static-analysis

80 servers · 5,763★ total

Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.

Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 285 commands, 244 MCP tools, change-safety gates, audit evidence, zero API keys.

Reverse engineer anything with agents, from app behavior down to native binaries.

Deterministic, local-first memory and guardrails for AI coding agents with no LLM in the hot path.

Graph-native code intelligence that replaces embedding-based RAG with deterministic program understanding.

MCP server that orchestrates language servers into agent-native workflows. 65 tools, 30 CI-verified languages.

MCP server for Slither static analysis of Solidity smart contracts

The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.

Free, MIT alternative to paid Django schema review. Blast radius on every PR, schema drift, N+1 across functions, ER diagrams, MCP server. No DB, no Django boot, no Pro tier.

MCP server for AI coding agents. Instead of reading files one by one, your agent gets dependency graphs, git intent, blast radius, and change health in a single call. Works with any language deep analysis for TypeScript,Java, Go, and C#.

The code quality toolkit for the agentic AI era. Find dead code, clones, and scaffolding across 15 languages. MCP server + CLI.

Local-first static analysis that turns source code into deterministic, source-grounded workflow maps for coding agents via MCP.

A Pure-Java MCP Server for JaDX Android Reverse Engineering Tool

MCP server with 23 tools for structured code understanding via tree-sitter. 10 languages. 999 tests. One-command install.

The immune system for AI coding agents

Local pre-flight linter and architecture gate for AI agents. Uses tree-sitter, Stack Graphs, and Datalog to mechanically block structural drift, layering bypasses, and scope creep on virtual ASTs before code changes land.

The testing standard for MCP servers. Lint (14 rules), test, and fuzz over real stdio/SSE/HTTP transport. 18 assertion types in YAML. Found 4,794 schema issues across 55 servers. Any language, no mocks, single binary.

MCP server for deep semantic analysis of Scala via SemanticDB — exact find-usages, class hierarchies, implicit resolution & call paths for AI coding agents like Claude Code. Beyond grep and standard LSP.

Deterministic CI scanner and surface-risk scoring for MCP (Model Context Protocol) servers.

A Go symbol and call-graph database backed by SQLite. Query symbols, callers, callees, blast radius, dead code, and interface implementors as structured JSON — typed code navigation for AI agents (MCP) and humans.

Semantic code intelligence for AI agents — compile repositories into navigable concept graphs with impact analysis, coupling detection, and prophecy.

OrangePro local-first CLI + MCP server for behavior mapping, grounded test generation, and dynamic proof.

🛡️ The security firewall for AI agent tools & MCP servers (Claude, GPT-5.6, Gemini 3.7, Antigravity, Cursor, Codex, Hermes). Catch command injection, secret theft & toxic flows in <50ms. 100% offline Rust SAST + 1-click auto-fix + SARIF.

Multi-agent orchestration, persistent memory, and intelligent workflows for AI coding assistants. Supports Claude Code, OpenCode and Codex.

Headless CLI reflection debugger for .NET assemblies with MCP server support

A live, graph-verified map of your codebase for AI coding agents — real call graphs, compiler-verified edges, and hard safety gates on the write path.

Multi-engine security scanner for AI agents, MCP servers & plugins — 13 engines, one report.

Model Context Protocol server for BlackDuck Coverity Connect static analysis platform

A MCP Debugger Server for Windows executables (x86 and x64). Exposes debugger functionality as MCP Tools for static / dynamic analysis of the debuggee and memory inspection through a clean interface.

Deterministic code-graph (GraphRAG) over your repo for LLM agents — local-first, git-native, zero-infra, served via MCP. Python, TS/JS, Rust, Go, Java, C#.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Local CLI that audits coding-agent configuration for security, instructions, context, and MCP — no API key or code upload by default.

Find and fix what the MCP 2026-07-28 spec revision breaks in your server. 21 rules, 5 autofixers, and a readiness board.

Self-maintaining and persistent codebase memory for AI coding agents — a deterministic AST index plus agent-written notes that flag themselves stale when the code changes. Works with Claude Code, Cursor, and Codex via MCP + CLI.

MCP C++ project indexer for fast symbol, module, and source-range navigation in large C++20 codebases.

Python

Code quality platform for Bazel monorepos — static analyzers as aspects, SARIF, quality gates

Open-source toolkit for 1C:Enterprise/BSL: 180 diagnostics, formatter, LSP, CLI, VS Code/Cursor extension, SARIF, MCP server, and RU/EN documentation.

Compiler truth in, AI context out. Open semantic glue between language intelligence and AI tools.

Cut AI-agent token waste ~90% — query a local SQLite structural index of your JS/TS/CSS codebase with SQL in one round-trip instead of 3–5 file reads. Symbols, imports, calls, components, CSS tokens, coverage, markers. CLI, MCP (21 tools), HTTP, GitHub Action, ESM API. 71 recipes; AST+resolver; SARIF/audit/baselines for CI.

MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.

Portal de arquitetura auto-hospedado + linguagem executável: catálogo verificado, landscape C4 com drill-in, governança (fitness functions e SLO por caminho crítico) e editor no browser. Binário Go único, com LSP, MCP e WebAssembly.

MCP server for analyzing and managing technical debt in codebases via the Model Context Protocol

MCP server that gives LLM agents deterministic access to IDA Pro: decompilation with CFG/data-flow evidence, cross-references, local-embedding semantic search, and an evidence-backed findings workspace.

MCP server that reverse-engineers architecture from code (Go, TypeScript, Python) and markdown into a structured graph. Detects drift between any two branches, tags, or commits

🛡️ Automated security scanner for MCP (Model Context Protocol) servers — 52 rules for prompt injection, credential exposure, SSRF & tool poisoning. pip install mcp-safeguard

Weld connected structure toolkit for agent-first repository discovery

First MCP for the Xahau network — offline Hook intelligence (WASM inspection + a Hooks-specific static-analysis rule engine), read-only ledger/codec/governance tools, and unsigned-tx builders. Read-only, no key custody.

Superpowers your agent's debugging: what introduced this bug, and is my fix actually complete? Deterministic, offline, read-only, MCP-native.

Engineering OS — a suite of Model Context Protocol (MCP) servers that bring engineering discipline to AI coding assistants: dependency & version governance, hallucination detection, security/architecture/QA/performance review, multi-agent code review, self-healing, and compliance.

AI code review agent MCP server. Reviews code like a kernel maintainer: blunt, technical, no sugarcoating. Detects bugs + OWASP Top 10 security vulnerabilities. 4 harshness levels. Anti-RLHF.

Local code intelligence graph for AI coding agents: Tree-sitter static analysis, structural code search, dependency impact, blast-radius analysis, CLI and MCP server.

Your app generates its own verified UI transition graph — screens as nodes, guarded (event, effect) edges. Proof-gated verification, trust tiers, model-free MCP for AI agents.

Offline MCP server for AI coding agents with semantic code search, symbol intelligence, dependency graphs, and safe file operations.

Elenchus MCP Server - Adversarial verification system for code review

MCP server that gives AI agents a local security scanner before they install or trust third-party tools.

Compression Runtime for Universal eXecution — a 60–95% token reducer for AI coding agents (Claude Code, Cursor, Cline, …). Single Rust binary, SQLite, 11 layers, local-first.

Public distribution surface for jarvis — local-first code intelligence MCP server (SCIP navigation + Zoekt search). Installer, Claude Code / Codex / Cursor plugins, and prebuilt binaries.

Turn any repo into a Code Knowledge Graph your coding agent can reason over — symbols, API routes, ORM models, architecture decisions & git history as a typed, provenance-tracked graph, served over MCP. Built on AgentForge.

The quality gate for the MCP ecosystem. Spec compliance, security scanning, and performance benchmarks for MCP servers.

Local graph memory for AI coding agents, giving MCP-compatible tools precise codebase context before they edit.

AI-powered repository intelligence platform with semantic code analysis, knowledge graphs, Model Context Protocol (MCP) support, FastAPI, Astro, and a VS Code extension.

Mobile app security analysis MCP server for Android APK and iOS IPA files

Native Weavatrix MCP for coding agents: 43 read-only repository-intelligence tools across 24 code and configuration surfaces, with typed evidence, impact, architecture, APIs, Git, search, semantics, and memory.

Static code map generator (MAP.md + map.json) powered by tree-sitter — a Claude Code /map plugin and MCP server that gives coding agents call graphs, file outlines, and impacted-test lookups without spending tokens on parsing.

Find and remove dead code in React, Next.js, and Python projects

MCP server for code structure analysis across 20+ languages. Tree-sitter powered. Works with Claude Code and Claude Desktop.

Persistent, semantically-searchable memory and a symbol-level code graph for AI coding agents. One static Rust binary — SQLite or PostgreSQL, MCP-compatible.

An open-source modeling language and static risk scanner for secure AI agents, MCP servers, and A2A integrations. Model agent boundaries before they act.

Production-ready context database and MCP server for AI assistants. Provides code intelligence with hybrid search, call graphs, impact analysis, and semantic search for Cursor, VS Code, and Claude Desktop. Docker-first, 248 languages, auto-indexing.

CLI-first, deterministic architecture intelligence. Builds an offline model of your repo to answer impact, cycles, dead code, duplication and security, and enforces your architecture as a contract in CI. No LLM in the loop; usable by coding agents over MCP or directly via CLI.

Offline repository and workspace maps, wikis, dependency graphs, and context artifacts with file:line provenance, zero runtime dependencies, and MCP.

Local MCP server that extracts high-level Git repository context for AI coding agents

Description: Local-first pre-commit policy guard for AI-agent repositories. Website: https://pypi.org/project/aigenguard/

AI Architect Codebase: cross-platform code intelligence MCP for Claude Code, Codex, Gemini, Cursor, VS Code, and Zed. Tree-sitter AST to LadybugDB graph, hybrid search, and impact analysis.

CodeGraphX (CGX) — a local, token-efficient codebase graph engine & MCP server for AI coding agents. Tree-sitter parsing, a bi-temporal SQLite semantic graph, O(1) symbol lookup, and impact/blast-radius tracing so agents answer 'what breaks if I change this?' in a few hundred tokens.

A Roslyn analyzer that catches prompt-injection and tool-poisoning in C# Model Context Protocol (MCP) server tool descriptions at build time. MCPGxxx diagnostics, code fixes, and a CI gate.

Turn any .NET test-automation solution into a queryable map in one SQLite file — features, steps, API clients, page objects, and their dependencies. Zero config, no AI, no network, 100% deterministic.

Local, deterministic code intelligence for developers and AI coding assistants — cited answers about symbols, callers, references, routes, and change impact, without dumping your repo into a context window.

Give any AI assistant real architectural understanding of a codebase — local, private, zero-config MCP serve