codegraphcontext — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited codegraphcontext (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
cgc, choose a database backend, or wire MCP into an editor.codegraph_find_code, analyze_code_relationships, add_code_to_graph, etc.pip install codegraphcontext (or pipx install codegraphcontext). With uv, uv tool install codegraphcontext or uvx codegraphcontext … is supported; if a parser fails with ModuleNotFoundError: tree_sitter_c_sharp, run with an explicit extra package, e.g. uvx --with tree-sitter-c-sharp codegraphcontext ….~/.codegraphcontext/.env for DEFAULT_DATABASE, Neo4j URI, or Kùzu path. Run cgc doctor if connections fail.cgc index . (or cgc index --force . to rebuild). Ensure CLI and MCP use the same config so they see the same graph.cgc find, cgc query, …) or MCP tools after cgc mcp setup / cgc mcp start in the client config.cgc mcp setup and pick the editor, or add a server entry that runs cgc with args mcp start and the same env as the CLI.cgc with arguments mcp, start (same as other editors). Official OpenCode MCP overview: OpenCode MCP servers.Repository nodes (see Neo4j example in logs) if it keeps happening.codegraphcontext.cli.maincodegraphcontext.server, tool_definitions.pydocs/docs/setup_workflows.md, docs/docs/guides/mcp_guide.mddocs/docs/agent_skill_codegraphcontext.md~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.