npm JavaScript not analyzable deep scan unknown

DeusData/codebase-memory-mcp

v0.11.0
npm

not analyzable — repository too large to unpack in full

Fast code intelligence for AI coding agents — installs a verified native runtime set

maintainer
DeusData
licence
MIT
first seen
2026-05-22
last seen
2026-09-18
releases · 30d
3
short id

DeusData/codebase-memory-mcp is an MCP server distributed on npm, maintained by DeusData, tracked here since May 2026. It has shipped 80 releases (currently 0.11.0) and exposes 14 tools. Tools include delete_project, detect_changes, get_architecture, get_code_snippet, get_graph_schema, index_repository, and 8 more. No risk grade is shown: the source hasn't been analyzed deeply enough to stand behind one.

what we found

Reading the source raised one review prompt — exfiltration combo — each a pattern worth a human look rather than a finding of fault.

Its 14 tools appear to reach filesystem, network and database, inferred from tool names, descriptions and input schemas rather than from observed behaviour.

Since the previous scan on 2026-09-15: 4 tools added and 4 tools removed.

full security breakdown →
tools 14
  • delete_project Remove a project and all its graph data.
  • detect_changes Map git diff to affected symbols + blast radius with risk classification.
  • get_architecture Codebase overview: languages, packages, routes, hotspots, clusters, ADR.
  • get_code_snippet Read source code for a function by qualified name.
  • get_graph_schema Node/edge counts, relationship patterns, property definitions per label. Run this first.
  • index_repository Index a repository into the graph. Auto-sync keeps it fresh after that.
  • index_status Check indexing status of a project.
  • ingest_traces Ingest runtime traces to validate HTTP_CALLS edges.
  • list_projects List all indexed projects with node/edge counts.
  • manage_adr CRUD for Architecture Decision Records (get reads, update replaces the whole document, set_sections rewrites only the named sections and le…
  • query_graph Execute Cypher-like graph queries (read-only).
  • search_code Grep-like text search within indexed project files.
  • search_graph Structural, BM25, and semantic search. Page structural rows with offset/limit and ranked semantic rows independently with semantic_offset/s…
  • trace_path BFS traversal — who calls a function and what it calls (alias: trace_call_path). Depth 1-5.
release cadence · 90d 36 releases
06-21 00:00 08-04 00:00 now
recent releases last 10
version date src
0.11.0 2026-09-15 npm
v0.11.0 2026-09-15 github
0.11.0 2026-09-15 pypi
v0.10.8 2026-08-19 github
0.10.8 2026-08-19 pypi
0.10.8 2026-08-19 npm
0.10.7 2026-08-18 github
0.10.7 2026-08-18 pypi
0.10.7 2026-08-18 npm
v0.10.6 2026-08-17 github

view all →