Containerized MCP server exposing Joern Code Property Graphs for program and vulnerability analysis.
CodeBadger defines 5 tools with reasonable naming and partial documentation. Tool names follow verb-first patterns (list_methods, list_calls, find_command_injection_sinks, supported_languages, codebase_overview). Descriptions vary in quality: some are comprehensive with examples and return schemas documented (list_methods, list_calls, find_command_injection_sinks), while others are minimal (supported_languages: 'Languages and recommended workflow supported by CodeBadger.', only 64 chars, under the 194-char baseline). Input schemas are present for all tools and include type definitions and parameter descriptions, meeting JSON Schema standards. However, critical gaps exist: (1) output schemas are described in prose within tool descriptions but not formally documented as response types in the MCP tool registration; (2) error handling is absent, no guidance on retryability, user-fixable errors, or recovery actions; (3) some parameter descriptions lack format constraints and allowed value ranges (e.g., 'page' and 'page_size' in list_methods have no documented bounds, inviting invalid LLM input); (4) the composition of tools is sound (each does one thing), but discovery workflows are not well-supported (supported_languages and codebase_overview lack clear descriptions of when/why to call them); (5) security aspects are not documented (no permission declarations, no audit trail guidance). Overall, the server demonstrates competent baseline engineering but lacks the polish required for production LLM interaction.
Guide an LLM through a concise, bounded codebase overview.
Find potential OS command injection sinks (CWE-78). Identifies call sites where shell-execution functions receive a non-literal argument — the minimal syntactic signal that user-controlled data might reach a command interpreter. Works across C, C++, Python, Java, JavaScript, Go, PHP, and Ruby. Args: codebase_hash: Hash returned by generate_cpg. language: Narrow to a language's sink set (c, cpp, python, java, javascript, go, php, ruby). Auto-detected when omitted. filename: Optional filename to restrict results (substring match). max_results: Upper bound on returned call sites (default 50). Returns: Text report listing each sink call site with location and code snippet, followed by a suggested next step (find_taint_flows). Notes: - A non-literal argument is necessary but NOT sufficient to confirm injection. - Follow up with find_taint_flows(mode='auto', sink_patterns=[...]). - Literal-only calls (e.g., system("ls")) are excluded as safe. Examples: find_command_injection_sinks(codebase_hash="abc123") find_command_injection_sinks(codebase_hash="abc123", language="python") find_command_injection_sinks(codebase_hash="abc123", filename="handler.c")
List function/method calls in the codebase. Discover call relationships between functions. Args: codebase_hash: The codebase hash. caller_pattern: Regex for the calling method. callee_pattern: Regex for the called method. limit: Max results. page: Page number. Returns: { "success": true, "calls": [ {"caller": "main", "callee": "printf", "filename": "main.c", "lineNumber": 10} ], "total": 25000, "available": 1000, "returned": 100, "result_cap": 1000, "truncated": true, "page": 1, "page_size": 100, "total_pages": 10 } Notes: - Useful for finding where specific functions are used. Examples: list_calls(codebase_hash="abc", callee_pattern="strcpy") list_calls(codebase_hash="abc", caller_pattern="main")
Output schemas documented in prose, not as structured response types in MCP registration
Minimal descriptions for discovery/presentation tools (supported_languages, codebase_overview)
Pagination parameters (page, page_size, limit) lack documented constraints (min/max bounds)
No error handling guidance or recovery instructions in tool descriptions
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 60 | <=2025-11-25 | v2 |
List methods/functions in the codebase. Discover all methods and functions defined in the analyzed code. Args: codebase_hash: The codebase hash. name_pattern: Regex filter for method name. file_pattern: Regex filter for filename. callee_pattern: Regex filter for methods that call this specific function. include_external: Include external (library) methods (default False). limit: Max results. page: Page number. Returns: { "success": true, "methods": [{"name": "main", "filename": "main.c", ...}], "total": 1250, "available": 1000, "returned": 100, "result_cap": 1000, "truncated": true, "page": 1, "page_size": 100, "total_pages": 10 } Notes: - Use name_pattern to find specific methods. - Use callee_pattern to find usages (e.g., who calls 'malloc'). Examples: list_methods(codebase_hash="abc", name_pattern=".*auth.*") list_methods(codebase_hash="abc", callee_pattern="memcpy")
Languages and recommended workflow supported by CodeBadger.
No permission declarations or security scope metadata documented
Result limits documented for list_methods/list_calls (1000 result_cap) but enforcement mechanism and LLM guidance are unclear