Code Scanner Server
code-scanner-server
Una herramienta CLI y un servidor MCP que escanea archivos de código en busca de definiciones (clases, funciones, etc.), respeta .gitignore, proporciona números de línea y genera formatos compatibles con LLM (XML/Markdown).
Este proyecto proporciona una herramienta versátil de escaneo de código desarrollada con TypeScript y Node.js. Utiliza la biblioteca de análisis Tree-sitter para analizar el código fuente y extraer información estructural. Puede funcionar como herramienta de interfaz de línea de comandos (CLI) y como servidor MCP (Protocolo de Contexto de Modelo).
Nota: Esta herramienta se encuentra en desarrollo activo. Si bien la funcionalidad principal está operativa, es posible que algunas características o analizadores de lenguaje específicos no estén completamente probados y presenten errores o limitaciones.
Características
Extracción de definición de código: identifica funciones, clases, variables, interfaces, métodos, etc.
Compatibilidad con varios idiomas: analiza JavaScript (
.js,.jsx), TypeScript (.ts,.tsx), C# (.cs), PHP (.php), CSS (.css) y Python (.py) a través de Tree-sitter..gitignore Aware: respeta automáticamente las reglas definidas en los archivos
.gitignore.Filtrado flexible: filtre los resultados por tipo de definición, modificadores (
public,private), patrones de nombre (expresiones regulares) y patrones de ruta de archivo.Múltiples formatos de salida: genera resultados en Markdown (predeterminado), XML o JSON.
Niveles de detalle configurables: Nivel de verbosidad de salida:
minimal,standard(predeterminado),detailed.Operación en modo dual: Ejecútelo como una herramienta CLI independiente o como un servidor MCP integrado.
Related MCP server: Axon.MCP.Server
Modos de uso
1. Interfaz de línea de comandos (CLI)
Ejecute el escáner directamente desde su terminal. Este modo requiere el argumento --directory , que especifica el código base de destino.
Uso básico:
node build/index.js --directory /path/to/your/codebaseOpciones comunes:
-d, --directory <path>: (Obligatorio) Ruta absoluta o relativa al directorio a escanear.-p, --patterns <patterns...>: Patrones globales para extensiones de archivo (p. ej.,"**/*.ts"``"**/*.js"). El valor predeterminado son archivos JS, TSX, CS, PHP, CSS y PY.-f, --format <format>: Formato de salida (xml,markdown,json). Predeterminado:markdown.-l, --detail <level>: Nivel de detalle (minimal,standard,detailed). Predeterminado:standard.--include-types <types...>: incluye solo tipos de definición específicos (por ejemplo,class,method).--exclude-types <types...>: Excluye tipos de definición específicos.--include-modifiers <modifiers...>: solo incluye definiciones con modificadores específicos (por ejemplo,public).--exclude-modifiers <modifiers...>: Excluye definiciones con modificadores específicos.--name-pattern <regex>: incluye definiciones que coincidan con un patrón de expresión regular de JavaScript.--exclude-name-pattern <regex>: excluye definiciones que coincidan con un patrón de expresión regular de JavaScript.--include-paths <paths...>: Patrones de rutas de archivos adicionales (glob) para incluir.--exclude-paths <paths...>: Patrones de rutas de archivo (glob) a excluir.-h, --help: Muestra información de ayuda detallada para todas las opciones.
Ejemplo (Escanear archivos TypeScript en src , generar JSON detallado):
node build/index.js -d ./src -p "**/*.ts" -f json -l detailed2. Modo de servidor MCP (herramienta scan_code )
Si se ejecuta sin el argumento --directory , la herramienta se inicia como un servidor MCP, escuchando solicitudes mediante entrada/salida estándar. Esto permite la integración con clientes MCP, como asistentes de IA.
Nombre de la herramienta:
scan_codeDescripción: Escanea un directorio específico en busca de archivos de código y devuelve una lista de definiciones según los filtros proporcionados.
Esquema de entrada: Acepta argumentos correspondientes a las opciones de la CLI. La propiedad
directoryes obligatoria.{ "type": "object", "properties": { "directory": { "type": "string", "description": "Absolute path to the directory to scan." }, "filePatterns": { "type": "array", "items": { "type": "string" }, "description": "Glob patterns for files.", "default": ["**/*.js", ..., "**/*.py"] }, "outputFormat": { "type": "string", "enum": ["xml", "markdown", "json"], "default": "markdown" }, "detailLevel": { "type": "string", "enum": ["minimal", "standard", "detailed"], "default": "standard" }, "includeTypes": { "type": "array", "items": { "type": "string" } }, "excludeTypes": { "type": "array", "items": { "type": "string" } }, "includeModifiers": { "type": "array", "items": { "type": "string" } }, "excludeModifiers": { "type": "array", "items": { "type": "string" } }, "namePattern": { "type": "string", "description": "Regex pattern for names." }, "excludeNamePattern": { "type": "string", "description": "Regex pattern to exclude names." }, "includePaths": { "type": "array", "items": { "type": "string" } }, "excludePaths": { "type": "array", "items": { "type": "string" } } }, "required": ["directory"] }Ejemplo de uso con AI Assistant: "Utilice code-scanner-server scan_code en el directorio /path/to/project generando salida en formato xml".
Instalación
Requisitos previos: asegúrese de tener Node.js y npm instalados.
Clonar (opcional): si no tiene el código, clone el repositorio.
# git clone <repository_url> # cd code-scanner-serverDependencias de instalación:
npm installCompilación: compila el código TypeScript.
npm run buildEsto crea el archivo JavaScript ejecutable en
build/index.js.
Configuración (Servidor MCP)
Para utilizar el modo de servidor MCP, agréguelo al archivo de configuración de su cliente MCP (por ejemplo, claude_desktop_config.json para la aplicación de escritorio o cline_mcp_settings.json para la extensión VS Code).
Importante: reemplace /path/to/code-scanner-server en el siguiente ejemplo con la ruta absoluta al directorio de este proyecto en su sistema.
Ejemplo ( claude_desktop_config.json / cline_mcp_settings.json ):
{
"mcpServers": {
"code-scanner-server": {
"command": "node",
"args": [
"/absolute/path/to/your/code-scanner-server/build/index.js" // <-- Replace this path! (e.g., "C:\\Users\\YourUser\\Projects\\code-scanner-server\\build\\index.js" on Windows)
],
"env": {},
"disabled": false,
"autoApprove": [] // Add tool names here for auto-approval if desired
}
}
}Recuerde reiniciar su aplicación cliente MCP (IDE, aplicación de escritorio) después de modificar la configuración para que los cambios surtan efecto.
Desarrollo
Modo de observación: reconstruye automáticamente el proyecto cuando cambian los archivos de origen:
npm run watchDepuración (Modo MCP): Depurar servidores MCP con stdio puede ser complejo. Utilice la herramienta Inspector de MCP para una depuración más sencilla.
npm run inspectorEsto inicia el servidor con el inspector Node.js adjunto y proporciona una URL para conectar herramientas de depuración (como Chrome DevTools).
Expresiones de gratitud
Este proyecto se desarrolló significativamente con la ayuda de IA, principalmente utilizando el modelo Gemini 2.5 Pro de Google al que se accede a través de la extensión Roo Code para Visual Studio Code.
Licencia
Este proyecto está licenciado bajo la Licencia Pública General GNU v3.0 - consulte el archivo LICENCIA para obtener más detalles.
Available Tools
1 toolscan_codeA
Scans a directory for code files (JS, TS, C#, PHP, CSS, respecting .gitignore) and lists definitions (functions, classes, etc.) with line numbers. Supports XML, Markdown, and JSON output.
| Name | Required | Description | Default |
|---|---|---|---|
| detailLevel | No | Level of detail to include in the output. | standard |
| directory | Yes | The absolute path to the directory to scan. Relative paths are not supported. | |
| excludeModifiers | No | Modifiers to exclude. | |
| excludeNamePattern | No | Regex pattern to exclude element names. | |
| excludePaths | No | File path patterns to exclude. | |
| excludeTypes | No | Element types to exclude. | |
| filePatterns | No | Glob patterns for file extensions to include. | |
| includeModifiers | No | Modifiers to include (e.g., public, private). | |
| includePaths | No | Additional file path patterns to include. | |
| includeTypes | No | Element types to include (e.g., class, method). | |
| namePattern | No | Regex pattern to match element names. | |
| outputFormat | No | Output format for the results. | markdown |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It effectively describes key behaviors: it scans directories, respects .gitignore, lists definitions with line numbers, and supports multiple output formats. However, it does not mention performance aspects (e.g., speed, memory usage), error handling, or whether it's read-only (implied but not stated). The description adds substantial value beyond the schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is appropriately sized and front-loaded, with a single sentence that efficiently conveys the core functionality (scanning, listing definitions) and key features (supported languages, .gitignore respect, output formats). Every part earns its place without redundancy or unnecessary detail.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the complexity (12 parameters, no output schema, no annotations), the description is reasonably complete. It covers the main action, supported file types, filtering behavior (.gitignore), and output options. However, it lacks details on return values (since no output schema) and could mention more about error cases or limitations. It's sufficient but not exhaustive.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description coverage is 100%, so the schema already documents all 12 parameters thoroughly. The description does not add specific parameter semantics beyond what the schema provides (e.g., it mentions output formats but doesn't elaborate on parameter interactions). Baseline score of 3 is appropriate as the schema does the heavy lifting, and the description does not compensate with extra insights.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('scans', 'lists') and resources ('directory for code files', 'definitions with line numbers'). It distinguishes what it does by specifying supported languages (JS, TS, C#, PHP, CSS), respect for .gitignore, and output formats (XML, Markdown, JSON). No sibling tools exist, but the description is comprehensive enough to stand alone.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage context by mentioning 'scans a directory for code files' and output formats, but does not explicitly state when to use this tool versus alternatives. Since there are no sibling tools, this is less critical, but it lacks guidance on prerequisites (e.g., directory accessibility) or exclusions. The implied context is adequate but not explicit.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
1 tool update
v1.0.0- First observed
scan_code
TDQS
With only one tool, there is no possibility of ambiguity or overlap between tools. The tool 'scan_code' has a clear, distinct purpose focused on scanning code files and listing definitions, making it impossible for an agent to misselect between non-existent alternatives.
The single tool name 'scan_code' follows a verb_noun pattern, which is consistent and predictable. Since there is only one tool, there are no deviations or mixed conventions to evaluate, resulting in perfect naming consistency.
A single tool is too few for a server named 'Code Scanner Server', which implies a broader scope of code analysis operations. While 'scan_code' is comprehensive, the lack of additional tools (e.g., for filtering results, analyzing specific file types, or managing scans) makes the set feel thin and underdeveloped for the apparent domain.
The tool set is severely incomplete for a code scanning domain. It covers scanning and listing definitions but lacks essential operations such as filtering results, analyzing code quality, detecting vulnerabilities, or integrating with version control. This creates significant gaps that will likely cause agent failures when trying to perform comprehensive code analysis tasks.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
An MCP server that gives your AI access to the source code and docs of all public github repos
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
An MCP server that provides tools to discover and retrieve podcast episodes transcripts.
Related MCP Servers
- AlicenseCqualityDmaintenanceA MCP server that transforms code repositories from GitHub, GitLab, or local directories into LLM-friendly formats, preserving context and structure for better AI processing.311Apache 2.0
- FlicenseNot gradedqualityDmaintenanceAn MCP server that transforms codebases into intelligent, queryable knowledge bases, enabling AI assistants to perform semantic search, explore architecture, and analyze code relationships.166-
- AlicenseNot gradedqualityCmaintenanceAn MCP server that provides ultra-efficient code exploration through AST analysis, reducing LLM token usage by up to 95% while enabling instant call graph generation and dependency analysis for massive codebases.MIT
- AlicenseAqualityDmaintenanceUniversal MCP server that analyzes any codebase and provides structured context to AI assistants. Dynamic, accurate, and token-efficient.1814MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Ixe1/code-scanner-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server