determinisic information for golang projects.
Is Gopls safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (47/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Gopls need?
No credential environment variables were found in its source, so it appears to need none.
How does Gopls run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as gopls-mcp-docs at 1.0.4.
How current is this page?
The grade is for one exact copy of the source (c7889aa51893), read on 2026-10-08. The repository is watched and re-audited when it changes.