OpenCode Helper MCP
It is a local, read-only MCP server for code analysis in an allowed workspace, using a fixed chain of AI providers without letting clients choose endpoints or models.
analyze_code: runs the deterministic provider chain (native Mac Ollama, NVIDIA GPT-OSS, MiMo, Cloudflare) and returns sanitized provider statuses plus the analysis text.Provider-specific tools:
analyze_code_ollama,analyze_code_nvidia,analyze_code_mimo,analyze_code_cloudflare, and the schema also exposesanalyze_code_nemotronfor direct/diagnostic use.Read-only file operations: bounded tool loop using
list_files,search_text, andread_file; no shell access.Safety and scope: canonical path checks under allowed roots (default
C:\Develop; extendable viaOPENCODE_HELPER_ALLOWED_ROOTS), skips sensitive files, binaries, and hidden paths, rejects oversized files and symlink escapes.Budget-aware execution: clients choose
budgetMs; unused time is redistributed across providers without duplicate calls, and the output word cap is enforced locally.Sanitized failures: raw provider errors and credentials are never returned; a sanitized all-providers-failed status allows a direct Grok fallback by the caller.
Provides code analysis using Cloudflare Workers AI models (e.g., GLM-4.7-flash) via OpenCode, configured as the primary analysis provider with fallbacks to other services.
Provides code analysis using NVIDIA's Nemotron models via OpenCode, used as a fallback option when earlier providers fail or are insufficient.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@OpenCode Helper MCPAnalyze the code in C:\Develop\my-app for bugs"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
OpenCode Helper MCP
Local, read-only MCP server for code analysis. Normal callers use a single orchestrated tool; provider selection stays inside the server.
Tools
analyze_code: deterministic chain — native Mac Ollamaqwen3.8:27b-mlx, then NVIDIA GPT-OSS, then MiMo, then Cloudflare. After all fail, returns a sanitized all-providers-failed status so a direct Grok fallback is permitted.analyze_code_ollama: native Ollama only (diagnostic)analyze_code_nvidia: NVIDIAopenai/gpt-oss-20bvia OpenCodeplan/lowanalyze_code_mimo: OpenCodemimo-v2.5-freeanalyze_code_cloudflare: Cloudflare Workers AI@cf/zai-org/glm-4.7-flash
MCP input is only directory, prompt, and optional maxWords / budgetMs. Clients never pass endpoint, model, options, tools, or test mode.
Related MCP server: opencode-mcp
Native Ollama bridge
POST http://Zvis-MacBook-Pro.local:11434/api/chatIPv4 fallback
http://10.100.102.8:11434/api/chatonly on connection or address-family errorsFixed payload fields:
think: false,keep_alive: "30m",stream: falseNative Ollama final answers must contain the
## Analysismarker. Leaked reasoning tags are removed, incomplete fragments are rejected, and the requested output word cap is enforced locally before returning MCP text.Bounded read-only tool loop (no shell):
list_files,search_text,read_fileCanonical path checks under the allowed workspace; rejects traversal and symlink/reparse escapes
Skips
node_modules,.git,build,vendor, binaries, hidden paths, and common credential files such as.env,*.pem, andid_rsaRejects oversized files before a full read in
read_fileandsearch_textCaps rounds, files, bytes, context, output, and wall time; malformed, empty, unsafe, tool, and timeout errors fail the provider
OpenCode providers still launch opencode run with fixed arguments. NDJSON is accepted only with a valid final text event.
OpenCode child stdout and stderr are memory-bounded; MCP clients receive sanitized errors only. Timeouts and output limits terminate only the known child process tree.
Scope
By default, target folders must resolve canonically under C:\Develop, including Windows junction and symlink resolution. Set OPENCODE_HELPER_ALLOWED_ROOTS to a semicolon-separated list of additional allowed absolute paths if needed.
Callers choose budgetMs from request complexity (roughly 90 seconds focused, 180 seconds multi-file, or 270 seconds deep). The helper dynamically redistributes unused time across the fixed provider chain without duplicate provider calls.
Ollama receives half of focused and multi-file budgets, and two-thirds of a deep budget (180 seconds out of 270); unused time remains available to the fallback providers.
The orchestrated MCP result reports the successful provider and sanitized statuses for any previous attempts before the analysis text. It never includes raw provider errors or credentials.
Run locally
npm install
npm startTests
npm testAdd to Codex
codex mcp add opencodeHelper -- node C:\Develop\openCodeHelperMcp\src\index.jsOpen a new Codex task after adding the server. Remote OpenCode providers use credentials already stored by OpenCode; the helper does not store an API key. Native Ollama talks to the fixed Mac host above.
Available Tools
3 toolsanalyze_code_cloudflareAnalyze code with Cloudflare GLMA
Read-only code analysis using the fixed Cloudflare Workers AI GLM 4.7 Flash model at low reasoning effort. Use this first.
| Name | Required | Description | Default |
|---|---|---|---|
| prompt | Yes | The focused code-analysis question. | |
| directory | Yes | Absolute workspace path under an allowed root. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden, and it succeeds in an important way: 'Read-only' discloses the safety profile, while 'fixed model' and 'low reasoning effort' set expectations about determinism and output quality. It does not describe output format or potential rate limits, but for a read-only analysis tool this is reasonable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, zero filler. The core behavior is front-loaded and the usage directive is immediate. Every word earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a two-parameter read-only tool, the description gives model identity, safety profile, reasoning effort, and default usage priority. It is slightly thin on what the response looks like, but with 100% schema coverage and no output complexity this is acceptable.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the parameter meanings are already fully documented in the schema. The description adds no further param detail, so the baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states this is a read-only code analysis tool and identifies the exact model (Cloudflare Workers AI GLM 4.7 Flash). The phrase 'Read-only code analysis' gives a specific verb and resource, and the tool is differentiated from its siblings by being the recommended Cloudflare/GLM option.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'Use this first' provides explicit selection guidance, telling the agent this is the default among sibling analysis tools. It does not explain when to prefer analyze_code_mimo or analyze_code_nemotron, but the priority is clearly established.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
analyze_code_mimoAnalyze code with MiMo FreeA
Read-only code analysis using the fixed OpenCode MiMo V2.5 Free model at low reasoning effort. Use this after Cloudflare GLM fails or is insufficient.
| Name | Required | Description | Default |
|---|---|---|---|
| prompt | Yes | The focused code-analysis question. | |
| directory | Yes | Absolute workspace path under an allowed root. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Anontations are absent, and description carries the full burden. It discloses the important read-only nature of the operation and the low reasoning effort, a useful performance trait. It does not go into return maps or rate limits, but it does offer meaningful behavioral context beyond the bare schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The word I count is minimal, each sentence earns its place: the first defines the capability, the second defines the usage condition. The description is appropriately small, well-ordered, and holds no fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With only two well-sdhema'd parameters and no output schema, the description does not need to explain internals. However, some behavioral aspects such as return semantics or output format are not touched, which are minor for a read-analy analysis tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
He schema already has 100% coverage for both required parameters: 'prompt' has a focused question description and 'directory' a path description. The description adds no new semantic detail, so a baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description communicates a specific verb (analyze), a focused resource (code), and a specific model (fixed OpenCode MiMo V2.5 Free) with clarity and concision. By mentioning 'read-only' and naming Cloudflare GLM, it distinguishes itself from its primary sibling and provides a clear differentiation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It tells the agent exactly when to use it — after Cloudflare GLM fails or is insufficient — thereby providing a critical routing context. It does not explicitly mention the Nemotron sibling or exclude that alternative, which is a minor omission; hence the 4 rather than 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
analyze_code_nemotronAnalyze code with NVIDIA NemotronA
Read-only code analysis using the fixed NVIDIA Nemotron 3 Nano Omni model at low reasoning effort. Use this after MiMo fails or is insufficient.
| Name | Required | Description | Default |
|---|---|---|---|
| prompt | Yes | The focused code-analysis question. | |
| directory | Yes | Absolute workspace path under an allowed root. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full disclosure burden. It does convey 'read-only,' the fixed model, and low reasoning effort, which are meaningful behavioral details. It still lacks information about the tool's return format, error behavior, or failure modes, so transparency is incomplete.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two tightly written sentences with no filler. The core 'read-only code analysis' behavior is front-loaded, and the usage routing note follows efficiently.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a small 2-parameter read-only tool, the description provides adequate context for purpose and routing. The absence of an output schema and the lack of any description of what the result looks like means the behavioral contract is not fully complete. Still, the read-only nature and model selection details mitigate many concerns.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the input schema already fully documents the two parameters. The tool description adds no parameter-level detail, which is acceptable at the baseline of 3 but no more.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool performs read-only code analysis using a specific model, which goes beyond just restating the name. However, it does not explicitly distinguish itself from the Cloudflare sibling beyond the shared 'analyze_code' prefix, so differentiation is incomplete.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It explicitly says 'Use this after MiMo fails or is insufficient,' giving a clear when-to-use condition and naming one alternative. It does not mention the Cloudflare sibling, so the routing guidance is partial but still useful.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v0.1.0- First observed
analyze_code_cloudflare - First observed
analyze_code_mimo - First observed
analyze_code_nemotron
TDQS
The three tools share the same core operation—analyzing code at low reasoning effort—and differ only by backend model. Their descriptions include model names and a fallback order, but there is no distinct purpose-based choice; an agent can only distinguish them by which fallback step it happens to need.
All tools follow the consistent pattern analyze_code_<model>, with matchings-style and no mixing of verbs or argument formats. The naming is predictable and readable.
Three tools is not necessarily bloated, and the fallback approach justifies multiple endpooints. However, this functionality could just as easily be a single tool with model parameter, so the count is slightly inflated by the redundancy.
The server covers its narrow read-only code analysis goal by providing three fallback models. But beyond analyzing a snippet/no input, there is no capability for fetching code, changing analysis params, handling analysis output, or performing any related helper task, which leaves the surface limited.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Source-checked CLI guides and model-aware planning for Claude Code, Codex, and Grok Build.
Run verified read-only code tools: quant diagnostics + agent-ops preflight, no source exposure.
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
Related MCP Servers
- FlicenseAqualityCmaintenanceBridges Codex to external CLI coding agents for read-only code analysis and deterministic quality fixes.9-
- AlicenseNot gradedqualityBmaintenanceLets Claude Code delegate tasks to the OpenCode CLI, choosing cost-effective models by intelligence tier and tracking usage.23,488MIT
- AlicenseAqualityCmaintenanceAnalyzes a local codebase and exposes its structure, per-file summaries, dependency graph, and complexity hotspots as tools for MCP clients like Claude.4MIT
- AlicenseAqualityCmaintenanceEnables Codex to delegate coding tasks to an OpenCode CLI locally, returning structured results such as exit codes, session summaries, tool calls, and git diffs.2MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/segalz/openCodeHelperMcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server