ocr-mcp-server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| OCR_MCP_TIMEOUT | No | 单次扫描超时(秒) | 120 |
| OCR_MCP_SEMGREP_BIN | No | 分析器可执行文件 | semgrep |
| OCR_MCP_MAX_FINDINGS | No | 单次返回的命中上限 | 50 |
| OCR_MCP_SEMGREP_CONFIG | No | 规则集。可用 p/security-audit、p/python 或本地规则文件 | p/default |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| semgrep_scanA | Run deterministic static analysis (Semgrep) over repository files and return findings with exact line numbers plus the matched source snippet. Use this to substantiate a suspected defect rather than guessing at it: the results are rule matches, so a hit is a fact. The snippet can be reused directly as Scope An empty result is not a clean bill of health — it means no configured rule matched. The ruleset is broad but not exhaustive. |
| semgrep_scan_diffA | Run deterministic static analysis (Semgrep) restricted to the lines changed between two revisions, and return findings with exact line numbers plus the matched source snippet. Prefer this over
|
| semgrep_statusA | Report whether deterministic analysis is available: the Semgrep binary in use, its version, the active ruleset, and the per-call limits. Call this once if a scan reports that it is unavailable. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
All three tools have clearly distinct purposes: one scans an entire repository, one scans only changed lines, and one reports tooling status. The descriptions explicitly clarify when to prefer scan_diff over scan, eliminating meaningful ambiguity.
Every tool follows the same snake_case `semgrep_*` prefix pattern, making the family instantly recognizable. The verb-like suffixes `_scan`, `_scan_diff`, and `_status` are consistent and predictable.
Three tools is well-scoped for a focused analysis server: two scanning modes plus a status endpoint cover the core workflow without redundancy. Each tool earns its place; adding more would likely dilute the server's purpose.
The tool surface covers full-repo scanning, PR/diff scanning, and availability reporting, with no obvious dead ends. The status tool fills the operational gap for diagnosing unavailable scans, making the workflow self-contained.