Codacy MCP Server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Codacy MCP Serverrun a security audit on my repository"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Codacy MCP Server โ Vurb.ts Edition
The official Codacy MCP Server reimagined with the Vurb.ts framework โ structured perception for AI agents.
11 Tools - 44 actions available on-demand
Related MCP server: Akash MCP Server
3 Prompts MCP prompts โ code-review, security-audit, repo-health
๐ค Zero lines of human code.
An AI agent (Antigravity, Opus 4.6) read a framework's llms.txt and a 488-line skill file. That's all it knew about Vurb.ts.
From that, it built a complete production codebase from scratch:
11 tools ยท 44 actions ยท 12 models ยท 11 presenters ยท 3 prompts ยท 105 tests
No human wrote a single line.
The thesis of Vurb.ts: if an AI agent can learn a framework from its llms.txt and produce production-grade code on the first attempt โ the framework is doing its job.
๐ Designed for agents, not for humans.
Traditional frameworks optimize for human ergonomics โ tutorials, documentation, months of learning curve. Vurb.ts inverts this entirely. Its fluent API, llms.txt, and skill system were designed so that an AI agent can become productive in a single context window. The learning curve isn't short โ it's zero. The agent reads the spec, understands the patterns, and ships. This codebase is the proof.
Why Vurb.ts?
The original Codacy MCP Server is a solid, production-grade implementation. This edition rebuilds it using the Vurb.ts MVA (Model ยท View ยท Agent) pattern โ a framework designed specifically for MCP servers that gives AI agents structured, high-fidelity perception instead of raw JSON dumps.
Key advantages of the Vurb.ts approach:
๐ง Structured Perception โ Presenters transform raw API data into optimized, LLM-readable formats with semantic annotations, HATEOAS navigation links, and severity-based suggestions
๐ก๏ธ Guardrails โ Middleware (
requireAuth), egress limits, idempotent mutation markers, and DLP redaction (secrets are stripped before reaching the wire)๐ Prompt Templates โ First-class support for MCP prompts (
code-review,security-audit,repo-health) with dynamic argument injection๐ State Sync โ Declarative cache invalidation policies ensure mutations automatically refresh dependent queries
๐งฉ Fluent API โ Each tool action is defined as a composable, type-safe chain โ no manual JSON schemas or handler wiring
๐ฆ Zero Code Generation โ No auto-generated OpenAPI client; a lightweight typed HTTP client is all that's needed
๐๏ธ Grouped Exposition โ 44 actions exposed as 11 namespace tools, avoiding context window explosion
Capability Matrix
Capability | Original | Vurb.ts |
Security & DLP | ||
Auth middleware with self-healing errors | โ | โ |
Secret redaction before wire (DLP) | โ | โ |
Egress size limits per action | โ | โ |
Safe process execution ( | โ | โ |
Determinism & Guardrails | ||
Typed input schemas (Zod) | โ | โ |
Idempotent mutation markers | โ | โ |
Declarative cache invalidation | โ | โ |
| โ | โ |
Tool-redirection hints (cross-agent navigation) | โ | โ |
LLM Optimization | ||
Grouped tool exposition (โ78% context tokens) | โ | โ |
HATEOAS navigation links in responses | โ | โ |
Severity-aware action suggestions | โ | โ |
Presenter-formatted tables (vs raw JSON) | โ | โ |
MCP Protocol | ||
| โ | โ |
| โ | โ |
| โ | โ |
State sync / cache control headers | โ | โ |
Developer Experience | ||
Auto-discovery (zero manual imports) | โ | โ |
Fluent builder API | โ | โ |
Test suite (105 tests) | โ | โ |
Hot-reload dev server | โ | โ |
Grouped Tool Exposition โ Solving Context Explosion
This is the single most important architectural difference between the two implementations.
The Problem
The original server registers 24 flat tools in the MCP tools/list response. Every one of them โ with its full name, description, and JSON Schema โ is injected into the LLM's system prompt at the start of every conversation. This means the model must process ~4,000 tokens of tool definitions before the user even types a word.
At 44 actions, a flat approach would be even worse โ ~7,000+ tokens consumed permanently just by tool schemas, leaving less room for actual conversation and reasoning.
The Solution: toolExposition: 'grouped'
Vurb.ts introduces grouped tool exposition. Instead of exposing 44 individual tools, the MCP server advertises only 11 namespace routers:
Original (flat) Vurb.ts (grouped)
โโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโ
codacy_list_organizations codacy_organizations โ 2 actions
codacy_list_organization_repos codacy_repositories โ 3 actions
codacy_list_repository_issues codacy_issues โ 7 actions
codacy_search_org_srm_items codacy_security โ 6 actions
codacy_search_repo_srm_items codacy_tools โ 6 actions
codacy_list_files codacy_files โ 4 actions
codacy_get_file_issues codacy_pull_requests โ 6 actions
codacy_get_file_coverage codacy_commits โ 3 actions
codacy_get_file_clones codacy_overview โ 2 actions
codacy_get_file_with_analysis codacy_quality โ 3 actions
codacy_list_repository_pull_reqs codacy_cli โ 2 actions
codacy_get_repository_pull_req โโโโโโโโโโโโโโโโโโโโโโ
codacy_list_pull_request_issues 11 tools in system prompt
44 actions available on-demand
codacy_get_pr_files_coverage
codacy_get_pr_git_diff
codacy_get_repository_analysis
codacy_list_tools
codacy_list_repo_tools
codacy_get_pattern
codacy_list_repo_tool_patterns
codacy_get_issue
codacy_setup_repository
codacy_cli_analyze
codacy_cli_install
โโโโโโโโโโโโโโโโโโโโโ
24 tools in system promptHow the LLM Navigates
The model interacts with the 11 namespace tools using an action parameter. It works like a progressive disclosure pattern:
Step 1 โ Discovery. The LLM sees 11 high-level tools with concise descriptions. Each tool's schema has an action enum listing available actions:
codacy_security โ actions: [search_org, search_repo, dashboard, sbom_search, ossf_scorecard, ignore]Step 2 โ Selection. When the user asks "show me security vulnerabilities in my repo", the LLM picks codacy_security with action: "search_repo". The remaining 43 action schemas are never loaded into context.
Step 3 โ Navigation. Presenters include HATEOAS-style links in their response, guiding the LLM to the next logical tool:
๐ Next steps: codacy_issues.list (for code quality) ยท codacy_security.dashboard (for summary)Context Window Impact
Metric | Original (flat) | Vurb.ts (grouped) |
Tools in | 24 | 11 |
Actions available | 24 | 44 (+83%) |
JSON Schema surface (tool definitions) | 29,316 chars across 718 lines | Derived from fluent chain โ no hand-written schemas |
Fewer tools in the system prompt means the LLM spends less context budget on tool schemas and more on actual reasoning โ a critical advantage for models with limited context windows.
Developer Experience โ Side by Side
The same security search tool in both implementations:
// tools/searchSecurityItemsTool.ts (124 lines)
export const searchRepositorySecurityItemsTool = {
name: toolNames.CODACY_LIST_REPOSITORY_SRM_ITEMS,
description: `Tool to list security...
\n ${rules}
\n ${generalRepositoryMistakes}`,
inputSchema: {
type: 'object',
properties: {
...repositorySchema,
...getPaginationWithSorting('...'),
options: {
type: 'object',
properties: {
priorities: {
type: 'array',
items: { type: 'string',
enum: ['Low','Medium','High','Critical']
},
},
scanTypes: { /* ... 20 more lines */ },
categories: { /* ... 15 more lines */ },
statuses: { /* ... 8 more lines */ },
},
},
},
required: ['provider','organization','repository'],
},
};
// handlers/security.ts (35 lines)
export const handler = async (args: any) => {
const { provider, organization, repository,
cursor, limit, sort, direction, options
} = args;
return await SecurityService.searchSecurityItems(
provider, organization,
cursor, limit, sort, direction,
{ ...options, repositories: [repository] }
);
};
// index.ts โ manual tool registration
codacy_search_repository_srm_items: {
tool: Tools.searchRepositorySecurityItemsTool,
handler: Handlers.searchRepoSecurityItemsHandler,
},// codacy_security.tool.ts โ complete
export const searchRepo = security
.query('search_repo')
.describe('Search security findings within a repository.')
.instructions(`Repo-level security search.
Uses the organization-level API filtered by repo.
Scan types: SAST, SCA, Secrets, IaC, CICD.
DAST and PenTesting are org-level only.`)
.fromModel(CodacyScopeModel, 'repo')
.withOptionalEnum('priority', SEVERITY_LEVELS)
.withOptionalEnum('category', SECURITY_CATEGORIES)
.withOptionalEnum('scanType', REPO_SCAN_TYPES)
.withOptionalEnum('status', SECURITY_STATUSES)
.withOptionalNumber('cursor')
.withOptionalNumber('limit')
.egress(1 * 1024 * 1024)
.returns(SecurityPresenter)
.handle(async (input, ctx) => {
const body = { repositories: [input.repository] };
if (input.priority) body.priorities = [input.priority];
if (input.category) body.categories = [input.category];
return ctx.client.post(
`organizations/${input.provider}/${input.organization}/security/search`,
body,
{ cursor: input.cursor, limit: input.limit ?? 50 },
);
});What you don't write with Vurb.ts:
โ No JSON Schema objects โ input types derived from fluent chain
โ No handler wiring โ
autoDiscover()replaces manual registrationโ No OpenAPI codegen โ lightweight HTTP client replaces 3,000+ generated lines
โ No
anytypes โ full type inference from model to presenter
๐ What Reaches the LLM โ The Security Gap
The original server sends every API field directly to the LLM provider via JSON.stringify (index.ts:172). No filtering, no size limit, no redaction.
Here is what happens to each field from a Secrets detection scan:
API Field | โ Without Vurb.ts | โ With Vurb.ts | How |
|
|
| โ |
|
|
| Presenter |
| โ ๏ธ |
|
|
| โ ๏ธ | Gone โ never serialized | Schema stripping |
| โ ๏ธ | Gone โ never serialized | Schema stripping |
| โ ๏ธ | Gone โ never serialized | Schema stripping |
| โ ๏ธ Full internal API surface โ sent to LLM | Gone โ never serialized | Schema stripping |
247 findings | All 247 dumped (1,000+ lines) | Top results only |
|
Response size | Unbounded | Max 1 MB |
|
Next action | LLM must guess |
|
|
Architecture Comparison
Metrics (verified)
Every number below was measured directly from the source code.
Metric | Original | Vurb.ts | Diff |
Source files (hand-written) | 45 | 42 | โ3 |
Tool definitions ( | 718 lines | โ | โ |
Handlers ( | 424 lines | โ | โ |
Agents ( | โ | 763 lines | โ33% vs tools+handlers |
Tools in | 24 | 11 | โ54% |
Actions available to the LLM | 24 | 44 | +83% |
MCP Prompts | 0 | 3 | +3 |
Test cases | 0 | 105 | +105 |
Runtime dependencies | 6 | 4 | โ33% |
Dev dependencies | 9 | 3 | โ67% |
Tool Actions (44)
codacy_organizations (2)
Action | Description |
| List organizations the authenticated user belongs to |
| List repositories in an organization |
codacy_repositories (3)
Action | Description |
| Get repository details with analysis metrics |
| List branches of a repository |
| Add or follow a repository (multi-step orchestration) |
codacy_issues (7)
Action | Description |
| Search and filter code quality issues |
| Get detailed issue information |
| Get issues for a specific file |
| Get issues in a pull request |
| Download auto-fix patches |
| Mark an issue as ignored |
| Batch ignore multiple issues |
codacy_security (6)
Action | Description |
| Search org-level security findings |
| Search repo-specific security findings |
| Get security dashboard summary |
| Search SBOM dependencies |
| Get OSSF Scorecard for a package/repo |
| Ignore a security finding |
codacy_tools (6)
Action | Description |
| List all analysis tools available |
| List tools configured for a repository |
| Get a specific code pattern definition |
| List patterns for a tool in a repository |
| Enable/disable a tool for a repository |
| Enable/disable specific patterns |
codacy_files (4)
Action | Description |
| List files with analysis metrics |
| Get file details with metrics |
| Get line-by-line coverage |
| Get code duplication blocks |
codacy_pull_requests (6)
Action | Description |
| List PRs with analysis status |
| Get PR details with quality results |
| Get file-level PR coverage |
| Get the Git diff |
| Trigger AI-powered code review |
| Bypass the quality gate |
codacy_commits (3)
Action | Description |
| List commits with analysis status |
| Get commit details with delta statistics |
| Get issues introduced by a commit |
codacy_overview (2)
Action | Description |
| Aggregated issue overview with charts |
| Issue count breakdown by category |
codacy_quality (3)
Action | Description |
| Get quality gate thresholds for a repository |
| List gate policies for an organization |
| Get details of a specific gate policy |
codacy_cli (2)
Action | Description |
| Run local analysis via CLI |
| Install the CLI |
Setup
Requirements
Node.js โฅ 18
Configuration
Add to your MCP client configuration (Cursor, VS Code, Claude Desktop, etc.):
{
"mcpServers": {
"codacy": {
"command": "node",
"args": ["dist/server.js"],
"env": {
"CODACY_ACCOUNT_TOKEN": "<YOUR_TOKEN>"
}
}
}
}Development
npm install
npm run build # Compile TypeScript
npm run dev # Vurb dev server (hot-reload)
npm test # Run 105 tests
npm run inspect # MCP InspectorProject Structure
src/
โโโ agents/ # Tool definitions (Fluent API)
โ โโโ codacy_organizations.tool.ts
โ โโโ codacy_repositories.tool.ts
โ โโโ codacy_issues.tool.ts
โ โโโ codacy_security.tool.ts
โ โโโ codacy_tools.tool.ts
โ โโโ codacy_files.tool.ts
โ โโโ codacy_pull_requests.tool.ts
โ โโโ codacy_commits.tool.ts
โ โโโ codacy_overview.tool.ts
โ โโโ codacy_quality.tool.ts
โ โโโ codacy_cli.tool.ts
โโโ models/ # Zod schemas (data contracts)
โโโ views/ # Presenters (LLM-optimized output)
โโโ middleware/ # Auth, validation
โโโ prompts/ # MCP prompt templates
โโโ utils/ # Constants, rules, types
โโโ context.ts # API client + context factory
โโโ index.ts # Registry
โโโ server.ts # Entry pointUsage (MCP stdio)
This server runs as a stdio MCP transport โ the AI client launches it as a subprocess and communicates via stdin/stdout.
Cursor / Windsurf / Claude Desktop
Add to your MCP configuration file:
Cursor:
.cursor/mcp.jsonWindsurf:
.codeium/windsurf/mcp_config.jsonClaude Desktop:
claude_desktop_config.json
{
"mcpServers": {
"codacy": {
"command": "node",
"args": ["/absolute/path/to/codacy-vurb/dist/server.js"],
"env": {
"CODACY_ACCOUNT_TOKEN": "<YOUR_TOKEN>"
}
}
}
}VS Code (Copilot)
Add to your settings.json (Ctrl+Shift+P โ Preferences: Open User Settings (JSON)):
{
"mcp": {
"servers": {
"codacy": {
"command": "node",
"args": ["/absolute/path/to/codacy-vurb/dist/server.js"],
"env": {
"CODACY_ACCOUNT_TOKEN": "<YOUR_TOKEN>"
}
}
}
}
}Get your token
Generate an Account API Token
Paste it in the
CODACY_ACCOUNT_TOKENfield above
Build & run
npm install
npm run build
# The server starts automatically when the MCP client launches it via stdioLicense
Apache 2.0 โ see LICENSE.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceA TypeScript implementation of a Model Context Protocol server that provides a frictionless framework for developers to build and deploy AI tools and prompts, focusing on developer experience with zero boilerplate and automatic tool registration.2,50414MIT

Akash MCP Serverofficial
Alicense-qualityCmaintenanceA TypeScript server implementing the Model Context Protocol that enables AI agents to interact with the Akash Network, allowing them to deploy applications, create leases, manage deployments, and access other Akash services through typed tools.3512Apache 2.0
CodeAlive MCPofficial
Alicense-qualityAmaintenanceA Model Context Protocol server that enhances AI agents by providing deep semantic understanding of codebases, enabling more intelligent interactions through advanced code search and contextual awareness.86MIT- Flicense-qualityDmaintenanceA Model Context Protocol (MCP) server template designed for building structured tools, prompts, and resources with built-in support for HTTP and STDIO transports. It provides a standardized framework for developers to create and deploy AI-driven services using TypeScript and Zod schema validation.11
Related MCP Connectors
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yoโฆ
A Model Context Protocol server for Wix AI tools
A Model Context Protocol (MCP) application for automated GitHub PR analysis and issue management.โฆ
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/renatomarinho/codacy-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server