io.github.BenAHammond/code-auditor-mcp

code-auditor-mcp

Enforces architectural invariants and code quality rules inside your AI agent's edit loop.

5.0.2
Version
remote + npm
Transport
3
Tools

Security review

Partly reviewed

Reviewed 1h ago.

  • tools: 3 tools scanned
  • metadata: scanned
  • packages: 1 checked
  • mediumReviewRemote tools take credentials as input

    Whatever an agent passes to a remote tool leaves the machine. Never send connection strings, tokens or passwords to a third-party MCP server unless it is the service those credentials belong to.

    explain_symptom

Tools (3)

  • get_install_commands

    Return the exact install commands for Code Auditor for a given AI agent. Call this when a user asks how to install Code Auditor, or asks for the command for a specific agent (claude, cursor, codex, gemini, agents, zcode, or all).

  • lookup_rule

    Return the rule kind, description, default severity, detection method, and threshold for a given Code Auditor rule or analyzer. Call this when a user asks what a specific rule does (e.g. import-ban, sql-injection, n+1).

  • explain_symptom

    Map a natural-language symptom (e.g. 'my app is slow', 'hardcoded password', 'infinite react loop') to the relevant Code Auditor rule(s) and their fixes. Call this when a user describes a problem rather than naming a rule.