Sourcery MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| sourcery_capabilitiesC | Return the verified Sourcery integration boundary for this bundle. |
| sourcery_security_snapshotC | Triage overview: counts by status/severity plus the first page of active issues. |
| sourcery_list_findingsB | List security issues with spec filters; pass a previous |
| sourcery_get_findingB | Fetch a single security issue (full record incl. source snippet and dependency graph). |
| sourcery_get_security_countsC | Aggregate issue counts by status and severity. |
| sourcery_bulk_update_findingsB | Bulk-update issue status/severity (max 100 ids; SOLVED cannot be set manually). Returns |
| sourcery_list_groupsC | List security issue groups (same filters as findings; groups aggregate one rule/package). |
| sourcery_get_groupB | Fetch a single issue group including all its issues and any linked tracker task. |
| sourcery_get_group_countsC | Aggregate group counts by status and severity. |
| sourcery_bulk_update_groupsC | Bulk-update groups (max 100 ids); a group updates when at least one issue changes. |
| sourcery_build_fix_promptB | Build a minimal-change agent prompt from a Sourcery finding object. Handles DEPENDENCY findings via |
| sourcery_api_requestB | Compatibility bridge: call one of the eight verified operations directly. Prefer the typed tools. The path allow-list is enforced in the client; anything outside the pinned OpenAPI surface is rejected before a request is made. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 12 tools
Tools are organized around three distinct resources (findings, groups, counts) with clear actions, but there is overlap between sourcery_security_snapshot, sourcery_get_security_counts, and sourcery_get_group_counts, which could cause confusion about which to use for simple count retrieval. The compatibility bridge sourcery_api_request overlaps with all typed operations.
Nearly all tools follow a consistent 'sourcery_verb_noun' pattern (list_findings, get_group, bulk_update_findings, build_fix_prompt). Slight inconsistency in 'security_snapshot' and 'api_request' which are nouns rather than verb_noun, but overall very predictable.
12 tools is a reasonable number for a security finding management server. The presence of both typed tools and a generic API request bridge is slightly redundant but justified as a compatibility layer.
The server provides full lifecycle coverage for findings and groups (list, get, bulk update) and helpful aggregation tools. However, it lacks single-item update operations (only bulk), and does not support creating or deleting findings/groups, which may be by design but creates minor gaps for common workflows.