code-auditor-mcp
Enforces architectural invariants and code quality rules inside your AI agent's edit loop.
- 5.0.2
- Version
- remote + npm
- Transport
- 3
- Tools
Security review
Partly reviewedReviewed 1h ago.
- tools: 3 tools scanned
- metadata: scanned
- packages: 1 checked
- mediumReviewRemote tools take credentials as input
Whatever an agent passes to a remote tool leaves the machine. Never send connection strings, tokens or passwords to a third-party MCP server unless it is the service those credentials belong to.
explain_symptom
Tools (3)
get_install_commands
Return the exact install commands for Code Auditor for a given AI agent. Call this when a user asks how to install Code Auditor, or asks for the command for a specific agent (claude, cursor, codex, gemini, agents, zcode, or all).
lookup_rule
Return the rule kind, description, default severity, detection method, and threshold for a given Code Auditor rule or analyzer. Call this when a user asks what a specific rule does (e.g. import-ban, sql-injection, n+1).
explain_symptom
Map a natural-language symptom (e.g. 'my app is slow', 'hardcoded password', 'infinite react loop') to the relevant Code Auditor rule(s) and their fixes. Call this when a user describes a problem rather than naming a rule.