Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
CODE_AUDIT_UVNoAlternative path to the uv binary. By default resolved from PATH.
CODE_AUDIT_BUNNoAlternative path to the bun binary. By default resolved from PATH.
CODE_AUDIT_NPMNoAlternative path to the npm binary. By default resolved from PATH.
CODE_AUDIT_NPXNoAlternative path to the npx binary. By default resolved from PATH.
CODE_AUDIT_PHPNoAlternative path to the PHP binary. By default resolved from PATH.
CODE_AUDIT_UVXNoAlternative path to the uvx binary. By default resolved from PATH.
CODE_AUDIT_DARTNoAlternative path to the dart binary. By default resolved from PATH.
CODE_AUDIT_JOBSNoNumber of simultaneous heavy processes.3
CODE_AUDIT_CACHENoCache directory for PHP tools, PHPStan and gitleaks.~/.cache/code-audit-mcp
CODE_AUDIT_FLUTTERNoAlternative path to the flutter binary. By default resolved from PATH.
CODE_AUDIT_TIMEOUTNoMaximum seconds per tool.900
CODE_AUDIT_COMPOSERNoAlternative path to the Composer binary. By default resolved from PATH.
CODE_AUDIT_GITLEAKSNoAlternative path to the gitleaks binary. By default resolved from PATH or downloaded to the cache.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
auditA

Summary of all checks (dead code, dependencies, security, CVEs, complexity, lint) per stack, with totals by severity and the top 5 findings of each engine. Downloads tools on first run.

Args: path: project folder (defaults to the working directory).

checkA

Findings of one check, sorted by severity and paginated per engine.

Args: name: check to list. path: project folder (defaults to the working directory). severity: minimum severity to include. file: only paths matching this glob or prefix (e.g. "app/Http/**"). offset: findings to skip per engine (pagination). limit: maximum findings per engine. false_positives: include those flagged as likely false positives.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.7/5.0

Scored across 2 tools

Disambiguation4/5

audit and check are distinct: audit gives a summary across all checks, while check drills into a specific check with filters. The descriptions make the boundary clear, though both deal with findings and could momentarily confuse a new agent.

Naming Consistency4/5

Both tools use single, lowercase verbs (audit, check), which is consistent, but they don't follow the common verb_noun pattern. No mixing of conventions, so readability is high.

Tool Count4/5

Two tools is slightly under the typical 3-15 range, but they are well-scoped: audit provides the overview and check handles per-check details via a parameterized interface. Each earns its place, though the surface feels minimal.

Completeness3/5

Core read functionality is covered: summary and detailed findings with pagination/filtering. However, there is no way to list available check names, manage false positives, or run individual checks directly, which are notable gaps for a code audit workflow.

Maintenance

ActivityMaintained
ResponsivenessNo issues