better-code-review-graph
This server provides an MCP/CLI code-knowledge-graph toolkit for token-efficient code reviews, semantic search, impact analysis, and security scanning.
Graph lifecycle (
graph): build/update incremental or full graphs, get stats, compute embeddings, export to GraphML/JSON-LD/DOT/Cypher, import graphs, and summarize functions with LLMs.Query and analysis (
query): run relationship patterns (callers, callees, imports, children, tests, inheritors), keyword/semantic search, blast-radius impact analysis for changed files, find large functions, spot-check callsites, detect renamed symbols, and diff nodes between commits.Review context (
review): generate token-optimized code review context from git diffs (structural summaries, impacted nodes, source snippets, guidance) or delta reports showing refactor moves between two commits.Configuration and setup (
config): view server status, change runtime settings, clear embeddings cache, and manage model-cell credentials (local vs cloud) for embeddings and summaries.Security scanning (
security): run heuristic or Semgrep scans, generate JSON/SARIF reports, suppress findings, and list available rules.Help (
help): get full documentation for any tool topic, including recipes.Local-first design: works out of the box with no API keys (local ONNX embeddings), and also supports cloud embedding/summary providers (Cohere, OpenAI, Gemini, Jina, OpenRouter, Vertex).
Better Code Review Graph
Renamed (2026-09-13): repo is now
crg— CLI-first (crgcommand). PyPI package staysbetter-code-review-graph; MCP server is a secondary surface.
mcp-name: io.github.n24q02m/better-code-review-graph
Knowledge graph for token-efficient code reviews -- semantic search and call-graph resolution across your codebase.
Project | Tagline | Tag |
Peer AI agents chat in a shared folder — no human relay, no orchestrator, wor... | Tooling | |
Knowledge graph for token-efficient code reviews -- semantic search and call-... | MCP | |
2-way Google Drive sync with .driveignore filter — rclone engine, Windows tray | Tooling | |
IMAP/SMTP email for AI agents -- read, send, organize folders, and manage att... | MCP | |
Composite MCP server for Godot Engine -- 17 composite tools for AI-assisted g... | MCP | |
Markdown-first Notion for AI agents -- pages, databases, blocks, and comments... | MCP | |
Drop-in python-semantic-release fork with built-in release-safety guards (orp... | Tooling | |
Telegram for AI agents -- messages, chats, media, and contacts across both bo... | MCP | |
Google Workspace MCP server (Docs/Drive/Calendar/Gmail/Sheets/Slides/Tasks/Ch... | MCP | |
Claude Code plugin marketplace for the n24q02m MCP servers -- install web sea... | Marketplace | |
Image and video understanding + generation for AI agents -- across Gemini, Op... | MCP | |
Chrome Extension for bulk operations on Jules tasks via batchexecute API -- a... | Tooling | |
Shared foundation for building MCP servers -- Streamable HTTP transport, OAut... | MCP | |
Persistent AI memory with hybrid search and embedded sync. Open, free, unlimi... | MCP | |
Fast multi-model retrieval runtime for ONNX and GGUF embeddings, reranking, and model contracts | Library | |
Secrets without the server. | CLI | |
A self-distilling neuro-symbolic cascade that amortises LLM cost across knowl... | Tooling | |
Shared web infrastructure package for search, scraping, HTTP security, and st... | Library | |
Open-source MCP server for AI agents: web search, content extraction, and lib... | MCP |
An MCP server that parses your codebase with Tree-sitter, builds a structural graph of functions/classes/imports, and gives Claude (or any MCP client) precise context so it reads only what matters instead of the whole tree. Semantic search runs through the local ONNX model registry from fastretrieval by default (zero config, no API key), with an optional cloud embedding chain. Fork of code-review-graph with fixed multi-word search, qualified call resolution, dual-mode embeddings, output pagination, and production CI/CD.
v2.0 migration (BREAKING)
v2.0 adds temporal columns (valid_from_sha / valid_to_sha on every node + edge) and an opt-in security scanner. The schema migration is auto-applied on first GraphStore open, and a backup of the pre-2.0 DB is saved to <graph_db>.pre-2.0.bak so you can roll back. See BREAKING_CHANGES.md for the full schema-change list, behavior changes, environment requirements, and the downgrade procedure (CRG_DOWNGRADE_TO_1_X=1 uv run better-code-review-graph).
Related MCP server: TempoGraph
Table of contents
Install
For OMP and other local coding harnesses, the primary surface is the package CLI
plus the bundled skills/ workflows. The skills invoke the CLI directly and do
not require an MCP server mapping.
# Run without a persistent install (short `crg` script; PyPI package name stays
# better-code-review-graph, so `uvx` needs the explicit --from form)
uvx --python 3.13 --from better-code-review-graph crg graph build --full-rebuild \
--repo-root /path/to/repo
uvx --python 3.13 --from better-code-review-graph crg graph stats \
--repo-root /path/to/repo
# Or install the console scripts (installs both `crg` and the legacy long name)
pip install better-code-review-graph
crg query search --search-query "authentication" \
--repo-root /path/to/repoThe optional Semgrep engine for deeper security scans is a separate extra:
pip install 'better-code-review-graph[security]'MCP stdio remains a secondary protocol adapter for clients that require it:
{
"mcpServers": {
"better-code-review-graph": {
"command": "uvx",
"args": ["--python", "3.13", "better-code-review-graph"],
"env": { "MCP_TRANSPORT": "stdio" }
}
}
}Install matrix (stdio unless noted; the CLI-first usage above stays the primary surface):
Client | Install |
Claude Code (plugin) |
|
Claude Code (stdio) |
|
Codex | register stdio command |
Gemini CLI | add the |
Cursor / Windsurf | add the |
Any client (HTTP self-host) | point the client at |
Install with an AI agent -- paste this to your AI coding agent:
Install MCP server
better-code-review-graphfollowing the steps at https://raw.githubusercontent.com/n24q02m/claude-plugins/main/plugins/better-code-review-graph/setup-with-agent.md
Full CLI usage is in CLI. Optional per-client MCP setup is at mcp.n24q02m.com/servers/better-code-review-graph/setup/.
Local-first boundary
CRG is local-first for coding workflows:
CLI and bundled Skills are the primary surfaces for graph build/query, impact analysis, review context, security scans, and repository onboarding.
MCP stdio is the secondary protocol adapter over the same local domain services; it does not maintain a separate graph implementation.
Graph state stays in
<repo>/.better-code-review-graph/graph.dbunless an explicit multi-user/self-host configuration selects another data directory.PyPI, CI, security scanning, GitHub releases, and eligible stable MCP Registry publication remain active. Historical public OCI tags are retained, but new public Docker Hub/GHCR images are no longer published.
CRG has no hosted Cloudflare runtime in the target topology.
Smithery
The repo ships a smithery.yaml so the server can be built and
run through Smithery. It deploys over stdio and needs
no startup configuration -- the config schema is empty, and any optional cloud
embedding/summary keys are supplied at runtime through the server's own config
flow (see Configuration below). The launch command is the same
uvx invocation as a local install:
startCommand:
type: stdio
commandFunction: |-
(config) => ({ command: 'uvx', args: ['--python', '3.13', 'better-code-review-graph'] })Configuration
Everything works out of the box with zero configuration -- semantic search
uses the local ONNX registry from fastretrieval
(Qwen3-Embedding-0.6B is the current built-in reference entry, ~570 MB
downloaded on first graph embed). This reference entry is not a Qwen-only
boundary: any built-in registry ID or valid non-Qwen artifact manifest follows
the same resolver. All environment variables below are optional and only needed
for cloud embeddings, LLM summaries, or an explicit BYO local artifact.
Model selection
Embeddings select the first provider/model entry in EMBEDDING_MODELS; later
entries are retained as configuration but are not runtime fallbacks. Summaries
select the first SUMMARY_MODELS entry too, without runtime fallback. Providers
are inferred from model prefixes and use the matching <PROVIDER>_API_KEY.
Variable | Purpose | Empty (default) |
| Cloud embedding selection; the first entry is active | Local fastretrieval registry |
| Completion model selection for | Summaries disabled |
Cohere embed-v4.0 requests and stores 1024 dimensions; other backends retain
768-dimensional storage. CRG never slices, pads, or silently accepts a different
provider width. The embedding row's model and byte width must match before reuse.
Run graph(action="embed") after changing models or upgrading an old 768-wide
Cohere index. Searches reject incompatible widths before a provider call; graph
nodes are retained and re-embedding replaces only stale vectors.
Provider API keys
Cloud models need the provider key for the selected model prefix. Keys alone never select models: an empty embedding chain stays local, and an empty summary chain stays disabled. A configured cloud error does not fall back to local or another provider. Summarizers require a chat-completion model.
Model prefix | API key env var | Get a key |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| https://cloud.google.com/vertex-ai/generative-ai/docs/start/express-mode/overview |
Advanced
Variable | Purpose |
| Provider-compatible endpoint for cloud embedding, including CF AI Gateway (SSRF-guarded) |
| Provider-compatible base URL for the summarizer, including CF AI Gateway (SSRF-guarded) |
| Skip the local ONNX download; embedding is unavailable unless a cloud chain is configured |
| Built-in fastretrieval model ID, or a local directory containing |
| Fastretrieval |
| Required dimension for an external model ID without a manifest |
| ONNX file path inside a manifest-backed artifact directory |
| Explicit pooling for an external ID without a manifest: |
| Explicit L2 normalization for an external ID without a manifest |
| Override the per-user data directory (default |
| Deprecated singular vars, honored one release with a warning -- migrate to the |
When LOCAL_RERANK_MODEL is configured, semantic vector search retrieves a
bounded candidate pool of min(max(limit * 4, limit), 100) rows, applies the
existing kind, repo, and live-row filters, then reranks that pool and returns
at most limit rows. The response uses search_mode="semantic_reranked" and
adds rerank_score while preserving similarity_score. Blank keeps the
existing limit * 2 vector path and search_mode="semantic". Configured
reranker failures return an explicit error; CRG does not silently fall back to
vector or keyword results. Keyword searches, including as_of snapshots, do
not invoke the reranker.
Example -- cloud embeddings + summaries
{
"mcpServers": {
"better-code-review-graph": {
"command": "uvx",
"args": ["--python", "3.13", "better-code-review-graph"],
"env": {
"MCP_TRANSPORT": "stdio",
"EMBEDDING_MODELS": "cohere/embed-v4.0",
"SUMMARY_MODELS": "openrouter/minimax/minimax-m3:free",
"EMBEDDING_API_BASE": "https://gateway.ai.cloudflare.com/v1/<account>/<gateway>/cohere/v2/embed",
"LLM_API_BASE": "https://gateway.ai.cloudflare.com/v1/<account>/<gateway>/openrouter/v1",
"COHERE_API_KEY": "<cohere-key>",
"OPENROUTER_API_KEY": "<openrouter-key>"
}
}
}
}Cohere embedding is paid. Authorize a bounded budget before a live index/query; the Minimax-free completion choice does not make embeddings free. This example does not add a process-wide model override: missing subject credentials fail closed rather than inheriting the server environment.
CRG currently has no cloud rerank call: LOCAL_RERANK_MODEL is its only
reranking path. Setting RERANK_MODELS or RERANK_API_BASE does not enable one.
Tools
Six tools, each grouping related actions to keep the tool surface small.
graph -- Graph lifecycle
Actions: build | update | stats | embed | export | summarize
Action | Description |
| Full or incremental graph build. Set |
| Alias for |
| Graph size, languages, node/edge breakdown, embedding count. |
| Compute vector embeddings for semantic search. Dual-mode: local ONNX or cloud chain. |
| Export the graph as |
| LLM-generated one-paragraph docstrings for |
query -- Graph queries
Actions: query | search | impact | large_functions | spot_check | renamed_in_diff | diff
Action | Description |
| Predefined patterns: |
| Search code entities by name/keyword or semantic similarity. |
| Blast radius of changed files. Auto-detects from git diff. Paginated with |
| Find functions/classes exceeding a line-count threshold. |
| Random callsite snippets from the last |
| Symbols whose callsite line shifted versus a base ref. |
| Nodes added/removed/modified between two commit SHAs ( |
Most read actions accept as_of=<sha> for temporal (point-in-time) snapshots
and repo=<repo_id> to scope a federated multi-repo graph.
review -- Code review context
Actions: context (default) | delta
Token-optimized review context with structural summary, impacted nodes, source
snippets, and review guidance. context auto-detects changed files from the
git diff; delta (with from_sha/to_sha, optional show_line_shifts)
surfaces refactor moves between two commits.
config -- Server configuration and credential setup
Actions: status | set | cache_clear | setup_status | setup_start | setup_skip | setup_reset | setup_complete
Action | Description |
| Server info: version, graph path, node/edge counts, embedding backend, embeddings count. |
| Update a runtime setting ( |
| Remove all computed embeddings. |
| Show current credential state and which model cells have keys. |
| Explain where the host configures API keys (host-owned model cells). |
| Set local mode (local ONNX embedding, no cloud cells). |
| Reset state to local; host config re-resolves on next call. |
| Re-resolve credential state from host config. |
security -- Security scanning
Actions: scan | report | suppress | rule_list
Action | Description |
| Run a security scan ( |
| Re-emit cached findings as JSON ( |
| Suppress a finding by |
| List available rules for an engine. |
The semgrep engine requires the [security] extra and runs Semgrep's
p/auto registry pack plus a 3-rule curated overlay.
help -- Full documentation
Topics: graph | query | review | config | security | recipes
Returns complete documentation for each tool. Use when the compressed descriptions above are insufficient.
CLI
The package installs two console scripts: crg (primary) and
better-code-review-graph (legacy long name). Running either with no
arguments starts the MCP server over stdio; a leading positional argument
routes to a local CLI subcommand that calls the same domain services used by
the MCP adapter. Run them directly after pip install, or without a
persistent install via uvx --python 3.13 --from better-code-review-graph crg ....
# Start the MCP server over stdio (default -- no subcommand)
crg
# Build, inspect, and embed the local graph
crg graph build
crg graph stats
crg graph embed
# Query relationships and impact
crg query query \
--pattern callers_of --target "path/to/module.py::function"
crg query search --search-query "authentication"
crg query impact --changed-files src/app.py
# Produce review context and run a local security scan
crg review context --base HEAD~1
crg security scan --engine heuristicCommand | Description |
| Full or incremental graph build. |
| Compute vector embeddings using local ONNX or the configured cloud chain. |
| Inspect, export/import a portable |
| Run relationship patterns or keyword/semantic search. |
| Analyze changed-file blast radius or find oversized nodes. |
| Inspect callsites, line shifts, or commit-to-commit graph changes. |
| Generate review context or diff buckets for a code change. |
| Run and manage heuristic/Semgrep security findings. |
CLI subcommands print structured JSON and exit non-zero on an error.
Features
What this fork fixes versus the upstream code-review-graph:
Feature | code-review-graph | better-code-review-graph |
Multi-word search | Broken (literal substring) | AND-logic word splitting |
callers_of/callees_of | Empty results (bare name targets) | Qualified name resolution + bare fallback |
Embedding | sentence-transformers + torch (1.1 GB) | fastretrieval ONNX + cloud (200 MB), dual-mode |
Output size | Unbounded (500K+ chars) | Paginated (max_results, truncated flag) |
Tool design | 9 individual tools | 6 grouped tools: graph + query + review + config + security + help |
Plugin hooks | Invalid PostEdit/PostGit | Valid PostToolUse |
Comparison
How better-code-review-graph stacks up against direct competitors in each pillar:
Capability | better-code-review-graph | Greptile | Sourcegraph (Cody / MCP) | CodeGraph (colbymchenry) |
Codebase knowledge graph | Yes (Tree-sitter, 14 langs, SQLite) | Yes (functions/classes/deps) | Yes (precise code indexing) | Yes (Tree-sitter, 20+ langs, SQLite) |
Persistent incremental updates | Yes (git-diff + file-hash re-parse) | ? | Yes (continuous indexing) | Yes (OS file-watcher debounced) |
Qualified call resolution (callers/callees) | Yes (same-file bare-call resolution + fallback) | ? | Yes (go-to-def / find-references) | Yes (callers / callees / impact) |
Semantic search / embeddings | Yes (fastretrieval local registry + cloud Jina/Gemini/OpenAI/Cohere) | ? | Yes (semantic + keyword + regex) | No (FTS5 full-text only) |
Token-optimized review context | Yes ( | Yes (PR review comments) | No (code-context assistant) | No (context layer, not review) |
Security scanning | Yes (Semgrep | ? | ? | No |
Self-hostable | Yes (stdio default, machine-bound) | Yes (Docker / K8s / air-gapped) | Yes (self-hosted instance) | Yes (100% local, no API keys) |
Free / open source | Yes (Apache-2.0) | No (proprietary SaaS; free OSS tier) | No (Enterprise license, source private) | Yes (MIT) |
Sources: Greptile · Greptile pricing · Sourcegraph MCP · CodeGraph. Cells marked ? are capabilities the competitor does not publicly document, not confirmed absences.
Security
Explicit selection -- Cloud embedding errors are reported; the runtime does not silently switch models or fall back to local ONNX.
Error handling -- Tools return error strings with fix suggestions, never crash.
Read-only mount -- Docker mode mounts the repo as
:ro(read-only).SSRF-guarded endpoints -- Custom
EMBEDDING_API_BASE/LLM_API_BASEURLs are validated before any outbound call.
To report a vulnerability, see SECURITY.md.
Build from source
git clone https://github.com/n24q02m/crg
cd better-code-review-graph
uv sync --group dev
uv run pytest
uv run better-code-review-graphRequirements: Python 3.13, uv.
Trust model
This plugin implements TC-Local (machine-bound, single trust principal). See the mcp-core trust model for full classification.
Mode | Graph DB | Cloud credentials | Who can read your data? |
stdio (default) |
|
| Only your OS user |
HTTP self-host (multi-user) | Per-user | Per-user | Only the authenticated user |
Migration & changelog
Graph, security scan cache, and suppression state now use the package-owned
.better-code-review-graph/ directory. Run graph(action="build", full_rebuild=true)
once after upgrading, followed by graph(action="embed") if semantic search is
needed. The ambiguous old .code-review-graph/ and .code-review-graph.db paths
and their SQLite sidecars are left untouched: they may belong to the separate
upstream package. Review and reapply any desired suppression rules explicitly.
The v2.0 release added temporal columns (valid_from_sha / valid_to_sha
on every node and edge) plus an opt-in security scanner. The schema migration
is auto-applied on first GraphStore open, and a backup of the pre-2.0 DB is
written to <graph_db>.pre-2.0.bak. To downgrade and restore it:
CRG_DOWNGRADE_TO_1_X=1 uvx better-code-review-graphFull schema-change list, behavior changes, and rollback procedure: BREAKING_CHANGES.md. Release-by-release history: CHANGELOG.md.
Documentation
Full docs at mcp.n24q02m.com/servers/better-code-review-graph/setup/:
Setup -- install methods for Claude Code, Codex, Gemini CLI, Cursor, Windsurf, mcp.json
Modes overview -- stdio / local-relay / remote-relay / remote-oauth
Multi-user setup -- per-JWT-sub credential model
Use the help tool from any MCP client for inline per-tool reference.
License
Apache-2.0 -- See LICENSE.
Available Tools
6 toolsconfigConfigAIdempotent
Server configuration, status, and model-cell setup. Actions: status (show state), set (key, value -- keys: log_level), cache_clear (wipe embeddings), setup_status (state + configured model cells), setup_start (where the host configures keys), setup_skip (local mode), setup_reset (reset to local), setup_complete (re-resolve from host config). Use help tool for full docs.
| Name | Required | Description | Default |
|---|---|---|---|
| key | No | ||
| force | No | ||
| value | No | ||
| action | Yes | ||
| repo_root | No |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnlyHint=false, destructiveHint=false, idempotentHint=true, openWorldHint=true. The description adds behavioral context beyond annotations: cache_clear 'wipes embeddings' (destructive-ish), setup_skip 'local mode', setup_reset 'reset to local', setup_complete 're-resolve from host config'. This discloses state-changing behavior and setup flow. It doesn't contradict annotations; destructiveHint=false is consistent with cache_clear being a cache wipe rather than permanent data destruction. The description adds meaningful behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense but well-structured: a one-sentence overview followed by a parenthetical action list. It front-loads the purpose and packs a lot of information into a compact form. The action list is a bit long but necessary for a multi-action tool. It earns its place, though it could be slightly more scannable with line breaks.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (5 parameters, 8 actions, output schema present), the description covers the main actions and their effects. It doesn't explain 'force' or 'repo_root', and doesn't describe return values, but the output schema exists. The setup flow is described well enough for an agent to invoke actions. Minor gaps remain, but overall it's fairly complete for a config tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must compensate. It explains the 'action' parameter by listing valid actions and their meanings. It also explains 'key' (e.g., log_level) and 'value' in the set action. However, it doesn't explain 'force' or 'repo_root' parameters at all. With 5 parameters and 0% schema coverage, the description covers only some parameters, leaving gaps. Baseline 3 is appropriate because it adds some meaning but not complete coverage.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: server configuration, status, and model-cell setup. It enumerates specific actions (status, set, cache_clear, setup_status, setup_start, setup_skip, setup_reset, setup_complete), which distinguishes it from siblings like graph, query, review, and security. However, it doesn't explicitly name a sibling alternative, so it's clear but not fully differentiated.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit context for when to use this tool: for server configuration, status, and model-cell setup. It lists the actions and their purposes, which implies when to use each. It doesn't explicitly state when NOT to use it or name alternatives, but the action list gives clear usage guidance. The mention of 'Use help tool for full docs' is a minor pointer.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
graphGraphC
Build and manage the code knowledge graph. Actions: build (full_rebuild, base, repo_root), update (base, repo_root), stats (repo_root), embed (repo_root), export (format, output_path, repo_root), import (import_path, repo_root), summarize (max_nodes, repo_root). Use help tool for full docs.
| Name | Required | Description | Default |
|---|---|---|---|
| base | No | HEAD~1 | |
| roots | No | ||
| action | Yes | ||
| format | No | graphml | |
| max_nodes | No | ||
| repo_root | No | ||
| import_path | No | ||
| output_path | No | ||
| full_rebuild | No |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations indicate not read-only or destructive, but the description adds little behavioral detail. It implies the tool modifies state (build, update) but doesn't disclose side effects or prerequisites.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Description is dense but somewhat verbose. It lists actions and parameters inline, which is functional but not optimally structured. Could be more front-loaded.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With 9 parameters and only 1 required, and no schema descriptions, the description is insufficient. It covers action-to-parameter mapping but fails to explain parameter semantics and behavior. Output schema existence may help but is not referenced.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema has 0% coverage, so description must compensate. It connects actions to parameters (e.g., build requires full_rebuild, base, repo_root), adding meaning beyond bare names. However, still omits explanation for several parameters like roots and format.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool builds and manages a code knowledge graph, and lists specific actions. This distinguishes it from sibling tools like query or review.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use this tool vs alternatives. The description lists actions but does not provide context for selecting between them or other tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
helpHelpARead-onlyIdempotent
Get full documentation for any tool. Topics: graph | query | review | config | security | recipes. Use when compressed descriptions are insufficient.
| Name | Required | Description | Default |
|---|---|---|---|
| topic | No | graph |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, destructiveHint=false. Description adds that it returns 'full documentation', which is consistent and implies a safe, read-only operation. No contradictions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences: first states purpose, second gives usage guideline. No wasted words, front-loaded information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple doc lookup tool with one optional parameter and an output schema, the description adequately covers purpose, usage, and available topics. Output schema handles return value documentation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema has one parameter 'topic' with no enum, but description lists specific topics (graph, query, review, etc.), adding meaning beyond schema. Schema coverage is 0%, so description compensates well.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states verb 'Get full documentation' and resource 'any tool'. Lists specific topics (graph, query, etc.), which distinguishes it from sibling tools that are the tools themselves.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says 'Use when compressed descriptions are insufficient', providing clear guidance on when to invoke this tool. Also lists available topics for reference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
queryQueryBRead-onlyIdempotent
Query the code knowledge graph for relationships, search, and impact analysis. Actions: query (pattern, target), search (search_query), impact (changed_files|base), large_functions (min_lines), spot_check (n -- random callsite snippets from last callers_of/callees_of/inheritors_of/importers_of result), renamed_in_diff (base -- symbols whose callsite line shifted vs base ref), diff (from_sha, to_sha -- nodes added/removed/modified between two commit SHAs). Use help tool for full docs.
| Name | Required | Description | Default |
|---|---|---|---|
| n | No | ||
| base | No | HEAD~1 | |
| kind | No | ||
| repo | No | ||
| as_of | No | ||
| limit | No | ||
| action | Yes | ||
| target | No | ||
| to_sha | No | ||
| pattern | No | ||
| from_sha | No | ||
| languages | No | ||
| max_depth | No | ||
| min_lines | No | ||
| repo_root | No | ||
| max_results | No | ||
| search_query | No | ||
| changed_files | No | ||
| context_lines | No | ||
| file_path_pattern | No | ||
| max_payload_bytes | No |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, and the description aligns by presenting read-like actions (query, search, impact, diff). The description adds behavioral detail per action (e.g., 'spot_check returns random callsite snippets'), enhancing transparency beyond annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is information-dense, packing multiple actions and their arguments into a single paragraph without excessive verbosity. It is not structured with sections but remains focused. The mention of 'help' for full docs prevents over-expansion.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given 21 parameters and high complexity, the description provides a high-level overview of actions but lacks depth on many parameters. An output schema exists, which helps, but the description still leaves gaps regarding parameter usage and edge cases.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, so the description must explain parameters. It maps some parameters to actions (e.g., pattern, target for query), but many parameters (kind, repo, as_of, limit, languages, etc.) remain unexplained, limiting practical guidance.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool queries a 'code knowledge graph' and lists specific actions like query, search, impact, etc. It distinguishes itself from siblings like config or help by detailing unique functionalities, though it does not explicitly differentiate from the sibling 'graph' tool.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description lacks guidance on when to use this tool versus alternatives. It lists actions but does not specify when to use a particular action or when not to use the tool. The only direction is 'Use help tool for full docs,' which defers responsibility.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
reviewReviewARead-onlyIdempotent
Generate token-efficient review context for code changes. Actions: context (default — auto-detects changed files from git diff, returns structural summary, impacted nodes, source snippets, and review guidance), delta (from_sha, to_sha — wraps the query.diff buckets and, when show_line_shifts=true, surfaces qualified_names whose line_start moved between the two commits for refactor auditing). Context params: changed_files (auto), max_depth=2, include_source=true, max_lines_per_file=200, base='HEAD~1', repo_root (auto). Delta params: from_sha, to_sha, show_line_shifts=false, repo, repo_root. Use help tool for full docs.
| Name | Required | Description | Default |
|---|---|---|---|
| base | No | ``context`` action — git ref for change detection (default: ``HEAD~1``). | HEAD~1 |
| repo | No | Phase 2 Task 10 — when non-empty, scope to nodes whose ``repo_id`` matches (e.g. ``repo='repo_a-aaaaaaaa'``). Default ``""`` includes every federated repo. Both actions. | |
| action | No | ``context`` (default) or ``delta``. | context |
| to_sha | No | ``delta`` action — later commit SHA. Required. | |
| from_sha | No | ``delta`` action — earlier commit SHA. Required. | |
| languages | No | ``context`` action — optional list of language names (e.g. ``["python"]``) to scope the ``untested_functions`` list. Excludes functions whose language doesn't match. Fixes false positives on cross-language repos (D16, fixes #340). | |
| max_depth | No | ``context`` action — impact radius depth (default: 2). | |
| repo_root | No | Repository root path (auto-detected). Both actions. | |
| changed_files | No | ``context`` action — files to review (auto-detected from git if omitted). | |
| include_source | No | ``context`` action — include source code snippets (default: true). | |
| show_line_shifts | No | ``delta`` action — when True, include nodes whose ``line_start`` moved between ``from_sha`` and ``to_sha`` in the response (default False). | |
| max_lines_per_file | No | ``context`` action — max source lines per file (default: 200). |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, establishing safety. The description adds significant behavioral context: auto-detection of changed files, output structure (structural summary, impacted nodes, source snippets), and conditional behavior for 'show_line_shifts'. No contradictions with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is efficiently structured: starts with the primary purpose, then lists actions and their parameters. It avoids redundancy and front-loads the most important information. A minor density of technical details is acceptable.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given 12 parameters, 100% schema coverage, and an output schema, the description covers the tool's behavior well. It explains both actions, parameter defaults, and key behaviors. The slight reliance on the 'help' tool for 'full docs' indicates a minor gap, but overall it is sufficiently complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description adds value by grouping parameters under each action and providing examples (e.g., 'repo='repo_a-aaaaaaaa''), but it mostly reiterates schema descriptions. The grouping and context slightly elevate it from the baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool generates 'token-efficient review context for code changes' with two distinct actions: 'context' and 'delta'. It specifies verbs ('generate', 'auto-detects', 'returns') and the resource ('code review context'). While not explicitly distinguishing from siblings, the purpose is specific enough to make the tool's role clear against other tools like 'graph' or 'query'.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit guidance on when to use each action: 'context' for automatic git diff analysis and 'delta' for comparing two commits. It even details delta's 'show_line_shifts' option for refactor auditing. It lacks explicit 'when not to use' but offers clear context and refers to the 'help' tool for full documentation, which is reasonable.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
securitySecurityA
Security scanning over the code knowledge graph. Actions: scan (engine='heuristic'|'semgrep', repo_root), report (format='json'|'sarif', repo_root), suppress (rule_id, remove=false, repo_root), rule_list (engine='heuristic'|'semgrep'). Use help tool for full docs.
| Name | Required | Description | Default |
|---|---|---|---|
| action | No | scan | |
| engine | No | heuristic | |
| format | No | json | |
| remove | No | ||
| rule_id | No | ||
| repo_root | No |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations are sparse (no readOnlyHint, destructiveHint false) and provide little safety context. The description lists actions but does not disclose side effects, authorization needs, or limitations beyond scanning. No contradiction, but insufficient behavioral details.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences front-load the tool's purpose, followed by a compact enumeration of actions and parameters. No wasted words; every element adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With 6 parameters and 0% schema coverage, the description covers actions and key constraints but defers to the help tool for full docs. The output schema exists but is not referenced, leaving return values unexplained. Adequate but incomplete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, yet the description adds significant meaning by listing parameter values per action (e.g., engine='heuristic'|'semgrep', format='json'|'sarif'). This compensates for the schema's lack of description.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Security scanning over the code knowledge graph.' It enumerates four specific actions (scan, report, suppress, rule_list) with their parameters, differentiating it from sibling tools like config, graph, query, and review.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No explicit guidance on when to use this tool versus alternatives. The mention 'Use `help` tool for full docs' implies incomplete documentation but does not provide context for selection or exclusion.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v3.27.0- Removed
config__open_relay
TDQS
Scored across 6 tools
Each tool covers a distinct functional area: graph management, querying, review generation, security scanning, configuration, and documentation. The action lists within each tool reinforce these boundaries, so an agent can reliably select the right tool for the job.
All six tool names are single lowercase tokens (graph, help, config, query, review, security), following a consistent and predictable style. The naming convention is uniform and immediately understandable.
Six tools is a well-scoped set that covers the server's domain without bloat. Each tool consolidates a meaningful set of related actions, keeping the surface area manageable while still being powerful.
The toolset covers graph building/updating, querying, diff analysis, review context generation, and security scanning. Minor gaps exist, such as no direct tool for managing review comments or code ownership, but the core workflow of producing code-review intelligence is complete.
Maintenance
Related MCP Connectors
Codebase graphs, caller impact analysis, and recorded project context for AI coding agents.
Code intelligence for coding agents: semantic, AST, graph, and full-text search. 279+ languages.
Code intelligence platform for AI agents. 20 tools for architecture, security & impact analysis.
Give your AI agent a persistent map of your project's structure, dependencies, and bugs.
Related MCP Servers
- AlicenseAqualityAmaintenanceEnterprise-grade (40m+ lines) codebase intelligence in a zero-setup, private and local MCP: managed indexing, hybrid semantic search, polyglot code dependency graphs, and DB/API/infra knowledge. Benchmark: 61% less tokens, 84% fewer calls, 37x faster than standard AI grep.262,410 npm3,317AGPL 3.0
- AlicenseAqualityCmaintenanceCode graph context engine that parses codebases with tree-sitter (170+ languages), builds structural dependency graphs, and provides 24 MCP tools for code intelligence. One prepare_context call gives your AI agent the right files for any task. Includes focus, blast radius, hotspots, dead code detection, and hybrid search.241AGPL 3.0
- AlicenseAqualityCmaintenanceCross-repository code knowledge graph MCP server for Java, Kotlin, JavaScript, and TypeScript. Indexes source code into embedded KuzuDB via tree-sitter and exposes 30+ tools for call-flow tracing, multi-hop taint analysis (OWASP/CWE/PCI/STIG), entry-point reachability filtering, performance hotspot detection, and license compliance — without reading source files. 95% fewer tokens vs source-read331MIT

mcp-reposkeinofficial
AlicenseAqualityAmaintenanceDeterministic code-graph (GraphRAG) over your repo for LLM agents — local-first, git-native, zero-infra, served via MCP. Python, TS/JS, Rust, Go, Java, C#.812Apache 2.0