CodeHealth MCP
Integrates CodeHealth analysis into Slack with Block Kit UI, enabling users to trigger analyses and receive formatted results in channels or threads.
CodeHealth MCP
Codebase health analysis that works everywhere. Dead code, circular dependencies, coupling issues, and architectural drift — exposed as MCP tools for Claude Desktop, Cursor, Windsurf, and Slack.
The Problem
Dead code, circular dependencies, excessive coupling, and architectural drift are invisible in day-to-day work. Static analysis tools produce noise in CI dashboards nobody checks. CodeHealth MCP brings these insights into the tools developers actually use — via the Model Context Protocol.
Related MCP server: arch-viewer
What CodeHealth MCP Does
6 analysis tools, available in any MCP-compatible client:
Tool | What It Finds |
| Unused functions, classes, modules with file:line + fix suggestions |
| Module import cycles via DFS with impact assessment |
| Fan-out per module, tight cluster detection, refactoring suggestions |
| Layer boundary violations (UI→Data, Business→UI, etc.) |
| All four analyses + 0–100 health score + prioritized action items |
| AI-powered detailed explanation of any finding |
Where It Works
Client | How to Add |
Claude Desktop | Add to |
Cursor / Windsurf | Add to MCP settings |
Slack | Built-in Agent Builder integration with Block Kit UI |
Any MCP client | Standard MCP server (stdio) |
Install
npm install -g @cubiczan/codesentinel-mcp
npx -y @cubiczan/codesentinel-mcpMCP Registry: io.github.icohangar-ops/codesentinel-mcp
npm: @cubiczan/codesentinel-mcp 1.0.1
Claude Desktop / Cursor
{
"mcpServers": {
"codesentinel": {
"command": "npx",
"args": ["-y", "@cubiczan/codesentinel-mcp"]
}
}
}Quick Start (from source)
git clone https://github.com/icohangar-ops/codesentinel.git
cd codesentinel
npm install
cp .env.sample .env
npm startUse in Claude Desktop
Run a full health scan on /path/to/my/repoFind circular dependencies in the frontendCheck coupling metrics in src/servicesDaytona sandbox scans (optional)
Set DAYTONA_API_KEY (and optionally GITHUB_TOKEN for private repos). MCP tools and Slack analysis will shallow-clone GitHub URLs in a Daytona VM and return live import-graph findings instead of demo data.
full_health_scan repo_path=https://github.com/org/repoUse in Slack
Add the Slack app manifest, enable Agent Builder, and @CodeHealth in any channel.
Architecture
┌──────────────────────────────────────────┐
│ MCP CLIENT (any) │
│ Claude Desktop, Cursor, Slack, etc. │
└──────────────────┬───────────────────────┘
│ MCP Protocol (stdio)
┌──────────────────▼───────────────────────┐
│ CODEHEALTH MCP SERVER │
│ │
│ 🔧 analyze_dead_code │
│ 🔧 detect_circular_deps │
│ 🔧 analyze_coupling │
│ 🔧 detect_architectural_drift │
│ 🔧 full_health_scan │
│ 🔧 explain_finding │
│ │
│ ┌──────────────────────────────────┐ │
│ │ Analysis Engine │ │
│ │ dead-code | circular-deps │ │
│ │ coupling | drift │ │
│ └──────────────────────────────────┘ │
│ │
│ ┌──────────────────────────────────┐ │
│ │ LLM Provider │ │
│ │ Deepseek / OpenAI / Anthropic │ │
│ └──────────────────────────────────┘ │
└──────────────────────────────────────────┘Slack Integration
CodeHealth MCP ships with a full Slack Agent Builder app featuring:
Block Kit UI — Severity-coded findings, health scores, actionable suggestions
Thread-based conversations — Follow-up analysis in threads
Suggested prompts — One-click analysis triggers
MCP server — Same tools, available everywhere
Demo Sandbox (Devpost judges)
The live demo workspace is codehealthdemo.slack.com — the CodeSentinel agent (App ID A0BEHRDN5TQ) is installed and authorized there. Mention it in any channel:
@CodeSentinel run a full health scan on https://github.com/icohangar-ops/codesentinelSandbox configuration:
Live agent response in the sandbox — a real @CodeSentinel mention in #general triggering a Daytona-sandboxed repo scan:

App credentials & App ID | Agent capability enabled | Socket Mode enabled |
|
|
|
Adding Custom Analyzers
Each analyzer follows a simple interface:
function analyze(repoInfo) {
return {
type: "your_analysis_type",
findings: [
{
type: "finding_type",
severity: "critical" | "warning" | "info",
file: "path/to/file.ts",
line: 42,
name: "symbol_name",
reason: "Why this is a problem",
suggestion: "How to fix it",
},
],
stats: { /* summary metrics */ },
};
}Add a new analyzer in lib/analyzers/, register it in analysis-engine.js, and it's automatically available in Slack and via MCP.
Roadmap
Real AST analysis — ts-morph for TypeScript, tree-sitter for multi-language
GitHub App — Automatic analysis on PRs with inline comments
Historical trends — Track health score over time per repo
Custom architecture rules — Define layer boundaries via config
Team dashboards — Aggregate health in Slack Canvas
Project Structure
codesentinel/
├── app.js # Bolt app entry (Slack)
├── manifest.json # Slack app manifest
├── lib/
│ ├── analysis-engine.js # Analysis orchestrator + health score
│ ├── intent-parser.js # NLP intent classification
│ ├── block-kit-builder.js # Rich Slack UI
│ ├── llm-provider.js # Multi-provider LLM
│ └── analyzers/ # dead-code, circular-deps, coupling, drift
├── mcp-server/
│ ├── index.js # MCP server with 6 tools
│ └── package.json
└── functions/ # Slack function definitionsCommunity & Registry
MCP Registry — io.github.icohangar-ops/codesentinel-mcp
License
MIT. See LICENSE.
Available Tools
6 toolsanalyze_couplingA
Analyze coupling metrics across the codebase. Identifies modules with high fan-out (too many dependencies) and tightly coupled clusters.
| Name | Required | Description | Default |
|---|---|---|---|
| repo_path | No | Path or URL to the repository | |
| fan_out_threshold | No | Fan-out threshold for flagging modules |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the burden of disclosing behavior. It clearly states the tool identifies high fan-out and tightly coupled clusters, implying a read-only analysis, but it does not describe output format, repository access behavior, or any limitations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tightly worded sentences deliver purpose and output with no filler. The primary action is front-loaded, and every clause contributes meaning.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a 2-parameter tool with 100% schema coverage, the description gives enough context for an agent to select and invoke it correctly. It identifies what will be analyzed and what findings will be surfaced, though a bit more detail about the returned report would fully complete the picture.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, providing baseline 3. The description adds semantic value by explaining 'high fan-out' as 'too many dependencies,' which helps the agent understand the fan_out_threshold parameter's intent beyond the schema's terse label.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a specific verb and resource: 'Analyze coupling metrics across the codebase.' It further identifies concrete outputs (high fan-out modules, tightly coupled clusters), which clearly distinguishes it from siblings like analyze_dead_code and detect_circular_deps.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The phrase 'across the codebase' implies this is a whole-repository analysis tool and gives some sense of when to use it. However, it does not explicitly state when to prefer this over alternatives such as detect_circular_deps or detect_architectural_drift.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
analyze_dead_codeA
Analyze a codebase for dead code — functions, classes, and modules that are defined but never referenced. Returns findings with file paths, line numbers, severity, and fix suggestions.
| Name | Required | Description | Default |
|---|---|---|---|
| repo_path | No | Path or URL to the repository to analyze | |
| include_suggestions | No | Whether to include fix suggestions |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must disclose behavior. It mentions the detection criteria and the 'returns findings' structure, which indicates a read-only analysis. However, it does not disclose potential limitations such as language support, repository size constraints, or whether it modifies files. It adds some behavioral context but lacks depth.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, with the core purpose front-loaded in the first sentence. It avoids redundancy and every phrase conveys essential information (scope, detection target, output contents).
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description is concise but covers the key invocation details: input (repo_path), an optional toggle, and the expected output fields (file paths, line numbers, severity, fix suggestions). Given the tool's simplicity and full schema coverage, this is arguably sufficient, though it omits any guidance on language support or when to choose this over siblings.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Both parameters are already described in the schema with full coverage, so the baseline is 3. The description reinforces that include_suggestions controls fix suggestions, but adds no additional syntax or format details beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb 'Analyze' with resource 'codebase' for 'dead code' and specifies the kinds of dead code (functions, classes, modules) and that they are 'defined but never referenced.' This clearly distinguishes from sibling tools like detect_circular_deps or analyze_coupling, which focus on different aspects.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus siblings. It does not mention alternatives, exclusions, or prerequisites, leaving an agent to infer usage from the name and sibling titles alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
detect_architectural_driftB
Detect architectural drift — violations of intended layer boundaries (e.g., UI importing from data layer, reverse dependencies).
| Name | Required | Description | Default |
|---|---|---|---|
| repo_path | No | Path or URL to the repository | |
| layers_config | No | JSON string defining layer patterns, e.g. {"ui": ["src/components/"], "data": ["src/db/"]} |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are supplied, so the description carries the full burden of behavioral disclosure. It's a detect tool, which hints at read-only behavior, but it never states that explicitly, nor does it describe what the output looks like, whether it mutates anything, or how it uses the configured layers. For an analysis tool with zero annotations, this is insufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
One focused sentence with a concrete example. Front-loaded purpose, zero filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a complex analysis tool with no output schema and no annotations, this is thin. It doesn't clarify how layers_config is used, what the agent should pass, what the tool returns, or any prerequisites. With 100% schema coverage, the params are defined, but the tool's behavior and output are left unstated.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema already covers both parameters at 100%, so baseline 3. The description mentions layer boundaries but doesn't explicitly explain how repo_path and layers_config interact. It adds context but doesn't materially improve on the schema's example.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Detect') and a specific resource ('architectural drift'), then clarifies the exact nature with concrete examples (UI importing from data layer, reverse dependencies). This clearly distinguishes it from siblings like analyze_dead_code or detect_circular_deps, which target different defect classes.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies the tool should be used when checking layer-boundary violations, but it never explicitly says when to use it versus the sibling tools (detect_circular_deps, full_health_scan). It gives a clear purpose but no exclusions or conditions that would help an agent choose it over alternatives. It's adequate but not explicit.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
detect_circular_depsA
Detect circular dependencies between modules using DFS-based cycle detection. Returns cycles with involved files and impact assessment.
| Name | Required | Description | Default |
|---|---|---|---|
| repo_path | No | Path or URL to the repository |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are present, so the description carries the burden. It does disclose the algorithm (DFS-based cycle detection) and the return contents (cycles with involved files and impact assessment). However, it does not state whether the operation is read-only, whether it requires a local clone versus a URL, or what happens when repo_path is omitted.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences with no filler. The main action is front-loaded and the return-value summary is compact. Every part of the text earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple one-parameter tool, the description covers what it does and what it returns. Yet without an output schema or annotations it stays slightly incomplete: the fact that repo_path is not required is unexplained, and there is no mention of side effects or prerequisites. It is adequate but leaves a few gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The single parameter is fully described in the schema ('Path or URL to the repository'), so the description adds no extra parameter semantics. Baseline 3 applies; the description does not need to repeat what the schema already provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Detect'), a precise object ('circular dependencies between modules'), and even names the algorithm and return contents. It is clear and task-specific, but unlike a 5 it does not explicitly contrast itself with sibling analysis tools such as analyze_coupling.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no explicit when-to-use, when-not-to-use, or alternative routing. The intended use is only implied by the action word 'Detect'. An agent is given no guidance about when analyze_coupling or detect_architectural_drift would be more appropriate.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
explain_findingB
Get a detailed explanation of a specific code health finding, including why it matters, potential risks, and detailed remediation steps.
| Name | Required | Description | Default |
|---|---|---|---|
| finding_type | Yes | ||
| codebase_context | No | Additional context about the codebase (language, framework, etc.) | |
| finding_description | Yes | Description of the specific finding to explain |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the behavioral disclosure burden. It does convey that the tool is read-only ('Get') and what kind of content the explanation includes, which is useful. However, it does not disclose response format, behavior for unrecognized finding types, or whether the explanation is precomputed or generated, so significant behavioral detail is still missing.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with no filler. The core action is front-loaded, and the added clauses about risks and remediation steps are concise and informative.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description is minimally adequate: schema coverage provides parameter names and the description explains the return content. However, there is no mention of how this tool fits into a workflow with the sibling analysis tools, and there is no output schema to clarify the exact structure of the explanation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 67%, but the tool description adds no parameter-level meaning beyond the schema. It never names finding_type, finding_description, or codebase_context, and it does not explain how the enum values relate to the requested explanation. The phrase 'specific finding' only weakly maps to the required parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states a specific action ('Get a detailed explanation') on a specific resource ('a specific code health finding') and outlines the content of the explanation (why it matters, risks, remediation). It is not a tautology, and the 'explain' framing distinguishes it from the sibling analysis/detection tools, though it does not explicitly name that distinction.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives no explicit guidance on when to use this tool instead of the sibling tools like analyze_dead_code or full_health_scan. It does not state whether this tool should be used after a finding is reported, nor does it mention any exclusions or alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
full_health_scanA
Run a complete codebase health scan: dead code, circular dependencies, coupling metrics, and architectural drift. Returns an overall health score (0-100) and prioritized findings.
| Name | Required | Description | Default |
|---|---|---|---|
| repo_path | No | Path or URL to the repository |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations exist, so the description carries the behavioral burden. It clearly defines the operation as a scan, enumerates the analysis categories, and states the return contract: a 0–100 overall health score and prioritized findings. It does not mention side effects or repository-clone behavior for URLs, but for a read-only scanning tool the disclosed behavior is substantial.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, dense sentence that front-loads the core action and immediately states the output format. Every word contributes; there is no repetition or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a one-parameter tool with no output schema, the description adequately explains the return shape, but it leaves the relationship to the four sibling scanners implicit and says nothing about how an omitted repo_path should be handled even though the schema marks it optional. This is adequate but with clear gaps for an aggregation tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, and the sole parameter repo_path already has a clear description ('Path or URL to the repository'). The tool description adds no parameter-specific nuances, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description is specific and informative: it names a verb ('Run'), a resource ('complete codebase health scan'), and the four concrete scan dimensions (dead code, circular dependencies, coupling metrics, architectural drift). This clearly differentiates this aggregator from its single-concern siblings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The usage context is implied rather than explicit: the word 'complete' and the listed scan areas suggest this tool subsumes the sibling analyses, but it never states when to choose full_health_scan over analyze_dead_code, detect_circular_deps, or the others. No exclusion or alternative guidance is included.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
6 tool updates
v1.0.1- First observed
analyze_coupling - First observed
analyze_dead_code - First observed
detect_architectural_drift - First observed
detect_circular_deps - First observed
explain_finding - First observed
full_health_scan
TDQS
Each tool targets a distinct analysis concern: dead code, circular deps, coupling, architectural drift, combined scan, and explanation. No overlap in purpose; even full_health_scan is clearly a superset rather than a duplicative tool.
Naming follows a strong verb_noun pattern but mixes 'analyze' and 'detect' as starting verbs, plus 'full_health_scan' and 'explain_finding' break the strict pattern slightly. Still, all names are descriptive and predictable.
Six tools are well-scoped for a code health analysis server. Each tool covers a meaningful aspect, and the full scan consolidates several, avoiding redundancy.
The server covers the core analysis surface (dead code, circular deps, coupling, architecture) plus explanation and a comprehensive scan. Minor gaps like generating reports or managing ignore lists are not essential for the apparent scope.
Maintenance
Related MCP Connectors
AI-powered codebase analysis — call graphs, security, dead code, complexity. 150+ tools.
Code intelligence platform for AI agents. 20 tools for architecture, security & impact analysis.
AI code review for GitHub PRs with an MCP autofix loop for Claude Code and Cursor
AI-native git hosting — repos, PRs, issues, CI gates, and AI code review over MCP (60 tools).
Related MCP Servers
- AlicenseAqualityAmaintenanceCode dependency graph and AI context engine. 10 MCP tools that give Claude, Cursor, and any MCP client full codebase context — impact analysis, dependency tracing, architecture summaries, and interactive arc diagram visualization. Supports TypeScript, JavaScript, Python, and Go.241,80460Business Source 1.1
- AlicenseNot gradedqualityDmaintenanceProvides AI-powered architecture analysis and visualization of codebases, exposing 17 MCP tools for querying components, dependencies, and generating interactive diagrams.1MIT
- AlicenseNot gradedqualityCmaintenanceAI code analysis tools that plug into Claude Code, Cursor, VS Code, and any MCP client, providing six specialized tools for explaining code, debugging, code review, security audit, automation script generation, and MCP blueprint design.MIT
- FlicenseNot gradedqualityAmaintenanceAnalyzes repositories, explains architecture, calculates change impact, and enforces guardrails for AI Agents like Claude Code, Cursor, and Codex via MCP tools.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/icohangar-ops/codesentinel'
If you have feedback or need assistance with the MCP directory API, please join our Discord server


