A Model Context Protocol (MCP) server providing powerful code tools: Grep (ripgrep), Glob, Read, Edit, Write, Git Status/Log/Diff/Show/Branch, filesystem helpers (list_dir, delete, remove, copy, move, tree), and Run.
Code Tools MCP has 17 tools with complete naming and explicit JSON schemas across the board, but suffers from inconsistent and often vague parameter descriptions. Tool descriptions themselves are moderately good (averaging ~130 chars), but parameter-level documentation is sparse, incomplete, or generic. Examples: 'grep' tool has 12 parameters but descriptions lack format constraints (e.g., 'pattern' just says 'The search pattern to look for' without mentioning regex syntax); 'run' tool accepts env as type 'object' with no guidance on key/value format or security warnings; 'edit' tool requires 'old_string' to be unique but this constraint is buried in the description rather than enforced/validated. No output schemas are documented anywhere, LLMs cannot predict what fields to extract from results. Error handling is invisible in the source provided, no evidence of recovery guidance, categorization, or actionable error messages. The schema definitions are syntactically present (all tools show input type structures), but lack depth: no enums where appropriate, no min/max for numeric params, no regex patterns for strings. Security: 'run' tool accepts arbitrary env vars and commands with no sanitization guidance visible. Overall, this is a functional but underdeveloped toolkit that prioritizes breadth (17 tools) over depth (parameter validation, error guidance, output documentation).
Copies files or directories.
Deletes a single file from the filesystem.
Performs exact string replacements in files. You must use your Read tool at least once before editing. The edit will FAIL if 'old_string' is not unique in the file. Use 'replace_all' to change every instance of 'old_string'.
Lists branches using 'git branch'. Toggle flags to list local, remote, or all branches. Use contains to filter for branches containing a commit and sort to order results.
Shows differences between revisions using 'git diff'. Compare the working tree, index, or specific revisions. Provide base/target revisions to diff between commits or branches.
Reads commit history using 'git log' with filters. Supports oneline output, limit (number of commits), grep pattern, since/until date expressions.
Output schemas completely undocumented. No tools include return type definitions, field names, or result structure guidance. LLMs cannot predict what to extract from results without experimenting.
Parameter descriptions are generic and lack format constraints. 'pattern' in grep lacks regex syntax hints; 'timeout_seconds' in run lacks min/max bounds; 'env' in run lacks key=value format guidance. LLMs cannot reliably construct valid inputs.
Destructive tools (delete, remove) have minimal descriptions and no error recovery guidance. No mention of confirmation steps, dry-run capability, or what happens on failure. Agents may destroy data without understanding consequences.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 33 | - | v1 |
Displays commit or object details using 'git show'. Specify a ref (commit, tag, etc.); defaults to HEAD when omitted. Optionally provide a single path to inspect that file within the selected ref.
Lists modified, staged, and untracked files using 'git status'.
Lists files matching a glob pattern in a directory.
Searches for patterns in files using ripgrep with support for case-insensitive search, context lines, output modes (files_with_matches, count, content), type filtering, glob patterns, multiline matching, and result limiting.
Lists directory contents with optional recursion, hidden file display, and result limiting.
Moves or renames files and directories with optional overwrite support.
Reads file contents with optional line range and formatting. Useful for examining code before editing.
Removes a file or directory. When recursive is true, removes directories and their contents.
Executes shell commands with support for working directory, timeout, stdin, and environment variables.
Displays a tree-structured view of directory contents with optional depth limit, hidden file filtering, and result limiting.
Writes content to a file, creating it if it doesn't exist or overwriting existing content.
'run' tool accepts arbitrary shell commands and environment variables with no sanitization guidance visible in source. Security implications (command injection, secret exposure via env vars) are not addressed in parameter descriptions.
No enums declared for parameters that accept fixed option sets. Examples: 'output_mode' in grep (should be enum: files_with_matches|count|content); 'format' in git_show (custom pretty format). Free-form strings invite hallucination.
No indication of which tools are idempotent vs. irreversible. 'read' is idempotent; 'delete' is not. LLMs cannot reason about retry safety without this classification.
Parameter relationships undocumented. 'edit' tool requires 'old_string' to be unique in file, but LLM has no guidance on how to verify uniqueness before calling. 'grep' has mutually-exclusive context params (context, context_before, context_after) but no documentation of this.
No error handling guidance visible in source. No indication of what errors are recoverable (e.g., 'file not found' vs. 'permission denied') or what the LLM should do next. Agents cannot self-correct.
git tools return full git output without structure or field extraction. LLM must parse freeform text (commit hashes, dates, messages) rather than receiving typed results. Risk of hallucination on date parsing (e.g., 'git log' timestamps).
No pagination support visible. 'list_dir', 'glob', 'tree' have 'limit' params but no cursor/offset or total_count fields in output. Large results risk context window overflow.