whats-inherited-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@whats-inherited-mcpWhat does this repo tell my agent to do?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
whats-inherited-mcp
You review the code you clone. Almost nobody reviews the part of it that talks to your agent. An MCP server that enumerates everything in a checkout addressed to an AI agent rather than to you: instruction files, hook commands wired to agent events, MCP servers the repo declares, and the skills and subagents it ships.
Why
git diff shows you code, and you read code. It also shows you three added lines in a CLAUDE.md, and you skim those, because they look like documentation. They are not documentation — they are instructions your model will follow.
The surface is bigger than most people picture. A directory you cloned can carry:
CLAUDE.md/AGENTS.md/.cursorrules— loaded into context and treated as instructions, including nested copies deep in the tree that only apply when the agent works in that subdirectoryhook commands in
.claude/settings.json— shell wired to fire on tool use, session start, or prompt submit.mcp.json— MCP servers the repo asks to add, often launched withnpx -y <package>, which means the code that runs is downloaded at start time and is not the code you reviewed.claude/skills,.claude/commands,.claude/agents— capabilities the repo hands the agent
Nothing collects that in one place. This does.
Run against a checkout of langfuse/langfuse at 7d2afa4 — an ordinary, reputable open-source repo, picked precisely because there is nothing wrong with it:
# Inherited agent surface
**12 item(s) in this checkout are addressed to an agent, not to you.**
| Surface | Count | Detail |
|-------------------------------|------:|--------------------------------------------------------------|
| Instruction files | 12 | ~41,848 est. tokens, 5,593 lines your agent is told to follow |
| Hook commands | 0 | configured to run on agent events |
| MCP servers declared | 0 | 0 fetch code from a registry at launch |
| Skills / commands / subagents | 33 extensions (196 files) | shipped under `.agents/`, available to the agent |
## Worth a look
- 11 instruction file(s) are **not at the repo root** — they apply when the agent
works in those subdirectories and are easy to miss in review.and instruction_files adds:
> Counted once, reachable under more than one name (symlinks):
> - `AGENTS.md` ← also `.agents/AGENTS.md`, `CLAUDE.md`Five and a half thousand lines of standing instruction, most of it in files you would never open, in a repo nobody has any reason to distrust. That is the point: the number is large even in the benign case, which is exactly why an unusual entry in it goes unnoticed.
Related MCP server: claude-init
Tools
Tool | What it answers |
| The headline: everything in this checkout addressed to an agent. Start here |
| Every |
| Hook commands the checkout wires to agent events, and whether the script each references is inside the repo, outside it, or missing |
| MCP servers the repo declares, which of them fetch code at launch, and filesystem paths they are granted outside the checkout |
| Skills, slash commands and subagents the repo ships |
Every tool takes an optional dir; it defaults to the working directory.
Install
Register with Claude Code (available in every session):
claude mcp add --scope user whats-inherited -- npx -y whats-inherited-mcpOr in any MCP client config:
{
"mcpServers": {
"whats-inherited": {
"command": "npx",
"args": ["-y", "whats-inherited-mcp"]
}
}
}git clone https://github.com/stcmain/whats-inherited-mcp.git
cd whats-inherited-mcp
npm install && npm run build
# then point your client at node /path/to/whats-inherited-mcp/dist/index.jsPublished as whats-inherited-mcp on npm and as
io.github.stcmain/whats-inherited-mcp in the MCP Registry.
No configuration. No environment variables.
What it counts, and what it refuses to guess
Inflating this in the alarming direction would be easy and would make the tool useless, so the accounting is deliberately conservative:
It does not detect malicious content. There is no heuristic scanner, no "suspicious phrase" regex, no risk score. Those produce confident false positives on ordinary repos and miss anything written with care. This server tells you where to look; you do the reading.
Files are counted once. A repo can expose one file under several names —
CLAUDE.md → AGENTS.md → .agents/AGENTS.mdis a real pattern in the wild. Entries are deduplicated by resolved real path and the aliases are listed, rather than counting the same content three times..claude/is not double-counted. A skill's ownCLAUDE.mdis reported as a skill, not also as a project instruction file."No path token identified" is not a safety claim. When a hook command has no filesystem path this server can confidently extract, it says so and stops. That is a stated gap in the analysis, not a verdict.
Import detection is conservative. Fenced code blocks are stripped first, and an unrooted
@tokenonly counts when it names a document — so@scope/pkgand@mentionsstay out of the number.
Honest limitations
It reports; it does not judge, and it does not fix. Nothing is edited, quarantined or scored. Every item it lists is normal in a legitimate repo.
Whether your client actually runs project hooks is your client's business. Clients differ, and they prompt differently and change between versions. This server reports what the files declare, not what your client will do with them.
Token counts are estimates (~4 chars/token). Treat them as a ranking and a rough scale, not as billing. Anthropic's tokenizer is not public, so nothing local can do better.
Claude Code layout is the model. Cursor, Windsurf, Cline and Copilot instruction files are recognised, but hook and MCP parsing follows the Claude Code schema.
Very large monorepos are truncated. The walk is depth- and entry-capped; when the cap is hit the output says so and marks the results partial rather than quietly under-reporting.
It never reads git history. It describes the working tree as it is on disk right now, not what a diff changed.
Symlinked directories are not followed (loop risk). Symlinked files are.
Design notes / threat model
This server's whole job is to look at content that may be hostile, so the design assumes it is.
It must not become the injection vector it reports on. The body of an instruction file is never returned — only metadata, paths and structured fields parsed out of known JSON config keys. Pasting a repo's
CLAUDE.mdinto your context to tell you the repo might contain something bad would be self-defeating.Repo-authored strings are fenced and labelled. Hook commands and MCP launch lines have to be shown to be useful. They are emitted inside inline code spans with backticks neutralised, pipes escaped and newlines flattened so a crafted string cannot break out of the span or out of a markdown table, and every block carries a standing note that the quoted text is data from the checkout, not instructions.
No child processes. No shell. No network. No writes. The only Node APIs used are
node:fsreads,node:pathandnode:os. There is nochild_processimport anywhere in the source, so nothing in a scanned repo can be executed by scanning it.diris the one model-controlled path, and it is bounded by construction: it is resolved, real-pathed and required to be an existing directory. Because file bodies are never emitted, pointing it somewhere sensitive discloses filenames and sizes, never contents — and it cannot write, execute or transmit anything.Environment variable values are never read — only names.
.mcp.jsonis a place people leave API keys in plaintext.Bounded work: depth cap, entry cap, file-size ceiling, and no symlinked-directory traversal.
Who makes this
Built by Shift The Culture — we run a one-person company on AI agents and ship the tooling we needed ourselves. This server is free and MIT-licensed, no strings.
It has two siblings, both also free and MIT:
whats-running-mcp — what is actually running on the box right now, instead of what an old transcript claims.
whats-loaded-mcp — what is eating your context window before you type: skill descriptions, memory files and their imports.
The rest of that tooling is paid:
Agent Fleet Ops Kit ($29) — the other failure modes of running three or four agents on one box: two sessions editing the same checkout, a dev server nobody owns (so the agent tests a different app than it edits), and MCP servers leaked from crashed sessions that hold ports and RAM for weeks.
Agent Reliability Kit ($29) — a Stop hook and two CLIs that block a turn when an agent claims "done" against a repo, URL, or build that was never actually checked.
The server above stays free and MIT either way — it has no upsell in it, no telemetry, and no dependency on the paid kits.
License
MIT © Zachary Pampu
This server cannot be installed
Maintenance
Related MCP Servers
- Alicense-qualityCmaintenanceEnables access to agent instruction files and prompts for AI development workflows. Provides tools to retrieve and list development rules, security checks, and common prompts from an agents library through MCP protocol.Last updated3Apache 2.0
- AlicenseAqualityAmaintenanceGenerates AI context files (CLAUDE.md, AGENTS.md, Cursor/Windsurf/Cline/Continue/Kilo Code/Trae rules, GEMINI.md, Copilot, Aider, Junie, Warp) for any repository. Runs as CLI or MCP server, 100% local.Last updated3341MIT
- AlicenseAqualityBmaintenanceEnables AI agents to autonomously navigate a codebase by listing directories, reading files, searching code, and running whitelisted commands.Last updated514ISC
- Alicense-qualityDmaintenanceAn MCP server that gives LLMs structured, read-only insight into local code repositories — directory tree, languages, dependencies, scripts, and config files.Last updatedMIT
Related MCP Connectors
Generate AGENTS.md, AP2 compliance docs, checkout rules, debug playbook & MCP configs from any repo.
Repo intel for AI coding agents: overview, PRs, contributors, hot files, CI, deps. Remote MCP.
Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/stcmain/whats-inherited-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server