An MCP server that indexes local code into a graph database to provide context to AI assistants.
CodeGraphContext provides 18 tools with complete input schemas and descriptions. Naming follows verb_noun convention (add_, check_, find_, analyze_, etc.). Descriptions are substantive (100-300 chars typical), explaining WHAT and WHEN. However, output schemas are undocumented, LLMs cannot predict response structure for chaining. Error handling is absent: no recovery guidance, no categorization of retryable vs fatal errors. Parameters lack constraints (e.g., edit_distance accepts 0-2 but no validation shown). Security: no evidence of secret injection, permission gates, or audit logging. Composition is reasonable, tools are single-purpose, but some tools like analyze_code_relationships combine 14 query types in one tool, risking confusion.
Performs a one-time scan of a local folder to add its code to the graph. Ideal for indexing libraries, dependencies, or projects not being actively modified. Returns a job ID for background processing.
Add a package to the graph by discovering its location. Supports multiple languages. Returns immediately with a job ID.
Analyze code relationships like 'who calls this function' or 'class hierarchy'. Supported query types include: find_callers, find_callees, find_all_callers, find_all_callees, find_importers, who_modifies, class_hierarchy, overrides, dead_code, call_chain, module_deps, variable_scope, find_complexity, find_functions_by_argument, find_functions_by_decorator.
Calculate the cyclomatic complexity of a specific function to measure its complexity.
Check the status and progress of a background job.
Delete an indexed repository from the graph.
No output schemas documented. LLMs cannot predict response structure (fields, types, pagination) for downstream tool chaining. E.g., find_code returns results but structure is unknown.
No error handling or recovery guidance. Tools lack categorization of retryable vs fatal errors, and no actionable error messages. E.g., if add_code_to_graph fails, LLM has no guidance on next steps.
analyze_code_relationships combines 14 distinct query types (find_callers, find_callees, class_hierarchy, etc.) in one tool. This violates single-responsibility principle and forces LLM to reason about which enum value to pass. Should split into separate tools.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
Fallback tool to run a direct, read-only Cypher query against the code graph. Use this for complex questions not covered by other tools. The graph contains nodes representing code structures and relationships between them. **Schema Overview:** - **Nodes:** `Repository`, `File`, `Module`, `Class`, `Function`. - **Properties:** Nodes have properties like `name`, `path`, `cyclomatic_complexity` (on Function nodes), and `source`. - **Relationships:** `CONTAINS` (e.g., File-[:CONTAINS]->Function), `CALLS` (Function-[:CALLS]->Function or File-[:CALLS]->Function), `IMPORTS` (File-[:IMPORTS]->Module), `INHERITS` (Class-[:INHERITS]->Class).
Find relevant code snippets related to a keyword (e.g., function name, class name, or content).
Find potentially unused functions (dead code) across the entire indexed codebase, optionally excluding functions with specific decorators.
Find the most complex functions in the codebase based on cyclomatic complexity.
List all indexed repositories.
List all background jobs and their current status.
Lists all directories currently being watched for live file changes.
Load a pre-indexed .cgc bundle into the database. Can load from local file or automatically download from registry if not found locally. Bundles are portable snapshots of indexed code that load instantly without re-indexing.
Search for available pre-indexed bundles in the registry. Returns bundles matching the search query with details like repository, version, size, and download information.
Stops watching a directory for live file changes.
Generates a URL to visualize the results of a Cypher query in the Neo4j Browser. The user can open this URL in their web browser to see the graph visualization.
Performs an initial scan of a directory and then continuously monitors it for changes, automatically keeping the graph up-to-date. Ideal for projects under active development. Returns a job ID for the initial scan.
Parameter constraints not validated or documented. edit_distance accepts 0-2 but no validation shown. No min/max bounds on limit, page_size. LLMs can pass invalid values without feedback.
No security controls visible: no secret injection pattern, no permission gates for destructive tools (delete_repository), no audit logging. delete_repository lacks confirmation step.