Dependency graph + 24 MCP tools for AI coding assistants. Impact analysis, health scoring, security scanner, agent coordination.
Depwire presents a comprehensive set of 23 code-analysis tools with generally well-structured schemas and descriptions. Most tools have clear, action-oriented names (get_*, search_*, analyze_*, etc.) and descriptions in the 100-300 character range, meeting the 10-1024 baseline. However, there are notable gaps: (1) parameter descriptions are often minimal or missing depth, many parameters lack concrete format guidance (e.g., what constitutes a valid 'symbol' format?); (2) output schemas are documented in descriptions but not formally specified in the JSON schema, LLMs cannot infer return structure; (3) error handling guidance is absent, tools do not explain what to do if a symbol is not found or a graph is empty; (4) some parameters are overly generic or lack constraints (e.g., 'query' in search_symbols accepts unbounded strings with no length or character guidance). Tool design is solid for a specialized domain (dependency analysis), but polish is uneven. Schema completeness, output documentation, and error recovery patterns are the primary weaknesses.
Find unused symbols, dead code branches, and unreachable functions. Returns symbols with confidence scores (high/medium/low). Useful before refactoring to identify what's safe to remove.
Analyze how the codebase has evolved over time. Samples commits to show: file churn, complexity growth, dead code emergence, and stability metrics. Helps identify architectural drift and hotspots.
Calculate a health score (0-100) for the codebase based on: coupling metrics, cyclomatic complexity, dead code ratio, test coverage, commit activity, and refactoring health. Returns detailed breakdown and improvement suggestions.
Claim ownership of files for multi-agent coordination. Mark files as reserved to prevent concurrent modifications by other agents. Useful in multi-agent refactoring workflows.
Connect Depwire to a codebase for analysis. Accepts a local directory path or a GitHub repository URL. If a GitHub URL is provided, the repo will be cloned automatically. This replaces the currently loaded project.
Get the current set of file claims across all agents. Shows which files are reserved and by which agent. Useful for coordination and conflict detection.
Output schemas not formally specified in JSON Schema. Descriptions document return types informally, but LLMs cannot parse expected field structure from the input schema alone. E.g., impact_analysis says 'Shows direct dependents, transitive dependents...' but does not declare the structure of the response object or its fields.
Parameter descriptions lack concrete format guidance. 'symbol' parameters in get_symbol_info, get_dependencies, get_dependents say 'Symbol name... or fully qualified ID (e.g., ...)' but do not specify the delimiter, case sensitivity, or valid characters in symbol names or IDs. LLMs may pass invalid formats.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 62 | 2026-07-28+ | v2 |
Get a high-level overview of the project's architecture — file count, symbol count, most connected files, dependency hotspots, and orphan files.
Retrieve the project's architectural and refactoring decision log. Can filter by date range, decision type, or affected files.
Get all symbols that a given symbol depends on (what does this symbol use/import/call?). Pass a symbol name (e.g., 'Router') or a fully qualified ID (e.g., 'src/router.ts::Router') for exact matching. If multiple symbols share the same name, returns all matches for disambiguation.
Get all symbols that depend on a given symbol (what uses this symbol?). Pass a symbol name (e.g., 'Router') or a fully qualified ID (e.g., 'src/router.ts::Router') for exact matching. If multiple symbols share the same name, returns all matches for disambiguation.
Get complete context about a file — all symbols defined in it, all imports, all exports, and all files that import from it. Includes cross-language connections (REST API calls, subprocess invocations). Supports startLine/endLine for reading large files in chunks.
Retrieve auto-generated codebase documentation. Returns architecture overview, code conventions, dependency maps, and onboarding guides. Documentation must be generated first with `depwire docs` command.
Look up detailed information about a symbol (function, class, variable, type, etc.) by name. Pass a symbol name (e.g., 'Router') or a fully qualified ID (e.g., 'src/router.ts::Router') for exact matching. If multiple symbols share the same name, returns all matches for disambiguation.
Analyze what would break if a symbol is changed, renamed, or removed. Shows direct dependents, transitive dependents (chain reaction), and all affected files. Cross-language edges included — a TypeScript fetch call to a Python route will show the Python file as affected. Pass a symbol name (e.g., 'Router') or a fully qualified ID (e.g., 'src/router.ts::Router') for exact matching. If multiple symbols share the same name, returns all matches for disambiguation. Use this before making changes to understand the blast radius.
List all files in the project with basic stats.
Record architectural and refactoring decisions in the project's decision log. Decisions are timestamped and linked to affected files and symbols. Useful for post-hoc analysis and decision tracking.
Release ownership of files previously claimed with claim_files. Marks files as available for other agents to claim.
Scan the codebase for common security vulnerabilities: SQL injection, unsafe deserialization, hardcoded secrets, insecure random, weak crypto, unsafe reflection, XSS/CSRF, directory traversal. Returns findings grouped by vulnerability class with confidence scores.
Search for symbols by name across the entire codebase. Supports partial matching.
Simulate the impact of a proposed refactoring: renaming symbols, moving files, removing dead code, splitting modules. Preview the effects on the dependency graph before executing the actual changes. Non-destructive — does not modify the codebase.
Regenerate codebase documentation with the latest changes. If docs don't exist, generates them for the first time. Use this after significant refactoring.
Verify that a proposed change doesn't introduce inconsistencies or unintended side effects. Checks: symbol references are still valid, imports resolve, no circular dependencies introduced, and all dependents are updated.
Render an interactive arc diagram visualization of the current codebase's cross-reference graph. Shows files as bars along the bottom and dependency arcs connecting them, colored by distance. The visualization appears inline in the conversation.
Missing error handling and recovery guidance. Tools do not document what happens when a symbol is not found, a repo is not loaded, a graph is empty, or Git is not initialized. Error responses should include actionable next steps (e.g., 'Symbol not found. Try search_symbols() first.').
search_symbols 'query' parameter is unconstrained. No minimum/maximum length, no character restrictions, no guidance on case sensitivity or partial-match semantics. LLMs may pass empty strings, extremely long strings, or special characters.
simulate_refactor 'actions' parameter is typed as array of generic objects with no schema for action structure. Description says 'renaming symbols, moving files, removing dead code, splitting modules' but does not document the required fields or format for each action type.
No pagination or result-limiting guidance for tools that may return large result sets. search_symbols accepts 'limit' but defaults to 20 with no documented maximum. get_architecture_summary, list_files, and get_decisions may return many items but do not specify caps or pagination patterns.
Tool composition assumes prior state. Many tools (get_symbol_info, get_dependencies, etc.) assume a repo is already loaded via connect_repo. No tool documents this prerequisite or provides clear error guidance if the project is not loaded.
claim_files and release_files lack atomicity guarantees or conflict-resolution guidance. If multiple agents claim the same file concurrently, behavior is undefined. Descriptions do not specify timeout, retry semantics, or conflict handling.
analyze_temporal_trends 'start_date' parameter says 'ISO 8601 format, optional' but does not specify timezone handling, what happens if start_date > end_date, or whether dates are inclusive/exclusive.