Containerized MCP server exposing Joern Code Property Graphs for program and vulnerability analysis.
CodeBadger presents a moderate-quality MCP server with explicit tool definitions, structured schemas, and detailed parameter documentation. All three tools have full JSON Schema input definitions with type constraints and descriptions. Descriptions are comprehensive and include return value structures. However, there are notable gaps: (1) parameter descriptions sometimes embed examples that could be misused by LLMs; (2) error handling lacks actionable recovery guidance; (3) output schemas are documented in descriptive prose rather than formally in the tool definitions; (4) parameter relationships and dependencies are not clearly marked; (5) no evidence of permission gates or security scoping for sensitive operations like taint analysis. The tools follow a consistent verb_noun naming pattern (list_*, find_*) and accept multiple filter options, enabling composition. Pagination is implemented with limit/page parameters and total counts. Overall, the tools are well-named, parametrized, and capable, but descriptions could be more LLM-focused and error paths need stronger guidance.
Find potential OS command injection sinks (CWE-78). Identifies call sites where shell-execution functions receive a non-literal argument — the minimal syntactic signal that user-controlled data might reach a command interpreter. Works across C, C++, Python, Java, JavaScript, Go, PHP, and Ruby. Args: codebase_hash: Hash returned by generate_cpg. language: Narrow to a language's sink set (c, cpp, python, java, javascript, go, php, ruby). Auto-detected when omitted. filename: Optional filename to restrict results (substring match). max_results: Upper bound on returned call sites (default 50). Returns: Text report listing each sink call site with location and code snippet, followed by a suggested next step (find_taint_flows). Notes: - A non-literal argument is necessary but NOT sufficient to confirm injection. - Follow up with find_taint_flows(mode='auto', sink_patterns=[...]). - Literal-only calls (e.g., system("ls")) are excluded as safe. Examples: find_command_injection_sinks(codebase_hash="abc123") find_command_injection_sinks(codebase_hash="abc123", language="python") find_command_injection_sinks(codebase_hash="abc123", filename="handler.c")
List function/method calls in the codebase. Discover call relationships between functions. Args: codebase_hash: The codebase hash. caller_pattern: Regex for the calling method. callee_pattern: Regex for the called method. limit: Max results. page: Page number. Returns: { "success": true, "calls": [ {"caller": "main", "callee": "printf", "filename": "main.c", "lineNumber": 10} ], "total": 25000, "available": 1000, "returned": 100, "result_cap": 1000, "truncated": true, "page": 1, "page_size": 100, "total_pages": 10 } Notes: - Useful for finding where specific functions are used. Examples: list_calls(codebase_hash="abc", callee_pattern="strcpy") list_calls(codebase_hash="abc", caller_pattern="main")
Output schemas are documented in prose descriptions but not formally specified in tool definitions. LLMs cannot parse return structures from narrative text, they need explicit JSON Schema or a structured response format. This violates the 'Document the output schema' pattern and forces LLMs to guess field names and types.
Error handling lacks actionable recovery guidance. No tool documents what errors are possible, when they are retryable, or what the agent should do if a call fails. E.g., find_command_injection_sinks might fail if codebase_hash is invalid, but there is no documented error response or recovery path.
Descriptions embed example values (main, main.c, strcpy, malloc) that LLMs may reuse literally in subsequent calls, causing false positives or mismatches. Replace examples with formal constraints (regex pattern, enum) or remove them.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-21 | C | 66 | <=2025-11-25 | v2 |
| 2026-03-09 | C | 60 | - | v1 |
List methods/functions in the codebase. Discover all methods and functions defined in the analyzed code. Args: codebase_hash: The codebase hash. name_pattern: Regex filter for method name. file_pattern: Regex filter for filename. callee_pattern: Regex filter for methods that call this specific function. include_external: Include external (library) methods (default False). limit: Max results. page: Page number. Returns: { "success": true, "methods": [{"name": "main", "filename": "main.c", ...}], "total": 1250, "available": 1000, "returned": 100, "result_cap": 1000, "truncated": true, "page": 1, "page_size": 100, "total_pages": 10 } Notes: - Use name_pattern to find specific methods. - Use callee_pattern to find usages (e.g., who calls 'malloc'). Examples: list_methods(codebase_hash="abc", name_pattern=".*auth.*") list_methods(codebase_hash="abc", callee_pattern="memcpy")
find_command_injection_sinks language parameter accepts 'c, cpp, python, java, javascript, go, php, ruby' as described text, not a formal enum. This invites hallucinated values (e.g., 'c#', 'rust', 'kotlin'). Formalize as an enum in the JSON Schema.
Pagination in list_methods and list_calls returns truncated, page, page_size, total_pages in the response, but these are only documented in prose examples, not in the schema definition. LLMs cannot extract or reason about pagination metadata without formal output schema.
No evidence of permission gates or scope declarations for tools that analyze code for vulnerabilities (find_command_injection_sinks) or taint flows. These are sensitive operations that could expose secrets or generate false positives used in security decisions. Missing the scope-declaration and permission-gate patterns.
Parameter dependencies are undocumented. For example, find_command_injection_sinks suggests calling find_taint_flows(mode='auto', sink_patterns=[...]) in the Notes section, but the relationship between these tools and the required parameter formats are not formally declared. LLMs may misuse or misconfigure the downstream call.