Skip to main content
Glama

analyze

Runs the open-source hefesto-ai engine (hefesto analyze --no-config, free tier) on the files you send and returns its findings: rule id, severity, file, line, message and the SARIF hefestoFingerprint/v1 fingerprint (format "sarif" adds the full SARIF 2.1.0 log). Covers Python, COBOL, the DevOps/IaC formats hefesto analyze routes, and TypeScript, JavaScript, Java, Go, Rust and C# through the multilang tree-sitter grammars (the first such request on a fresh server instance downloads the grammars and can take a few seconds longer). Limits: 20 files, 100 KB per file, 256 KB in total, 20 seconds. No .hefesto.yaml is read. Files are deleted after the run; nothing is stored.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
codeNoA single snippet, used when files is not given (written as e.g. snippet.py for language python).
filesNoFiles to analyze. path: relative POSIX path (letters, digits, '_', '.', '-'; no '..', no absolute paths); content: UTF-8 text.
formatNojson (default): findings only; sarif: also the full SARIF 2.1.0 log.
languageNoLanguage of code: python (default), cobol, yaml, dockerfile, terraform, shell, sql, javascript, typescript, java, go, rust, csharp.
severityNoMinimum severity to report (default LOW).

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed5 schema fields changed
    • changedInput schema / properties / code / description
      Previous value: -"Ignored. Accepted for backward compatibility; run hefesto analyze locally to analyze code."New value: +"A single snippet, used when files is not given (written as e.g. snippet.py for language python)."
    • addedInput schema / properties / files
      Added value: +{
      +  "description": "Files to analyze. path: relative POSIX path (letters, digits, '_', '.', '-'; no '..', no absolute paths); content: UTF-8 text.",
      +  "items": {
      +    "properties": {
      +      "content": {
      +        "type": "string"
      +      },
      +      "path": {
      +        "maxLength": 200,
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "path",
      +      "content"
      +    ],
      +    "type": "object"
      +  },
      +  "maxItems": 20,
      +  "type": "array"
      +}
    • addedInput schema / properties / format
      Added value: +{
      +  "description": "json (default): findings only; sarif: also the full SARIF 2.1.0 log.",
      +  "enum": [
      +    "json",
      +    "sarif"
      +  ],
      +  "type": "string"
      +}
    • changedInput schema / properties / language / description
      Previous value: -"Ignored. Accepted for backward compatibility."New value: +"Language of code: python (default), cobol, yaml, dockerfile, terraform, shell, sql, javascript, typescript, java, go, rust, csharp."
    • addedInput schema / properties / severity
      Added value: +{
      +  "description": "Minimum severity to report (default LOW).",
      +  "enum": [
      +    "LOW",
      +    "MEDIUM",
      +    "HIGH",
      +    "CRITICAL"
      +  ],
      +  "type": "string"
      +}
  2. Changed3 schema fields changed
    • changedInput schema / properties / code / description
      Previous value: -"Code snippet to analyze"New value: +"Ignored. Accepted for backward compatibility; run hefesto analyze locally to analyze code."
    • changedInput schema / properties / language / description
      Previous value: -"Programming language (python, javascript, etc)"New value: +"Ignored. Accepted for backward compatibility."
    • changedInput schema / required
      Previous value: -[
      -  "code"
      -]New value: +[]
  3. First observed

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.