Code Analysis
Tools for static analysis, code intelligence, and code understanding. Provides capabilities for parsing, analyzing, and gaining insights into codebases across different programming languages.
MCP ServersBrowse all โ
AlicenseBqualityDmaintenanceAllows developers to query security findings (SAST issues, secrets, patches) using natural language within AI-assisted tools like Claude Desktop, Cursor, and other MCP-compatible environments.179MIT- AlicenseAqualityBmaintenanceOfficial Codna MCP server with Mojo-powered risk simulation. Maps repos with zero LLM tokens. 5 stdio tools: triage, root-cause analysis and fix plans (optional PRs), SARIF reachability proof, on-device code memory and bug reporting. Introspection needs no credentials; execution requires a one-time free codna login. Source: cli/codna/mcp_server.py. Registry: io.github.thyn-ai/codna.5Apache 2.0

mcp-repodnaofficial
AlicenseAqualityBmaintenanceAnalyzes repositories to extract engineering culture and conventions, generating executable skill scripts and rule documents for AI coding agents.42Apache 2.0
Chromia LSP MCPofficial
AlicenseAqualityBmaintenanceEnables AI assistants to query and analyze Rell code via Language Server Protocol features like hover information, completions, diagnostics, and code actions. Automatically manages the Rell LSP server and provides resource-based access with real-time subscriptions.107 npmMIT- MIT
- AlicenseAqualityBmaintenanceEnables MCP-native multi-agent security audits for Google Antigravity, orchestrating subagents for 0day research, static analysis, PoC verification, exploit chaining, reporting, and code remediation.6153MIT
- AlicenseAqualityAmaintenancePHP static analysis MCP server with 11 tools for querying 60+ code quality metrics, detecting problems (God Class, dependency cycles, SOLID violations), analyzing dependencies, identifying refactoring priorities, and mapping test coverage โ all from live analysis data.113 npm92MIT

kinofficial
AlicenseBqualityAmaintenanceKin is an open-source code repository for people and AI agents. It versions code and recorded relationships together.2264Apache 2.0- AlicenseAqualityAmaintenance๐ ๐ - Code graph for AI agents over MCP: resolves Python and TypeScript calls to fully qualified names and reports the share it could not resolve instead of guessing. Multi-hop impact analysis, authz reachability audit, architectural drift against declared patterns. Local, SQLite. uvx codegraph-brain1415231 PyPI2MIT
- AlicenseAqualityAmaintenanceLocal memory for coding agents that can refuse, not only recall. A rule carrying a machine-checkable proof blocks the matching command before it runs, while prose-only rules can warn but never block.6164GPL 3.0

Symbiotic MCP Serverofficial
AlicenseAqualityDmaintenanceEnables security analysis of code and infrastructure files via MCP, using Symbiotic CLI for scanning vulnerabilities.4MIT
AgentAuditofficial
AlicenseAqualityDmaintenanceEnables AI agents to scan MCP servers and AI packages for vulnerabilities, prompt injection, and supply chain attacks.7167 npmAGPL 3.0- AlicenseBqualityDmaintenanceConnects Claude Code to a Latent Defense deployment to map GitHub repositories into an infrastructure graph, discover attack paths using the JEPA energy model, and triage findings from the terminal.85Apache 2.0
- AlicenseAqualityAmaintenanceA 100% local MCP server for semantic and lexical search over your code, library docs, and PDFs, featuring hybrid BM25 and dense retrieval, syntax aware chunking, and an optional code knowledge graph. It also ships a Coral integration, so you can expose your code search as SQL and join it with live data, all without anything leaving your machine.816115 PyPI9Apache 2.0
- AlicenseAqualityAmaintenanceMarrow is an MCP server that solves agent amnesia. It gives coding agents persistent task tracking, versioned docs, and semantic search over your actual source code (via a tree-sitter powered background indexer) โ so a new session, or a different model entirely, can pick up exactly where the last one left off. Built for multi-agent, multi-session software delivery.620247MIT
- AlicenseAqualityBmaintenanceRead, write, analyze and test the VBA inside Excel, Word, PowerPoint and Access files, and edit the document around it. The file layer needs no Office installation and runs anywhere; running macros and tests needs Windows with Office.12658MIT

lachesis-mcpofficial
AlicenseBqualityAmaintenanceExposes Lachesis's code navigation tools over MCP, letting LLM agents ask precise compiler-level questions about dataflow, taint, callers, and guards in source code.50163 PyPI3AGPL 3.0
mcp-reposkeinofficial
AlicenseAqualityAmaintenanceDeterministic code-graph (GraphRAG) over your repo for LLM agents โ local-first, git-native, zero-infra, served via MCP. Python, TS/JS, Rust, Go, Java, C#.812Apache 2.0- AlicenseAqualityAmaintenanceRead-only MCP server that gives Claude Code and Codex clean, token-efficient codebase context, with API keys and passwords masked automatically.17826Apache 2.0

noir-mcp-serverofficial
AlicenseAqualityCmaintenanceMCP server for Noir development that clones and searches Noir documentation, standard library, examples, and community libraries.920 npm3MIT- AlicenseBqualityAmaintenanceEnables deterministic verification for AI assistants by executing Python code that uses symbolic engines like SymPy and Z3 for math, logic, and code analysis.2Apache 2.0
- AlicenseAqualityDmaintenanceDeterministic code review MCP server that provides tools for file selection, rule matching, comment positioning, and reflection, ensuring stable review quality without LLM calls.513 npm1MIT
- AlicenseAqualityAmaintenanceEnables AI to read and analyze repository incident scan results, including file diffs and summaries, to help investigate suspicious changes. It is read-only and does not execute code or send data externally.1144 npmMIT

treeweft-mcpofficial
AlicenseAqualityAmaintenanceProvides GraphRAG code search to AI agents, combining structural code graph traversal with semantic and keyword retrieval so agents can find relevant code without exact name matches.20MIT- AlicenseAqualityAmaintenanceContract-first programming language with a local MCP server for checking types, effects, capabilities, and contracts in agent-written modules. Its review tool compares before and after source sets and returns receipts for new authority, weaker promise tiers, and new Guarded runtime obligations.78Apache 2.0

OuterSpace Apizrofficial
AlicenseAqualityAmaintenanceOpen-source capability compiler for Python codebases. Discover existing Python capabilities, plan explicit exposure, and expose selected functions through MCP or REST without rewriting business logic.31,428 PyPI3GPL 3.0- AlicenseAqualityCmaintenanceEnables safe read-only interaction with SQL Server and Azure SQL databases, providing schema exploration, query linting and analysis, query plan insights, write previews as SELECTs, and a versioned library of .sql queries via MCP.29MIT
- AlicenseAqualityAmaintenanceThis server enables AI-assisted APK reverse-engineering entirely on-device, orchestrating jadx, apktool, adb, frida, and APKiD through a job/workflow engine, and exposing those agents as native MCP tools for Claude without any cloud dependency.38208MIT

mergesafe-mcpofficial
AlicenseAqualityCmaintenanceEnables coding agents to retrieve pull request review findings, reproduce and fix them locally, reply on review threads, report reproduction results, and request fresh reviews.4MIT
Asyntheticofficial
AlicenseAqualityDmaintenanceAn MCP server that gives AI coding agents verified migration maps: exactly what breaks between two versions of a library and how to fix it, from hand-curated maps with source citations - instead of hallucinated answers from stale training data551 npmBusiness Source 1.1
MCP ConnectorsBrowse all โ
Signed third-party verdict on what an npm package or file does when run. No key, no signup.
Coding agents in multi-service codebases routinely rebuild existing helpers, trust stale type definitions, and modify API contracts without knowing who consumes them. Carrick solves this by indexing your entire TypeScript ecosystem across service and repository boundaries. By integrating deeply with the TypeScript compiler, Carrick traces every route, type, and cross-service call while recording function behaviour so agents search by intent rather than name. Delivered via MCP for AI agents and LSP for IDEs, Carrick ensures models see existing endpoints and utilities before generating new code. The scanner is source-available and runs from your CLI or CI pipeline.
Lint a SKILL.md for frontmatter, structure, secrets and size. All 6 tools free.
Thermal label MCP server: render, validate, debug and convert ZPL, EPL, TSPL and CPCL labels.
Risk-scan a diff, flag AI-generated-code tells, find secrets. 5 of 7 tools need no account.
Guardian agent for AI coding: four frontier models review risky diffs and commits before they ship.
Scan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.
Production-safety audits for AI-generated code, with a fix for every finding.
Review and rewrite LangChain, LlamaIndex, Ollama, and XRPL code against current APIs.
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
**Can AI actually read your page?** ChatGPT, Perplexity, Claude and Google's AI Overviews fetch pages very differently from your browser โ no JavaScript, tight timeouts, and a robots.txt rulebook of their own. Lekta fetches a URL exactly the way they do and grades what survives, **A+ to F**. This is the technical half of **AEO** (answer engine optimization) and **GEO** (generative engine optimization): before a model can cite you, it has to be able to fetch you, parse you, and find one sentence worth quoting. **The loop this server was built for:** `Audit https://mysite.com/pricing with Lekta, apply the fixes it lists, audit it again, and show me the difference.` Your agent gets a graded verdict, a ranked fix plan with the exact markup to paste, and a diff that proves the change landed. Repeat until A+. **Four layers, 100 points:** **Access** 25 โ do the ~17 AI crawler tokens get past robots.txt? **Indexability** 25 โ how much content survives without JavaScript? **Answerability** 30 โ is there a single quotable sentence an engine can lift? **Recency** 20 โ can a model tell when this page was last true? **What this is not:** a rank tracker. Lekta will not tell you how often ChatGPT mentions your brand. It tells you whether your page can be read and quoted when it does โ the part you can actually fix. **No black box.** Every finding cites its basis โ an RFC, a vendor doc, or a dated measurement we ran. The engine is versioned with a public changelog: a score never moves without a published shift table. **Tools:** `lekta_audit` (fresh fetch) ยท `lekta_report` (cached read) ยท `lekta_fix_plan` (ranked, paste-ready) ยท `lekta_diff` (before/after) ยท `lekta_my_sites` Listing tools is open. Tool calls need a free key from lekta.dev/en/panel/api โ send `Authorization: Bearer lekta_โฆ` or `x-api-key`. Cached reads, fix plans and diffs cost nothing; only fresh fetches count against the daily limit. **Topics:** AEO ยท GEO ยท AI SEO ยท LLM SEO ยท answer engine optimization ยท generative engine optimization ยท AI crawler access (GPTBot, ClaudeBot, PerplexityBot, Google-Extended) ยท JavaScript-free indexability ยท structured data ยท content freshness
Hosted, OAuth-gated endpoint for quantakrypto's post-quantum crypto tools: scan code for quantum-vulnerable cryptography (RSA/ECDH/ECDSA/DH) and get NIST ML-KEM/ML-DSA/SLH-DSA migration guidance over authenticated HTTP โ nothing to install. Sign-in required (Google/GitHub/email). Same tools as the open-source @quantakrypto/mcp server; source at github.com/quantakrypto/pqc-tools.
Check that your AI is being logical. Free tool that mathematically catches contradictions in agent reasoning. No account needed. Also offers paid guardrails that converts natural language to formal verification proofs, that anyone can check succinctly.
Paid AI utility APIs for semantic web comparison, migration safety, code verification, document extraction, security analysis, monitoring, accessibility auditing, and citation research. Accessible through MCP with x402 payments on Base mainnet.
Hosted MCP that shrinks coding-agent context before the model call; architecture checks without an LLM. Zero data retention.
CodeSentinel โ AI-powered codebase health agent
Paid AI utilities for web comparison, code checks, document extraction, security, and research.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).