Charlie Work
Charlie Work is a code-health MCP server that scans, prioritizes, and tracks maintenance toil (technical debt) in your repository, integrating with AI agents and CI/CD pipelines.
Scan for toil (charlie_scan_toil): Detect flaky/skipped/focused tests, TODO rot, expiring TLS certs, dead feature flags, vulnerable/outdated dependencies, secret leaks, unpinned deps, unowned scripts, and stray debug statements. Findings are ranked by severity, effort, confidence tier (verified, high, heuristic), and a hotspot multiplier (churn × complexity). Detection uses real parsers (Python AST, tree-sitter) and authoritative data sources (OSV.dev, PyPI/npm/crates, real X.509 parsing).
Summarize toil budget (charlie_summary): Report total estimated remediation minutes, a debt ratio, and an A–E maintainability grade — inspired by Google SRE's "keep toil under 50%" guideline.
Triage top findings (charlie_triage): Return a prioritized top-N action plan of the most critical toil items for an agent or developer to work through.
Explain a specific finding (charlie_explain): Dive deep into a toil item by ID — evidence, why it's real debt, hotspot weight, owner, and a suggested fix.
Track toil over time (charlie_trend): Record budget snapshots and report deltas to observe whether technical debt is improving or degrading.
Record completed work (charlie_did_it): Log that someone cleared a piece of toil, persisting credit to a local ledger so invisible maintenance work becomes visible.
View the credit ledger (charlie_ledger): See who cleared what, the current "Champion of the Grease Trap," and how much toil remains open — ideal for standups and retros.
Generate automated patches: For auto-safe toil types (e.g., removing breakpoint()), the server can suggest ready-to-apply unified diffs without directly modifying files.
CI/CD integration: Can serve as a CI gate to block new high-severity toil and generate SARIF output. Output mode can be toggled between charlie (personality-flavored) and plain (paste-into-a-ticket clean).
Folds in open issues and PRs labeled with chore, tech-debt, or good-first-issue from a GitHub repository.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Charlie WorkScan this repo for toil and show the prioritized queue."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Charlie Work
A code-health tool that surfaces — and dignifies — the toil in your repo. An MCP server and a CLI and a CI gate.
The un-fun, load-bearing maintenance work everyone ignores until it bites: flaky tests, a TLS cert nine days from death, known-vulnerable dependencies, committed secrets, dead feature flags, TODO rot, scripts nobody owns. Charlie Work scans your repo with real parsers and real vulnerability data, ranks the findings by where your team actually bleeds time, and keeps a credit ledger so the invisible work finally shows up in standup.
Named after the episode where the gang realizes Charlie has been quietly holding Paddy's together the whole time.
THIS IS CHARLIE WORK. Nobody else will do it. That's why it's yours.
The jokes are a toggle, not a tax — pass mode="plain" (or set CHARLIE_VOICE=off) and every response is flavor-free, paste-into-a-ticket clean. CI and SARIF output are always plain.
Use it with any agent
Charlie is a stdio MCP server, so it drops into every MCP client — Claude Code, Codex, Cursor, VS Code, Claude Desktop, Windsurf, Zed, Gemini, Cline. The universal config is one block:
{
"mcpServers": {
"charlie-work": { "command": "uvx", "args": ["charlie-work-mcp"] }
}
}Don't hand-write it — let Charlie wire himself in:
uvx --from charlie-work-mcp charlie-work install --client cursor --write # or: codex, claude-code, vscode, …install knows each client's dialect and prints (or, for project-local clients, --writes) the exact config. Run install --client all to see every one.
Claude Code — claude mcp add --transport stdio charlie-work -- uvx charlie-work-mcp (or the block above in .mcp.json).
OpenAI Codex CLI — ~/.codex/config.toml:
[mcp_servers.charlie-work]
command = "uvx"
args = ["charlie-work-mcp"]Cursor (.cursor/mcp.json), Claude Desktop (claude_desktop_config.json), Windsurf, Gemini CLI, Cline — the universal mcpServers block above.
VS Code — .vscode/mcp.json uses servers (not mcpServers):
{ "servers": { "charlie-work": { "type": "stdio", "command": "uvx", "args": ["charlie-work-mcp"] } } }Zed — settings.json uses context_servers:
{ "context_servers": { "charlie-work": { "source": "custom", "command": "uvx", "args": ["charlie-work-mcp"] } } }Teach every agent the drill — write a Charlie section into AGENTS.md (the cross-vendor rules file read by Codex, Cursor, Copilot, Gemini, Aider, Windsurf, Zed; Claude reads it too):
uvx --from charlie-work-mcp charlie-work initAs a CLI:
uvx --from charlie-work-mcp charlie-work scan # the prioritized toil queue
charlie-work next # the single next best fix, as a patch
charlie-work fix --top 5 | git apply # patch the safe ones
charlie-work summary # toil budget + A–E gradeAs a CI gate — fail a PR only when it introduces new high-severity toil ("Clean as You Code"):
- uses: Falcon305/charlie-work-mcp@master
with:
severity: "4"As a scheduled watchman — some toil is time-based: a cert quietly ticks toward expiry, a TODO ages, a new CVE lands against a dep you already shipped. A nightly scan catches it before it pages you:
on:
schedule: [{ cron: "0 7 * * *" }]
jobs:
charlie:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- run: uvx --from charlie-work-mcp charlie-work sarif -o charlie.sarif
- uses: github/codeql-action/upload-sarif@v3
with: { sarif_file: charlie.sarif }Until the PyPI release lands, replace
uvx charlie-work-mcpwithuvx --from git+https://github.com/Falcon305/charlie-work-mcp charlie-work-mcp(and likewise--from git+…for the CLI).
Related MCP server: skillhub
Trustworthy detection (not regex theater)
Every scanner is backed by a parser or an authoritative data source, and every finding carries a confidence tier (verified / high / heuristic) so CI gates on facts, not guesses.
Kind | How it's detected |
| Lockfiles → OSV.dev (free, no key). Emits the CVE + the exact fixed version. |
| gitleaks-style provider regexes + Shannon-entropy gate + allowlists. |
| Python AST and tree-sitter (JS/TS/Go) — never matches a string or a comment. |
| AST calls: |
| Flags read but never set anywhere (the Pepe Silvia case), via AST literal extraction. |
| Real X.509 parsing — |
| Registry queries (PyPI/npm/crates/Go) → majors-behind. |
|
|
| Unpinned deps; operational scripts with no owner or CODEOWNERS. |
The difference from regex, in one line: the Python string "pytest.mark.skip" and a # breakpoint() comment are not flagged. Only real code is.
Where your team actually bleeds — hotspots + a toil budget
Charlie ranks by churn × complexity (CodeScene-style): debt in a file edited 40× this quarter outranks the same debt in one untouched for years. charlie-work summary rolls it into a toil budget — total remediation minutes, a SQALE-style debt ratio, and an A–E grade. Google SRE says keep toil under 50%.
Not just a reporter — a doer
Charlie returns patches, not prose. charlie_next hands the agent the single highest-value item — where it is, why it matters (hotspot × severity), and a ready-to-apply unified diff when it's safely fixable:
$ charlie-work next
breakpoint() left in the code at pay.py:88 — severity 4, in a hotspot (2.1x). [auto-safe]
--- a/pay.py
+++ b/pay.py
@@ -85,7 +85,6 @@
- breakpoint()Every patch is a diff you (or CI) apply with git apply — the server never edits your files. Fixes are labelled auto-safe (mechanical: delete a breakpoint()) or needs-review (changes behaviour: un-skip a test, delete a stale TODO). Secrets, certs, and dependency bumps are surfaced for a human, never auto-patched.
Tool | What it does |
| The single next best fix, as a patch + why + follow-up actions. |
| Unified-diff patches for a finding (or the top N), labelled auto-safe / needs-review. |
| Prioritized, paginated toil queue (structured output). |
| Toil budget: score, debt ratio, A–E grade. |
| Top-N action plan for an agent to work through. |
| Why a finding is debt — evidence, hotspot, owner, fix. |
| Records a snapshot and reports the delta over time. |
| The credit ledger — who cleared what, Champion of the Grease Trap. |
Plus toil://queue + toil://item/{id} resources and four prompts (slash commands in any client): triage_toil, fix_next, pre_pr_check, charlie_rules. Things a dashboard can't do: "fix the next thing, run the tests, and credit me in the ledger."
Not a toy: token discipline + evals
The heavy work happens server-side. An agent finding this toil itself would read the whole repo into context; Charlie returns only a compact ranked queue. The raw files never enter the model's context.
A reproducible eval harness (
evals/run.py) plants known toil and asserts the end state — recall and ranking — plus a token-cost measurement. There's also an optional model-graded tool-selection eval (evals/agentic.py).
$ uv run evals/run.py
kinds recalled : 9/9 (100% recall) top item is the cert : True
naive: read whole repo : 1881 tokens
charlie work queue : 1353 tokens → 28% fewer tokens
RESULT: PASSThat 28% is on a tiny fixture; the gap widens fast — naive cost grows with the repo, the queue stays bounded to one page.
Configuration & suppression
Zero-config to start. Tune via [tool.charlie] in pyproject.toml (or charlie.toml):
[tool.charlie]
exclude = ["vendor/**"]
disable = ["charlie/todo-rot"]
min_confidence = "high"
[tool.charlie.per-file-ignores]
"tests/**" = ["secret_leak"]Plus inline # charlie: ignore[rule], a .charlieignore, and a committed baseline (charlie-work baseline) so a fresh install starts at "0 new."
Development
uv sync --extra dev
uv run ruff check . && uv run mypy && uv run pytest -q
uv run python evals/run.pyCI runs ruff + mypy(typed) + pytest + evals across Python 3.11–3.13. Releases publish to PyPI via OIDC Trusted Publishing.
The gang (roadmap)
Each ships as its own standalone MCP server: The Implication (auth & dark-pattern auditor), Pepe Silvia (dead-code tracer), The D.E.N.N.I.S. System (rollout comms planner).
License
Code: MIT. The hero image is a still from It's Always Sunny in Philadelphia (© FX Networks), used for identification and commentary; it is not covered by the MIT license. An original vector rendition ships at assets/hero.svg.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-qualityBmaintenanceEnables AI agents to scan codebases for prioritized findings (TODO, FIXME, XXX) and retrieve results in table, JSON, or SARIF format via MCP.Last updated
- Flicense-qualityBmaintenanceEnables AI agents to scan codebases for TODO/FIXME/XXX patterns and get prioritized results over MCP, supporting CI gates and multiple output formats.Last updated
- Alicense-qualityDmaintenanceScans codebases for TODOs, FIXMEs, code complexity, file stats, and dependencies, generating a health report with a letter grade. Zero configuration required.Last updated16MIT
- Alicense-qualityCmaintenanceScans codebases for TODO comments and exposes them as structured data to LLMs, enabling AI assistants to inspect, prioritize, and propose fixes.Last updated7ISC
Related MCP Connectors
Screens public GitHub repos and PRs to generate risk maps, findings, and merge-readiness signals.
Generate AGENTS.md, AP2 compliance docs, checkout rules, debug playbook & MCP configs from any repo.
Scan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Falcon305/charlie-work-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server