An MCP server that indexes local code into a graph database to provide context to AI assistants.
CodeGraphContext defines 17 tools with complete input schemas and descriptions. Naming follows verb_noun convention (add_code_to_graph, find_code, analyze_code_relationships). Descriptions are substantive (100-300 chars typical), explaining WHAT and WHEN. However, output schemas are entirely undocumented, no tool specifies what fields are returned, forcing LLMs to infer structure. Error handling is absent: no guidance on retryability, user-fixable vs fatal errors, or recovery paths. Parameters lack constraints (e.g., edit_distance accepts 0-2 but no enum/min/max validation shown). Risk annotations (WRITE, READ_ONLY, DESTRUCTIVE) are present but not formalized as tool annotations per MCP spec. Composition is strong: tools chain logically (add_code_to_graph → check_job_status → find_code). No secrets exposed in parameters.
Performs a one-time scan of a local folder to add its code to the graph. Ideal for indexing libraries, dependencies, or projects not being actively modified. Returns a job ID for background processing.
Add a package to the graph by discovering its location. Supports multiple languages. Returns immediately with a job ID.
Analyze code relationships like 'who calls this function' or 'class hierarchy'. Supported query types include: find_callers, find_callees, find_all_callers, find_all_callees, find_importers, who_modifies, class_hierarchy, overrides, dead_code, call_chain, module_deps, variable_scope, find_complexity, find_functions_by_argument, find_functions_by_decorator.
Calculate the cyclomatic complexity of a specific function to measure its complexity.
Check the status and progress of a background job.
Delete an indexed repository from the graph.
No output schemas documented for any tool. LLMs cannot infer what fields are returned (e.g., does find_code return file_path, line_number, snippet, confidence?). Forces agents to guess structure and risks parsing failures.
No error handling guidance. Tools do not specify what errors are retryable (e.g., job_id not found vs database timeout), what is user-fixable (invalid query syntax), or what is fatal. Agents cannot recover intelligently.
Parameter constraints not enforced in schema. edit_distance accepts 0-2 but no min/max in schema. fuzzy_search is boolean but no guidance on when to use. Agents may pass invalid values without validation feedback.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
Fallback tool to run a direct, read-only Cypher query against the code graph. Use this for complex questions not covered by other tools. The graph contains nodes representing code structures and relationships between them. **Schema Overview:** - **Nodes:** `Repository`, `File`, `Module`, `Class`, `Function`. - **Properties:** Nodes have properties like `name`, `path`, `cyclomatic_complexity` (on Function nodes), and `source`. - **Relationships:** `CONTAINS` (e.g., File-[:CONTAINS]->Function), `CALLS` (Function-[:CALLS]->Function or File-[:CALLS]->Function), `IMPORTS` (File-[:IMPORTS]->Module), `INHERITS` (Class-[:INHERITS]->Class).
Find relevant code snippets related to a keyword (e.g., function name, class name, or content).
Find potentially unused functions (dead code) across the entire indexed codebase, optionally excluding functions with specific decorators.
Find the most complex functions in the codebase based on cyclomatic complexity.
List all indexed repositories.
List all background jobs and their current status.
Lists all directories currently being watched for live file changes.
Load a pre-indexed .cgc bundle into the database. Can load from local file or automatically download from registry if not found locally. Bundles are portable snapshots of indexed code that load instantly without re-indexing.
Stops watching a directory for live file changes.
Generates a URL to visualize the results of a Cypher query in the Neo4j Browser. The user can open this URL in their web browser to see the graph visualization.
Performs an initial scan of a directory and then continuously monitors it for changes, automatically keeping the graph up-to-date. Ideal for projects under active development. Returns a job ID for the initial scan.
Risk annotations (WRITE, READ_ONLY, DESTRUCTIVE) are informal comments, not MCP tool annotations. Should use readOnlyHint, destructiveHint, idempotentHint per spec to enable agent safety policies.
Destructive tool (delete_repository) lacks confirmation/dry-run pattern. No guidance on whether deletion is reversible or what happens to dependent watches/bundles. Agents could accidentally delete indexed code.