Skip to main content
Glama
abyssbugg-labs

Sourcery MCP Server

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
sourcery_capabilitiesC

Return the verified Sourcery integration boundary for this bundle.

sourcery_security_snapshotC

Triage overview: counts by status/severity plus the first page of active issues.

sourcery_list_findingsB

List security issues with spec filters; pass a previous next_cursor to page.

sourcery_get_findingB

Fetch a single security issue (full record incl. source snippet and dependency graph).

sourcery_get_security_countsC

Aggregate issue counts by status and severity.

sourcery_bulk_update_findingsB

Bulk-update issue status/severity (max 100 ids; SOLVED cannot be set manually).

Returns updated_ids plus failed entries with reason not_found or not_eligible.

sourcery_list_groupsC

List security issue groups (same filters as findings; groups aggregate one rule/package).

sourcery_get_groupB

Fetch a single issue group including all its issues and any linked tracker task.

sourcery_get_group_countsC

Aggregate group counts by status and severity.

sourcery_bulk_update_groupsC

Bulk-update groups (max 100 ids); a group updates when at least one issue changes.

sourcery_build_fix_promptB

Build a minimal-change agent prompt from a Sourcery finding object.

Handles DEPENDENCY findings via fixed_versions + manifest_file_path and renders the dependency chain when dependency_graph is present.

sourcery_api_requestB

Compatibility bridge: call one of the eight verified operations directly.

Prefer the typed tools. The path allow-list is enforced in the client; anything outside the pinned OpenAPI surface is rejected before a request is made.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3/5.0

Scored across 12 tools

Disambiguation3/5

Tools are organized around three distinct resources (findings, groups, counts) with clear actions, but there is overlap between sourcery_security_snapshot, sourcery_get_security_counts, and sourcery_get_group_counts, which could cause confusion about which to use for simple count retrieval. The compatibility bridge sourcery_api_request overlaps with all typed operations.

Naming Consistency4/5

Nearly all tools follow a consistent 'sourcery_verb_noun' pattern (list_findings, get_group, bulk_update_findings, build_fix_prompt). Slight inconsistency in 'security_snapshot' and 'api_request' which are nouns rather than verb_noun, but overall very predictable.

Tool Count4/5

12 tools is a reasonable number for a security finding management server. The presence of both typed tools and a generic API request bridge is slightly redundant but justified as a compatibility layer.

Completeness4/5

The server provides full lifecycle coverage for findings and groups (list, get, bulk update) and helpful aggregation tools. However, it lacks single-item update operations (only bulk), and does not support creating or deleting findings/groups, which may be by design but creates minor gaps for common workflows.

Maintenance

ActivityMaintained
ResponsivenessNo issues