MCP-Server

searchcode

com.searchcode/mcp
Entwicklertools Sicherheit Öffentlich und erreichbar MCP 2026-07-28

Was dieses MCP kann

Analyzes, searches, and retrieves code from public Git repositories, including code-quality findings and secret scanning.

code_analyze
Instant repo overview — languages, complexity, file count, tech stack, code quality findings, and secret scanning. Use as your first call to understand any remote public codebase. This is the tool that scans for LEAKED CREDENTIALS: security_summary is a dedicated secret and credential scanner covering API keys, access tokens, private keys and connection strings, each with a file, a line and a confidence grade. Prefer it over grepping for key prefixes with code_search — a pattern search only finds what you thought to spell, and finds nothing at all in the repositories where you guessed wrong. Supports language filtering and path scoping (for large monorepos, analyze a subdirectory instead of the full repo). When analysing multiple repositories, call in parallel rather than sequentially. Dependency/build directories excluded by default.
Eingabeschema
{'type': 'object', 'required': ['repository'], 'properties': {'path': {'type': 'string', 'description': "Subdirectory to scope analysis to (e.g. 'src', 'clang/lib'). Only files under this path are walked and analyzed — use this for large monorepos where full analysis is too slow or when the user's question is about a specific component. Omit to analyze the entire repository."}, 'tests': {'enum': ['exclude', 'include', 'only'], 'type': 'string', 'default': 'exclude', 'description': 'Findings in TEST files (*_test.go, test/, tests/, spec/, __tests__/, testdata/, *.test.ts, *.spec.js, *Test.java, *Tests.cs, test_*.py, conftest.py, *_spec.rb and the like). "exclude", the default, leaves them out of code_quality_summary and security_summary and counts them in tests_excluded; "include" adds them, each marked test: true; "only" returns just them. They are kept, not deleted: a credential committed in a test fixture is still a real credential, and include reaches it.'}, 'language': {'type': 'string', 'description': 'Filter results to a specific language (e.g. "Java", "Go", "Python").'}, 'repository': {'type': 'string', 'description': 'Full git URL of ONE public remote repository, e.g. "https://github.com/redis/redis". Required. There is no cross-repository or global search: this API analyses one repository per call, cloning it on demand. Wildcards and placeholders ("*", "all", "global", a bare host like "github.com") are rejected — if you do not have a specific repository URL, ask for one rather than guessing.'}, 'detail_level': {'enum': ['summary', 'full'], 'type': 'string', 'description': 'Controls response verbosity. summary returns top 20 across all languages; full returns top 20 per language. Use summary for portfolio reviews, hiring assessments, and high-level overviews. Use full for deep per-language audits or when you need granular per-file breakdowns within a specific language.'}, 'scan_test_files': {'type': 'boolean', 'default': False, 'description': 'Older spelling of tests="include", honoured when tests is not set. Prefer tests.'}, 'include_all_dirs': {'type': 'boolean', 'default': False, 'description': 'Include dependency/build/cache directories that are excluded by default (vendor, node_modules, third_party, target, build, dist, Pods, generated, etc.). Set to true if you need to analyze generated/vendored code.'}}}
code_file_tree
List files and directories in any public git repo. Supports fuzzy file search (query parameter), language/path filtering, and depth control. Combine query with path_filter to search within a directory subset. Use to explore project layout, find files by name, or browse specific directories. Results capped at 1000 files; response includes total_files, files_shown, and truncated fields. Use language or path_filter to narrow large repos. Dependency/build directories excluded by default.
Eingabeschema
{'type': 'object', 'required': ['repository'], 'properties': {'query': {'type': 'string', 'description': "Fuzzy search query for finding files by approximate name. Returns ranked matches instead of tree. Examples: 'main.go', 'auth handler'. Can be combined with path_filter to search within a directory subset."}, 'language': {'type': 'string', 'description': 'Filter to only show files of this language (e.g. "Go", "Java").'}, 'max_depth': {'type': 'integer', 'description': 'Maximum directory depth to return. If omitted, returns full tree.'}, 'repository': {'type': 'string', 'description': 'Full git URL of ONE public remote repository, e.g. "https://github.com/redis/redis". Required. There is no cross-repository or global search: this API analyses one repository per call, cloning it on demand. Wildcards and placeholders ("*", "all", "global", a bare host like "github.com") are rejected — if you do not have a specific repository URL, ask for one rather than guessing.'}, 'max_results': {'type': 'integer', 'default': 20, 'maximum': 100, 'minimum': 1, 'description': 'Max fuzzy matches to return. Integer between 1 and 100 — values above 100 are rejected, not clamped. Only used with query.'}, 'path_filter': {'type': 'string', 'description': "Filter to restrict tree to matching paths. Supports both glob patterns (e.g. 'pkg/**', 'src/**/*.go') and token-style filters (e.g. 'pkg/api .go'). Glob patterns are auto-converted to token filters. When combined with query, narrows the file set before fuzzy matching."}, 'include_stats': {'type': 'boolean', 'default': False, 'description': 'If true, include line count and file size for each file.'}, 'include_all_dirs': {'type': 'boolean', 'default': False, 'description': 'Include dependency/build/cache directories that are excluded by default (vendor, node_modules, third_party, target, build, dist, Pods, generated, etc.). Set to true if you need to see generated/vendored code in the tree.'}}}
code_find_usages
Find which files in a repository use a given technology, library or framework — with the line number and the import keyword that proves it. Use after code_analyze reports a technology in tech_stack and you need to know which files it is actually in, rather than searching for import statements by hand. Returns file, line, evidence keyword and language. COVERAGE LIMIT: technology detection reads only the first 150 lines of each file, so a file that imports the technology further down, or uses it without a top-of-file import, does not appear. Absence from these results is not proof the file does not use the technology. The count matches the files_using value code_analyze reports for the same technology. Shares the analysis cache with code_analyze — no duplicate work if analyze already ran.
Eingabeschema
{'type': 'object', 'required': ['repository', 'technology'], 'properties': {'offset': {'type': 'integer', 'default': 0, 'description': 'Skip this many files before returning. Use for paging.'}, 'language': {'type': 'string', 'description': 'Restrict results to files of this language (e.g. "Python", "Go").'}, 'repository': {'type': 'string', 'description': 'Full git URL of ONE public remote repository, e.g. "https://github.com/redis/redis". Required. There is no cross-repository or global search: this API analyses one repository per call, cloning it on demand. Wildcards and placeholders ("*", "all", "global", a bare host like "github.com") are rejected — if you do not have a specific repository URL, ask for one rather than guessing.'}, 'technology': {'type': 'string', 'description': 'Technology, library or framework to find. Matched against the names code_analyze reports in tech_stack, exactly first and then as a substring — so "boto3" finds "AWS SDK (Boto3)". Call code_analyze first if you are unsure what is detected.'}, 'max_results': {'type': 'integer', 'default': 50, 'maximum': 500, 'description': 'Maximum number of files to return (cap: 500).'}, 'path_filter': {'type': 'string', 'description': 'Restrict results to files whose path contains this substring (e.g. "src/", "handlers").'}}}
code_get_file
Get code from a remote public git repository — either a specific function/class by name, a line range, or a full file. PREFERRED WORKFLOW: When search results or findings have already identified a specific function, method, or class, use symbol_name to extract just that declaration. This avoids fetching entire files and keeps context focused. Only fetch full files when you need a broad understanding of a file you haven't seen before. For supported languages (Go, Python, TypeScript, JavaScript, Java, C, C++, C#, Kotlin, Swift, Rust) the response includes a symbols list of declarations with line ranges. This is not a first-call tool — use code_analyze or code_search first to identify targets, then extract precisely what you need.
Eingabeschema
{'type': 'object', 'required': ['repository', 'path'], 'properties': {'path': {'type': 'string', 'description': 'File path relative to repository root'}, 'end_line': {'type': 'integer', 'description': 'Last line to return (inclusive). If omitted, returns to end of file. Cannot combine with symbol_name.'}, 'max_lines': {'type': 'integer', 'default': 500, 'maximum': 2000, 'description': 'Lines to return (max: 2000). When reading an unfamiliar file for orientation, set this to 2000. When you already know which function or class you need (from search or findings results), prefer symbol_name instead — it returns only the relevant declaration and avoids pulling unnecessary context.'}, 'repository': {'type': 'string', 'description': 'Full git URL of ONE public remote repository, e.g. "https://github.com/redis/redis". Required. There is no cross-repository or global search: this API analyses one repository per call, cloning it on demand. Wildcards and placeholders ("*", "all", "global", a bare host like "github.com") are rejected — if you do not have a specific repository URL, ask for one rather than guessing.'}, 'start_line': {'type': 'integer', 'default': 1, 'description': 'First line to return (1-based). Cannot combine with symbol_name.'}, 'symbol_name': {'type': 'string', 'description': 'PREFERRED for targeted retrieval. Name of a function/method/class to extract — returns only that declaration. Use this when search results or findings have pointed you to a specific symbol, instead of fetching the entire file. Cannot combine with start_line/end_line. Response includes a symbols list for supported languages.'}, 'include_adjacent_symbols': {'type': 'boolean', 'default': False, 'description': 'When true and symbol_name is set, includes structurally related declarations (nearby siblings) alongside the target symbol.'}}}
code_get_files
Get contents of multiple files from a remote public git repository in a single call. Reduces round-trips when you need to read several related files. Max 10 files per batch, 5000 total lines budget across all files. Each file supports optional line ranges. Failed files return per-file errors without blocking other files.
Eingabeschema
{'type': 'object', 'required': ['repository', 'paths'], 'properties': {'paths': {'type': 'array', 'items': {'type': 'object', 'required': ['path'], 'properties': {'path': {'type': 'string', 'description': 'File path relative to repository root'}, 'end_line': {'type': 'integer', 'description': 'Last line to return (inclusive). If omitted, returns to end of file.'}, 'start_line': {'type': 'integer', 'default': 1, 'description': 'First line to return (1-based).'}}}, 'maxItems': 10, 'description': 'List of files to read. Each entry has a path and optional line range.'}, 'max_lines': {'type': 'integer', 'default': 500, 'maximum': 2000, 'description': 'Per-file safety cap on lines returned (cap: 2000).'}, 'repository': {'type': 'string', 'description': 'Full git URL of ONE public remote repository, e.g. "https://github.com/redis/redis". Required. There is no cross-repository or global search: this API analyses one repository per call, cloning it on demand. Wildcards and placeholders ("*", "all", "global", a bare host like "github.com") are rejected — if you do not have a specific repository URL, ask for one rather than guessing.'}}}
code_get_findings
Get detailed code quality findings from a remote public git repository. Returns rule IDs, line numbers, severity, category, descriptions, and source snippets. Supports filtering by file path, severity (error, warning, info), category (security, deprecated, safety, correctness, maintainability, accessibility, modernization, performance, concurrency), and kind (security, quality) — kind=security is every security-category finding in one call, kind=quality is everything else. code_analyze.top_findings shows only the quality half; use kind=security here to see the security-category findings it leaves out. THIS IS NOT THE SECRET SCANNER. kind=security means insecure code — weak hashes, unsafe deserialization, injection-shaped patterns — and it will not find a leaked API key or private key. Leaked credentials are code_analyze.security_summary, which is a different scanner over different rules; the two sets do not overlap, so an audit wants both. Use after code_analyze to drill into specific findings. Shares the same analysis cache — no duplicate work if analyze already ran.
Eingabeschema
{'type': 'object', 'required': ['repository'], 'properties': {'kind': {'enum': ['security', 'quality'], 'type': 'string', 'description': 'Partition the findings: "security" returns the security-category findings, "quality" returns every other category. The two are exhaustive and do not overlap, so kind is the way to ask for everything-but-security without enumerating the other eight categories and missing any added later.'}, 'path': {'type': 'string', 'description': 'Filter findings to files matching this path prefix (e.g. "pkg/api/" or "src/main.go").'}, 'tests': {'enum': ['exclude', 'include', 'only'], 'type': 'string', 'default': 'exclude', 'description': 'Findings in TEST files (*_test.go, test/, tests/, spec/, __tests__/, testdata/, *.test.ts, *.spec.js, *Test.java, *Tests.cs, test_*.py, conftest.py, *_spec.rb and the like). "exclude", the default, leaves them out of findings and total_findings and counts them in tests_excluded; "include" adds them, each marked test: true; "only" returns just them. They are kept, not deleted: a credential committed in a test fixture is still a real credential, and include reaches it.'}, 'offset': {'type': 'integer', 'default': 0, 'description': 'Skip this many findings before returning. Use for paging.'}, 'category': {'enum': ['security', 'deprecated', 'safety', 'correctness', 'maintainability', 'accessibility', 'modernization', 'performance', 'concurrency'], 'type': 'string', 'description': 'Filter findings by category.'}, 'severity': {'enum': ['error', 'warning', 'info'], 'type': 'string', 'description': 'Filter findings by severity level.'}, 'repository': {'type': 'string', 'description': 'Full git URL of ONE public remote repository, e.g. "https://github.com/redis/redis". Required. There is no cross-repository or global search: this API analyses one repository per call, cloning it on demand. Wildcards and placeholders ("*", "all", "global", a bare host like "github.com") are rejected — if you do not have a specific repository URL, ask for one rather than guessing.'}, 'max_results': {'type': 'integer', 'default': 50, 'maximum': 200, 'description': 'Maximum number of findings to return (cap: 200).'}, 'scan_test_files': {'type': 'boolean', 'default': False, 'description': 'Older spelling of tests="include", honoured when tests is not set. Prefer tests.'}}}
code_search
Fast code search across any public git repo. Returns file paths, line numbers, and code snippets with context. Supports regex, boolean queries, fuzzy matching, and structural filters (declarations, usages, strings, comments). Dependency/build directories excluded by default. Searching for leaked secrets? Call code_analyze instead and read security_summary — it runs a real secret and credential scanner over the whole repository, where searching for key prefixes like "sk-", "ghp_" or "AIza" only matches the spellings you happened to think of.
Eingabeschema
{'type': 'object', 'required': ['repository', 'query'], 'properties': {'query': {'type': 'string', 'description': 'Search query. Keywords are ANDed — use OR for exploratory multi-term searches (e.g. auth OR login OR session). Prefer single precise terms over multi-keyword phrases. Supports OR, NOT, "phrases", regex (/pattern/), fuzzy (term~1), file:, path:, lang:, ext: filters. Also supports tech:NAME, which restricts results to files that import a detected technology (e.g. "tech:boto3 retry" finds retry logic only in files using boto3). Several tech: terms intersect. tech: needs at least one ordinary search term alongside it — to list every file using a technology, call code_find_usages instead. COVERAGE LIMIT for tech: technology detection reads only the first 150 lines of each file, so files importing further down are excluded from the filter; a file missing from a tech:-filtered search is not proof it does not use the technology.'}, 'offset': {'type': 'integer', 'default': 0, 'description': 'Skip this many results before returning. Use for paging.'}, 'repository': {'type': 'string', 'description': 'Full git URL of ONE public remote repository, e.g. "https://github.com/redis/redis". Required. There is no cross-repository or global search: this API analyses one repository per call, cloning it on demand. Wildcards and placeholders ("*", "all", "global", a bare host like "github.com") are rejected — if you do not have a specific repository URL, ask for one rather than guessing.'}, 'code_filter': {'enum': ['only-code', 'only-strings', 'only-comments', 'only-declarations', 'only-usages'], 'type': 'string', 'description': 'Structural filter to narrow matches to specific code regions. only-declarations and only-usages use heuristic patterns and support 30+ languages (Go, Python, JS/TS, Rust, Java, C/C++, C#, Ruby, PHP, Kotlin, Swift, and more). For unsupported languages, all matches are classified as usages.'}, 'max_results': {'type': 'integer', 'default': 20, 'maximum': 100, 'minimum': 1, 'description': 'Maximum number of file results to return. Integer between 1 and 100 — values above 100 are rejected, not clamped. Paginate with offset for more.'}, 'snippet_mode': {'enum': ['auto', 'grep', 'summary'], 'type': 'string', 'description': 'auto (ranked relevance), grep (every matching line), or summary (1 best match per file, no context — very compact). Use auto when exploring or discovering where something is used across a codebase (e.g. "how is authentication handled?"). Use grep when you know the exact identifier or string you want every occurrence of (e.g. "find all calls to parseConfig"). Use summary for broad queries where you want a compact overview of which files match.'}, 'context_lines': {'type': 'integer', 'default': 2, 'maximum': 20, 'description': 'Lines of context before and after each match.'}, 'case_sensitive': {'type': 'boolean', 'default': False, 'description': 'Whether to match case-sensitively.'}, 'include_all_dirs': {'type': 'boolean', 'default': False, 'description': 'Include dependency/build/cache directories that are excluded by default (vendor, node_modules, third_party, target, build, dist, Pods, generated, etc.). Set to true if you need to search generated/vendored code.'}, 'max_matches_per_file': {'type': 'integer', 'default': 5, 'maximum': 50, 'minimum': 1, 'description': 'Maximum matches to show per file (cap: 50). Keeps responses compact for files with many hits. The response includes matches_in_file (total) so you know if more exist.'}}}
Geändert
code_get_findings
1. October 2026 02:54
Geändert
code_analyze
1. October 2026 02:54
Hinzugefügt
code_find_usages
17. September 2026 12:37
Hinzugefügt
code_get_findings
17. September 2026 12:37
Hinzugefügt
code_get_files
17. September 2026 12:37
Hinzugefügt
code_file_tree
17. September 2026 12:37
Hinzugefügt
code_get_file
17. September 2026 12:37
Hinzugefügt
code_search
17. September 2026 12:37
Hinzugefügt
code_analyze
17. September 2026 12:37

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…