Security-hardened, token-efficient MCP server for code exploration via tree-sitter AST parsing
codesight-mcp has 13 tools with clear naming (all verb-noun style) and generally good descriptions. However, schema completeness is inconsistent: while all tools have input schemas with types, parameter descriptions are often sparse or missing, and output schemas are entirely undocumented. Error handling is present but generic. The server shows security-hardened design (warnings in descriptions, sanitization) but falls short of production-grade definition quality. Most tools would be rated 55-65 individually due to missing parameter documentation and absent output schema specifications.
Check source file licenses and generate compliance report
Delete an indexed repository from local storage
Generate Software Bill of Materials for an indexed repository
Get file changes between repository versions or commits
Get file content from an indexed repository
Get detailed information about specific symbols by ID
Get server usage statistics and tool call metrics
Index a local folder containing source code. Walks, parses, summarizes, and saves an index to storage.
Output schemas are entirely undocumented. LLMs have no visibility into what fields tools return, preventing proper chaining and forcing blind consumption of responses.
Parameter descriptions are sparse across most tools. For example, 'lint_index' has 'repo_path' described as 'Host filesystem path of the repo working folder' but lacks context on format, required structure, or resolution rules. 'get_symbols' has 'symbol_ids' with minimal guidance on ID format.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 56 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 35 | - | v1 |
Index a GitHub repository's source code. Fetches files, parses ASTs, extracts symbols, and saves to local storage. Full file content (including function bodies) is stored locally at ~/.code-index/; secrets embedded in function bodies are redacted from API output but stored at rest.
Deep structural integrity audit. Finds orphaned symbols/content, duplicates, call graph broken references, and file hash corruption.
List all indexed repositories in local storage
Search symbols in an indexed repository by name, kind, or file pattern
Trace taint flow through code symbols for security analysis
Several tools with optional parameters lack guidance on parameter interdependencies or mutual exclusivity. For example, 'search_symbols' has optional 'kind' and 'file_pattern' filters but does not document how they combine or if one is preferred over another.
No pagination guidance documented. Tools like 'search_symbols' accept 'max_results' (default 20) but do not document how to retrieve additional results or whether total counts are returned.
Error handling responses are generic. The source code shows 'sanitize_error()' and reference to 'ADV-*' hardening notes, but no tool-specific recovery guidance is documented. LLMs cannot determine if errors are retryable, user-fixable, or fatal.
The 'confirm' parameter in 'delete_index' defaults to false, which creates risk of accidental deletion if the LLM omits the parameter. Tool description warns to only call on explicit user request, but a safer default would be true or the parameter should be required.