Mcp Ast Explorer — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Ast Explorer (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- mcp-name: io.github.LovRanRan/mcp-ast-explorer -->
MCP server for deterministic Python codebase symbol exploration.
mcp-ast-explorer indexes Python source files with LibCST and exposes focused MCP tools for codebase onboarding: definition lookup, function signatures, local references, direct call chains, and simple class hierarchy queries.
mcp-ast-explorer is the semantic symbol layer in a three-server MCP tool stack for Project 6 wayfinder, a codebase onboarding agent.
mcp-repo-mapper maps repository structure, languages, entry points, framework evidence, and Python dependency edges.mcp-ast-explorer provides symbol-grounded Python definition, signature, reference, call-chain, and class-hierarchy lookups.mcp-test-runner runs local pytest/Jest checks and coverage summaries so agent claims can be verified against execution.In wayfinder, this server feeds entry-point and symbol explanation while refusing to invent missing symbols.
This is a Python-only v1. TypeScript is registered as an unsupported backend placeholder so the server has an explicit extension point, but TypeScript analysis is not implemented yet.
The server does not use an LLM for symbol lookup. If a requested symbol or class is not present in the parsed index, tools return a structured not-found result instead of inventing an answer.
| Tool | Purpose |
|---|---|
health() | Returns ok for smoke checks. |
find_definition(path, symbol, language="python") | Finds a module, class, function, or method definition. |
function_signature(path, symbol, language="python") | Returns the signature for a function or method symbol. |
find_references(path, symbol, language="python") | Returns same-module CST name references for an existing symbol. |
call_chain(path, from_symbol, depth=2, language="python") | Returns direct callers detected from local references. |
class_hierarchy(path, class_name, language="python") | Returns direct subclasses detected from simple base-class names. |
class Child(Base): inheritance.call_chain currently returns direct callers only; recursive multi-hop expansion is not implemented.class_hierarchy currently returns direct subclasses only and handles simple base names.Install dependencies:
uv sync --extra devRun the MCP server:
uv run mcp-ast-explorerRun verification:
uv run ruff check .
uv run mypy
uv run pytestMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.