code-audit-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CODE_AUDIT_UV | No | Alternative path to the uv binary. By default resolved from PATH. | |
| CODE_AUDIT_BUN | No | Alternative path to the bun binary. By default resolved from PATH. | |
| CODE_AUDIT_NPM | No | Alternative path to the npm binary. By default resolved from PATH. | |
| CODE_AUDIT_NPX | No | Alternative path to the npx binary. By default resolved from PATH. | |
| CODE_AUDIT_PHP | No | Alternative path to the PHP binary. By default resolved from PATH. | |
| CODE_AUDIT_UVX | No | Alternative path to the uvx binary. By default resolved from PATH. | |
| CODE_AUDIT_DART | No | Alternative path to the dart binary. By default resolved from PATH. | |
| CODE_AUDIT_JOBS | No | Number of simultaneous heavy processes. | 3 |
| CODE_AUDIT_CACHE | No | Cache directory for PHP tools, PHPStan and gitleaks. | ~/.cache/code-audit-mcp |
| CODE_AUDIT_FLUTTER | No | Alternative path to the flutter binary. By default resolved from PATH. | |
| CODE_AUDIT_TIMEOUT | No | Maximum seconds per tool. | 900 |
| CODE_AUDIT_COMPOSER | No | Alternative path to the Composer binary. By default resolved from PATH. | |
| CODE_AUDIT_GITLEAKS | No | Alternative path to the gitleaks binary. By default resolved from PATH or downloaded to the cache. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| auditA | Summary of all checks (dead code, dependencies, security, CVEs, complexity, lint) per stack, with totals by severity and the top 5 findings of each engine. Downloads tools on first run. Args: path: project folder (defaults to the working directory). |
| checkA | Findings of one check, sorted by severity and paginated per engine. Args: name: check to list. path: project folder (defaults to the working directory). severity: minimum severity to include. file: only paths matching this glob or prefix (e.g. "app/Http/**"). offset: findings to skip per engine (pagination). limit: maximum findings per engine. false_positives: include those flagged as likely false positives. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 2 tools
audit and check are distinct: audit gives a summary across all checks, while check drills into a specific check with filters. The descriptions make the boundary clear, though both deal with findings and could momentarily confuse a new agent.
Both tools use single, lowercase verbs (audit, check), which is consistent, but they don't follow the common verb_noun pattern. No mixing of conventions, so readability is high.
Two tools is slightly under the typical 3-15 range, but they are well-scoped: audit provides the overview and check handles per-check details via a parameterized interface. Each earns its place, though the surface feels minimal.
Core read functionality is covered: summary and detailed findings with pagination/filtering. However, there is no way to list available check names, manage false positives, or run individual checks directly, which are notable gaps for a code audit workflow.