Mcp Server Codecov — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Server Codecov (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server that provides tools for querying Codecov coverage data. Supports both codecov.io and self-hosted Codecov instances with configurable URL endpoints.
📦 Published on npm: @egulatee/mcp-codecov 🐳 Docker image: ghcr.io/egulatee/mcp-server-codecov
📖 Learn More: Read about building this MCP server with AI in just 2 hours.
Get started in under 2 minutes:
Create an API token (not an upload token) from your Codecov account:
Add to your shell profile (~/.zshrc or ~/.bashrc):
export CODECOV_TOKEN="your-api-token-here"Then reload: source ~/.zshrc
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.io \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- npx -y @egulatee/mcp-codecovclaude mcp get codecovExpected output: codecov: @egulatee/mcp-codecov - ✓ Connected
That's it! You can now use Codecov tools in Claude Code. See Available Tools below.
Important: Codecov has two different types of tokens:
This MCP server requires an API token, not an upload token.
Get line-by-line coverage data for a specific file.
Parameters:
owner (required): Repository owner (username or organization)repo (required): Repository namefile_path (required): Path to the file within the repository (e.g., 'src/index.ts')ref (optional): Git reference (branch, tag, or commit SHA)Example:
Get coverage for src/index.ts in owner/repo on main branchGet coverage data for a specific commit.
Parameters:
owner (required): Repository ownerrepo (required): Repository namecommit_sha (required): Commit SHAExample:
Get coverage for commit abc123 in owner/repoGet overall coverage statistics for a repository.
Parameters:
owner (required): Repository ownerrepo (required): Repository namebranch (optional): Branch name (defaults to repository's default branch)Example:
Get overall coverage for owner/repo on main branchGet coverage data for a specific pull request, including coverage changes and file-level impact.
Parameters:
owner (required): Repository owner (username or organization)repo (required): Repository namepull_number (required): Pull request numberExample:
Get coverage for pull request #123 in owner/repoUse Cases:
Compare coverage between two git references (branches, commits, or tags).
Parameters:
owner (required): Repository owner (username or organization)repo (required): Repository namebase (required): Base reference (e.g., 'main', commit SHA)head (required): Head reference to compare against baseExample:
Compare coverage between main branch and feature-branch in owner/repoUse Cases:
Important Note: Before a repository can receive coverage uploads, it must be activated in Codecov. This is a one-time setup step that cannot be automated via API.
To activate a repository for coverage tracking:
Why manual activation is required: The Codecov API v2 does not provide a /activate endpoint. Repository activation must be done through the web UI or happens automatically on first coverage upload (depending on your Codecov configuration).
1. 401 Unauthorized Error
CODECOV_BASE_URL2. Environment Variable Not Expanding
~/.zshrc or ~/.bashrc)echo $CODECOV_TOKEN3. Connection Failed
echo $CODECOV_TOKENclaude mcp get codecov4. HTTP vs HTTPS
Always use https:// for the CODECOV_BASE_URL, not http://:
https://your-codecov-instance.comhttp://your-codecov-instance.comFor self-hosted Codecov instances, use your instance URL:
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.your-company.com \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- npx -y @egulatee/mcp-codecovAdd to your Claude Desktop configuration file:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"codecov": {
"command": "npx",
"args": ["-y", "@egulatee/mcp-codecov"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "your-codecov-token-here"
}
}
}
}Add to ~/.claude.json:
{
"mcpServers": {
"codecov": {
"command": "npx",
"args": ["-y", "@egulatee/mcp-codecov"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "${CODECOV_TOKEN}"
}
}
}
}Notes:
${VAR} syntax${CODECOV_TOKEN} will be read from your shell environment-y flag for npx automatically accepts the package installation promptPull and run the official multi-platform image from GitHub Container Registry:
docker run --rm -i \
-e CODECOV_TOKEN=your_token \
ghcr.io/egulatee/mcp-server-codecovPlatforms: linux/amd64 and linux/arm64 (Apple Silicon, AWS Graviton)
Claude Desktop (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"codecov": {
"command": "docker",
"args": [
"run", "--rm", "-i",
"-e", "CODECOV_TOKEN=your_token",
"ghcr.io/egulatee/mcp-server-codecov"
]
}
}
}With self-hosted Codecov:
docker run --rm -i \
-e CODECOV_TOKEN=your_token \
-e CODECOV_BASE_URL=https://codecov.your-company.com \
ghcr.io/egulatee/mcp-server-codecovAvailable tags: latest, 2, 2.1, 2.1.0 (full semver)
stdio bridge with socat:
The Docker image includes socat, which allows MCP clients that communicate over stdio to connect to the server running inside a container via a TCP socket:
# Start the server exposing a TCP port
docker run --rm -p 3000:3000 \
-e CODECOV_TOKEN=your_token \
ghcr.io/egulatee/mcp-server-codecov
# Bridge stdio ↔ TCP in a second terminal (or from your MCP client config)
socat TCP:localhost:3000 STDIONote:socatmust also be installed on the host machine running the bridge command. Install withbrew install socat(macOS),apt install socat(Debian/Ubuntu), orapk add socat(Alpine).
npm install -g @egulatee/mcp-codecovBenefits:
npm update -g @egulatee/mcp-codecovVerify installation:
npm list -g @egulatee/mcp-codecov
which mcp-codecov
npm view @egulatee/mcp-codecov versionOnly use this method if you're contributing to the project:
git clone https://github.com/egulatee/mcp-server-codecov.git
cd mcp-server-codecov
npm install
npm run buildThen configure with the built path:
Claude Code CLI:
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.io \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- node /absolute/path/to/codecov-mcp/dist/index.jsManual (`~/.claude.json`):
{
"mcpServers": {
"codecov": {
"command": "node",
"args": ["/absolute/path/to/codecov-mcp/dist/index.js"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "${CODECOV_TOKEN}"
}
}
}
}Claude Desktop:
{
"mcpServers": {
"codecov": {
"command": "node",
"args": ["/path/to/mcp-server-codecov/dist/index.js"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "your-codecov-token-here"
}
}
}
}This project maintains 97%+ code coverage with comprehensive unit tests using Vitest.
For detailed testing documentation, including how to run tests, coverage requirements, CI integration, and writing tests, see [TESTING.md](TESTING.md).
# Install dependencies
npm install
# Build the project
npm run build
# Watch mode for development
npm run watchThis project uses an automated release workflow via GitHub Actions. Releases are published to npm automatically when you push a version tag.
For detailed release instructions, including prerequisites, creating releases, manual releases, and version numbering, see [RELEASE.md](RELEASE.md).
This server uses Codecov's API v2. The API endpoints follow this pattern:
/api/v2/gh/{owner}/repos/{repo}/file_report/{file_path}/api/v2/gh/{owner}/repos/{repo}/commits/{commit_sha}/api/v2/gh/{owner}/repos/{repo}/api/v2/gh/{owner}/repos/{repo}/pulls/{pull_number}/api/v2/gh/{owner}/repos/{repo}/compare/{base}...{head}Currently supports GitHub repositories (gh). Support for other providers (GitLab, Bitbucket) can be added by modifying the API paths.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.