Code Guardian
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| audit_codebaseB | Full audit of a codebase against industry standards: linting, TypeScript, testing, CI/CD, docs, dependencies. Includes actionable guidance. |
| check_branchB | Check that the current git branch follows conventional naming (feature/, bugfix/, hotfix/, release/, main, master, develop). |
| check_testsA | Discover test files, detect test framework, and run a quick test execution check. |
| check_cicdB | Detect CI/CD configuration files (GitHub Actions, GitLab CI, Jenkins, CircleCI, Docker, pre-commit). |
| check_lintingA | Detect installed linters (ESLint, Prettier, Biome, oxlint, stylelint) and run ESLint if available. |
| check_securityB | Scan for security concerns: .env files at root, dependency vulnerabilities via npm audit. |
| check_architectureC | Review directory structure, monorepo indicators, and architectural conventions. |
| production_readinessA | Compute a production-readiness scorecard (A–F grade) across 10 dimensions: package.json, lock file, README, .gitignore, ESLint, TypeScript strict mode, tests, CI/CD, .env safety, build script. Includes remediation guidance per item. |
| generate_production_codeB | Generate production-ready code templates with industry-standard patterns. Supports: api, auth, database, testing, error_handling, logging, security, ci_cd, docker, branch_strategy. Specify stack (nestjs, express, fastify) and feature type. |
| get_industry_patternsA | Get full industry-standard patterns and checklists for any architectural concern: api, auth, database, testing, error_handling, logging, security, ci_cd, docker, branch_strategy. |
| generate_security_checklistB | Generate a security checklist based on current project findings + OWASP Top 10 standards. Detects stack and tailors recommendations. |
| generate_github_workflowB | Generate a production-ready GitHub Actions CI/CD workflow YAML. Supports custom name, stack, and deploy target (docker, k8s, vercel, aws). |
| detect_agentB | Detect which AI coding agent is in use (Claude Code, Cursor, Windsurf, Devin, Codex, Gemini, Antigravity) by scanning for agent-specific config files (.cursorrules, .windsurfrules, CLAUDE.md, AGENTS.md). Returns detected agents and all supported agents with best practices. |
| get_agent_guidanceC | Get agent-specific best practices and configuration guidance. Supported agents: claude-code, cursor, windsurf, devin, codex, gemini, antigravity. |
| generate_starter_repoB | Generate a complete starter project structure with production-ready defaults: directory layout, essential packages, eslint/prettier/tsconfig/jest configs. Supports nestjs, express, fastify frameworks. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 15 tools
The check_* family (tests, linting, security, architecture, CI/CD, branch) is well-separated by suffix, but audit_codebase and production_readiness heavily overlap as both assess overall codebase health. generate_starter_repo and generate_production_code also blur boundaries (full scaffold vs. feature templates), though descriptions partially clarify the distinction.
Most tools follow a clear verb_noun snake_case convention (check_tests, generate_starter_repo, audit_codebase, detect_agent). The single outlier is production_readiness, which is a noun phrase rather than a verb action, and the mix of check_/generate_/get_ verbs is still predictable. Overall the pattern is consistent with one minor deviation.
At 15 tools, the server sits at the upper boundary of a well-scoped set and is reasonable for a code-quality/readiness domain. A few tools feel tangential (detect_agent, get_agent_guidance) and add bulk without directly serving code auditing, but the count is not excessive.
The surface covers detection (checks), broad assessment (audit, scorecard), generation (starter repo, code templates, workflows, checklists), and reference guidance (industry patterns, agent practices). Notable gaps include a remediation/fix tool and test coverage analysis, but core workflows such as audit, generate, and recommend are well represented.