{"_id":"@astudioplus/codegraph-pro-mcp","name":"@astudioplus/codegraph-pro-mcp","dist-tags":{"latest":"0.18.5"},"versions":{"0.18.5":{"name":"@astudioplus/codegraph-pro-mcp","version":"0.18.5","mcpName":"io.github.codegraph-ai/codegraph-pro","description":"CodeGraph Pro MCP server — semantic code graph + 41 proprietary tools incl. multi-engine security orchestrator and 21 security detectors (CWE-22/78/89/190/208/284/310/326-330/347/426/427/476/611/639/755/798/916/918/1239), SARIF 2.1.0 export, SBOM, taint t","author":{"name":"Andrey Vasilevsky","email":"anvanster@gmail.com"},"license":"SEE LICENSE IN LICENSE","homepage":"https://codegraph.astudioplus.com","repository":{"type":"git","url":"git+https://github.com/codegraph-ai/CodeGraph.git"},"keywords":["mcp","model-context-protocol","code-intelligence","code-graph","security","sast","sarif","sbom","cwe","bounty","ai","claude","cursor","copilot"],"bin":{"codegraph-pro-mcp":"bin/codegraph-pro-mcp.js"},"engines":{"node":">=18.0.0"},"os":["darwin","linux","win32"],"cpu":["x64","arm64"],"scripts":{"postinstall":"node bin/postinstall.js"},"_id":"@astudioplus/codegraph-pro-mcp@0.18.5","bugs":{"url":"https://github.com/codegraph-ai/CodeGraph/issues"},"_integrity":"sha512-MT87Q6XvIf8e5/O+hQsaxbROSOdTah/RmrJw1XNGS9YuBhYUDqpi7ucHx9R6i+75O3oIc3gvfEQibWzJMaO7iA==","_resolved":"/Users/anvanster/projects/codegraph-pro/mcp-package/astudioplus-codegraph-pro-mcp-0.18.5.tgz","_from":"file:astudioplus-codegraph-pro-mcp-0.18.5.tgz","_nodeVersion":"25.6.1","_npmVersion":"11.9.0","dist":{"integrity":"sha512-MT87Q6XvIf8e5/O+hQsaxbROSOdTah/RmrJw1XNGS9YuBhYUDqpi7ucHx9R6i+75O3oIc3gvfEQibWzJMaO7iA==","shasum":"c52823169954348671f26e8c7261ff63daa0abe5","tarball":"https://registry.npmjs.org/@astudioplus/codegraph-pro-mcp/-/codegraph-pro-mcp-0.18.5.tgz","fileCount":23,"unpackedSize":601763406,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGemu+ufwjkRENk3PmaVTthl6dUn+tc+PtmHmoXY1BQWAiEApsDQnBYqjJZO4NfqICA/0QUJlNnSfflH+sqjFjVpsN8="}]},"_npmUser":{"name":"anvanster-personal","email":"anvanster@gmail.com"},"directories":{},"maintainers":[{"name":"anvanster-personal","email":"anvanster@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/codegraph-pro-mcp_0.18.5_1781421807222_0.40587974972640195"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-14T07:23:27.034Z","0.18.5":"2026-06-14T07:23:28.652Z","modified":"2026-06-14T07:23:28.897Z"},"maintainers":[{"name":"anvanster-personal","email":"anvanster@gmail.com"}],"description":"CodeGraph Pro MCP server — semantic code graph + 41 proprietary tools incl. multi-engine security orchestrator and 21 security detectors (CWE-22/78/89/190/208/284/310/326-330/347/426/427/476/611/639/755/798/916/918/1239), SARIF 2.1.0 export, SBOM, taint t","homepage":"https://codegraph.astudioplus.com","keywords":["mcp","model-context-protocol","code-intelligence","code-graph","security","sast","sarif","sbom","cwe","bounty","ai","claude","cursor","copilot"],"repository":{"type":"git","url":"git+https://github.com/codegraph-ai/CodeGraph.git"},"author":{"name":"Andrey Vasilevsky","email":"anvanster@gmail.com"},"bugs":{"url":"https://github.com/codegraph-ai/CodeGraph/issues"},"license":"SEE LICENSE IN LICENSE","readme":"# CodeGraph Pro MCP Server\n\nProprietary extension to CodeGraph — adds 41 pro tools on top of the 34 community tools (75 total), including a **multi-engine security orchestrator** (`codegraph_security_orchestrated_scan`) that runs the rule-pattern engine + the calibrated native detector arsenal in parallel, dedups findings via canonicaliser, and applies the attacker-reachability gate uniformly across engines. **21 security detectors** + 10 security-adjacent tools (SARIF 2.1.0 export, SBOM, taint tracing, IaC scan, vuln audit, CodeQL warmup, control-flow / data-flow tracing), plus 10 code-quality / similarity / git-intelligence tools. **38 languages.**\n\n## Install\n\n```bash\nnpm install -g @astudioplus/codegraph-pro-mcp\n```\n\n## License\n\nThe pro binary requires a license key. First launch without a key starts a **30-day trial**.\n\n- Purchase / manage license: <https://codegraph.astudioplus.com/license>\n- Individual: $19/mo, Team: $39/seat/mo, Enterprise: custom\n\nProvide the key via environment variable:\n\n```bash\nexport CODEGRAPH_LICENSE_KEY=cg-prod-...\n```\n\nOr via CLI flag (persists to `~/.codegraph/license.json`):\n\n```bash\ncodegraph-pro-mcp --license cg-prod-...\n```\n\n## Usage\n\n### Claude Code\n\nAdd to `~/.claude.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"codegraph-pro\": {\n      \"command\": \"codegraph-pro-mcp\",\n      \"args\": [\"--workspace\", \"/path/to/project\"],\n      \"env\": {\n        \"CODEGRAPH_LICENSE_KEY\": \"cg-prod-...\"\n      }\n    }\n  }\n}\n```\n\n### Cursor / Other MCP clients\n\nSame config — the `codegraph-pro-mcp` command starts the server in MCP (stdio) mode.\n\n### Flags\n\n| Flag | Default | Description |\n|------|---------|-------------|\n| `--workspace <path>` | current dir | Directories to index (repeatable) |\n| `--exclude <dir>` | — | Directories to skip (repeatable) |\n| `--license <key>` | from env | Persist the license key |\n| `--embedding-model <model>` | `bge-small` | `bge-small` or `jina-code-v2` |\n| `--max-files <n>` | 5000 | Maximum files to index |\n\n## Pro Tools (41)\n\n### Security — Aggregators & Output (5)\n- `codegraph_security_scan` — aggregate scan across all categories (legacy single-engine)\n- `codegraph_security_orchestrated_scan` — **multi-engine entrypoint**: rule packs + native detector arsenal merged via canonicaliser, cross-engine agreement scoring, reachability gate\n- `codegraph_security_scan_iac` — Docker / K8s / Terraform misconfig\n- `codegraph_security_export_sarif` — SARIF 2.1.0 aggregation across all detector classes\n- `codegraph_security_generate_sbom` — CycloneDX SBOM from 8 lockfile formats\n\n### Security — Analysis & Audit (5)\n- `codegraph_security_audit_deps` — OSV vulnerability check\n- `codegraph_security_check_licenses` — copyleft detection\n- `codegraph_security_codeql_warmup` — pre-build CodeQL DB for the dataflow engine (5–15 min cold; cached in `~/.codegraph/codeql-dbs/`)\n- `codegraph_security_control_flow` — CFG analysis (Rust/Python/TS/Go)\n- `codegraph_security_trace_data_flow` — variable taint tracing\n\n### Security — Detectors (21)\n\n**Heuristic analyzers (5):**\n- `codegraph_security_check_unchecked_returns` (CWE-252)\n- `codegraph_security_check_resource_leaks` (CWE-401, 772)\n- `codegraph_security_check_misconfig` (CWE-16, 295, 614, 1004)\n- `codegraph_security_check_input_validation` (CWE-20, 129)\n- `codegraph_security_check_error_exposure` (CWE-209, 497)\n\n**Pattern detectors (4):**\n- `codegraph_security_check_secrets_entropy` (CWE-798, Shannon-entropy)\n- `codegraph_security_detect_injection` (CWE-22/78/79/89/502/1336)\n- `codegraph_security_check_search_path` (CWE-426, 427) — macro/constexpr resolution, wrapper-library patterns (lt_dlopen, g_module_open, ENGINE_load_dynamic, Tss2_TctiLdr_Initialize)\n- `codegraph_security_check_crypto` (CWE-208/310/326-330/338/347/780/798/916/1239, 113 patterns, 8 languages, context-aware severity + FP filters)\n\n**Bounty round-5/6 — multi-tenant SaaS classes (5):**\n- `codegraph_security_check_ssrf` (CWE-918) — DataSource/webhook URL → outbound HTTP without `IsPrivateIP`/`safeurl` safeguard. Cross-function source tracing, trust-boundary tiering (server-admin / org-admin / authenticated / untrusted), upstream input-validation suppression, admin-gating awareness. Canonical: Grafana CVE-2020-13379 / 2022-31107 / 2024-1442.\n- `codegraph_security_check_idor` (CWE-639/284) — handler with object-lookup but no authz call. Recognizes route-level authz middleware (`routing.Wrap` + `authorizeInOrg`/`@PreAuthorize`/etc.), suppresses session-derived ID lookups (`c.SignedInUser.UserID` etc.). Canonical: Grafana CVE-2022-21713 / 2023-4822.\n- `codegraph_security_check_fail_open_verify` (CWE-755 → CWE-347 / CWE-295) — Go verify-call-then-warn shape AND C/C++/Rust \"fail-open on null precondition\" (CVE-2026-46333 generalization): decision-class function returns success when a precondition is null/missing, skipping a downstream security check. Errno-vs-predicate convention awareness, inverted-condition guard, ≤2-statement strict mode.\n- `codegraph_security_check_integer_overflow` (CWE-190 → 120, C/C++)\n- `codegraph_security_check_null_deref` (CWE-476, C/C++, 34 nullable allocators)\n\n**Bounty round-7 — attestation / CC-target additions (7):**\n- `codegraph_security_check_default_crypto` (CWE-1188) — relying on language-default crypto (`Random` without seed, `crypto/rand.Reader` vs `math/rand`, etc.)\n- `codegraph_security_check_jwt_completeness` — JWT verify call without algorithm allowlist / iss / aud / exp checks\n- `codegraph_security_check_trust_anchor_source` — trust anchor loaded from network / writable path / disabled verification\n- `codegraph_security_check_encoding_mismatch` — encoding boundary asymmetry (URL-decode vs raw bytes, percent-encode vs HTML)\n- `codegraph_security_check_rest_handler_missing_auth` — REST endpoint without authentication middleware\n- `codegraph_security_check_path_join_absolute_rhs` (CWE-22) — `path.join` with absolute RHS silently overrides the LHS prefix\n- `codegraph_security_check_fd_path_asymmetry` — same resource accessed via both fd-handle and path-string (race window)\n\n### Code Analysis (10)\n- `codegraph_analyze_coupling` — afferent/efferent coupling metrics\n- `codegraph_find_unused_code` — dead-code candidates via graph analysis\n- `codegraph_find_duplicates` / `codegraph_find_similar` / `codegraph_cluster_symbols` / `codegraph_compare_symbols` — similarity analysis via full-body embeddings\n- `codegraph_cross_project_search` — search across indexed projects\n- `codegraph_mine_git_history` / `codegraph_mine_git_history_for_file` / `codegraph_search_git_history` — hotspot analysis & semantic search over git log\n\n## Cross-cutting Features\n\nEvery `codegraph_security_*` tool supports:\n- **Attacker-reachability gate** — per-finding tri-state (`reachable_from_request: true | false | null`) with entry-point source attribution (`pkg/api/foo.go:57 (gin handler)`). BFS scoped to project root so multi-target sweeps don't produce phantom cross-project edges. Scan-level aggregates (`reachability: { entry_points, reachable_from_request, unreachable_from_request, unknown }`) for triage productivity tracking.\n- **Suppression markers** — 25 markers across bandit, flake8, pylint, mypy, NOLINT, codeql, semgrep, coverity, rubocop, eslint, plus `SAFETY:`/`SAFE:`/`# pragma: allowlist`\n- **Path filter** — test/sample/vendored/build-or-docs categorization (covers `tests/`, `mocks/`, `__mocks__/`, `e2e/`, `cypress/`, `storybook/`, `devenv/`, `testing.go`/`testutil.go`/`conftest.py` test helpers, 30+ JS/CSS lib prefixes); `include_tests` + `treat_as_production` args\n- **Defensive-gating** — findings inside `#ifdef X` where X isn't defined by CMake/Cargo/Makefile are marked `status: \"DEFENSIVE_GATED_OFF: X\"`\n- **Per-finding line attribution** — every finding points at the actual matching line, not the function header\n\nSSRF / IDOR / fail-open additionally provide:\n- **Cross-function source tracing** — call-graph BFS (depth ≤ 6, project-scoped) so helper functions inherit explicit-source confidence from their callers\n- **Trust-boundary tiering** (SSRF) — sources classified as `server-admin` (demoted to LOW), `org-admin` (multi-tenant CVE lane, retained), `authenticated`, or `untrusted`\n- **Admin-gating awareness** — severity downgrades when call chain passes through `c.IsGrafanaAdmin` / `ReqGrafanaAdmin` / `@Secured(\"ADMIN\")` / `requireAdmin` etc.\n- **Upstream input-validation tracing** — suppresses findings when a caller validates the input via regex/allowlist/prefix-bound followed by abort\n\n## Supported Languages (38)\n\nBash, C, C++, C#, Clojure, COBOL, CSS, Dart, Dockerfile, Elixir, Elm, Erlang, Fortran, Go, Groovy, Haskell, HCL/Terraform, Java, Julia, Kotlin, Lua, Objective-C, OCaml, Perl, PHP, Python, R, Ruby, Rust, Scala, Solidity, Swift, Tcl, TOML, TypeScript/JS, Verilog/SystemVerilog, YAML, Zig.\n\n## Documentation\n\nFull tool reference (request/response examples, severity rules, FP guards): [tool-calling-guide.md](https://github.com/codegraph-ai/CodeGraph/blob/main/docs/tool-calling-guide.md).\n\n## Feedback & Support\n\n- Issues: <https://github.com/codegraph-ai/CodeGraph/issues>\n- License support: <mailto:support@astudioplus.com>\n","readmeFilename":"README.md","_rev":"1-759c6b7638e0a228098d810c4af7ab5b"}