← Back to directory
C

Code Pathfinder

Community
An MCP server for code intelligence and cross-file taint analysis for security teams.
Category
Dev Tools #199 of 438
Stars
★ 142 Popular
Transport
stdio (local process)
Runtime
Python · Prebuilt binary · Docker
Credentials
No credential needed
License
Apache-2.0
Last commit
54FMRS · D

The supplied sources identify Code Pathfinder as an Apache-2.0 open-source security analysis MCP server, version 2.1.1, distributed through PyPI and OCI and using stdio transport. Its main capability is cross-file and cross-function dataflow and taint analysis. The sources do not provide concrete MCP tool identifiers, client configuration examples, or client authentication details.

Strongest · Documentation 13/20 Weakest · Reliability 8/20

Reliability
8/20
Security and permissions
10/20
Maintenance
12/20
Documentation
13/20
Setup experience
11/20
Why each score
Reliability 8/20
The manifest provides version-pinned PyPI and OCI stdio installation paths and declares the serve command and --project argument, making startup plausible statically. The README claims call-graph, data-flow, pattern-search, and security-rule tools, but provides no evidence for MCP initialization, tool enumeration, error handling, or tests covering key server paths. The manifest describes Python/Go while the README labels Go as coming soon, so points are deducted.
Security and permissions 10/20
The server is presented primarily as a local project indexer and static analyzer; the supplied material shows no credential theft, destructive write, or default remote-command behavior, and no API key is required. Rules are automatically downloaded from a CDN, and the README states that anonymous usage metrics exist; metrics can be disabled, but network access, upload boundaries, rule integrity verification, file permissions, least-privilege tool scope, and confirmation of dangerous operations are not documented. This supports only a mid-range score.
Maintenance 12/20
The repository is not archived and provides version 2.1.1, an Apache-2.0 license, a GitHub Actions build badge, contribution guidance, a CLA, and issue/discussion channels, indicating some maintenance and governance foundation. The supplied material does not verify commit cadence, dependency updates, sustained release practice, issue response, or a clearly documented security-response channel, so points are deducted.
Documentation 13/20
The README covers installation methods, scan examples, MCP startup, rules, output formats, supported scope, and GitHub Action inputs, providing substantial usage material. It lacks a complete mainstream-client configuration, itemized MCP tool and parameter documentation, resource or performance limits, detailed network and metrics behavior, troubleshooting, and verifiable MCP tests. The inconsistent Go support statements also reduce confidence, so the score is not near full marks.
Setup experience 11/20
Homebrew, pip, Docker, prebuilt binaries, and source-build paths are provided, while the manifest specifies versioned PyPI/OCI packages and stdio transport. The supplied material does not include complete connection configuration for Claude Code, Cursor, or another mainstream client, nor does it explain platform runtime prerequisites, Docker MCP configuration, or common failure recovery. Automatic rule downloads and undocumented network dependencies add setup uncertainty.

Static review · not runListed 2026-08-14

Read the FMRS scoring method →

Fit and risk

What it can accessReads local filesUses the network

Best for

  • Security teams that need local code-structure analysis and security scanning.
  • Projects using Python, Dockerfiles, or Docker Compose.
  • Development teams that want Claude Code, Cursor, or Cline to access call-graph and security analysis.

Not for

  • Projects requiring proven stable Go analysis support; the README lists Go as coming soon.
  • Use cases requiring only general language-server functionality without security or code-structure analysis.
  • Integrations that require source-listed MCP tool identifiers or a client-specific configuration example.

Required permissions

  • Needs to read and index source code and configuration files under the selected project root.
  • When remote rulesets are used, it needs to download rules; the README says rules are fetched automatically from a CDN.
  • No API keys or cloud accounts are required according to the README.

Risks and side effects

  • Results depend on supported languages, selected rulesets, and code structure; the README marks only Python, Dockerfiles, and Docker Compose as stable.
  • Providing a project to the analyzer allows it to process source code and configuration contents in that project.
  • Automatic CDN rule downloads depend on external network availability.

Setup

Before you start

Runtime:Python · Prebuilt binary · Docker

Install codepathfinder from PyPI, or use the manifest's Docker image docker.io/shivasurya/code-pathfinder:v2.1.1. Start the stdio server with pathfinder serve --project .; --project selects the project root to index and defaults to the current directory. The README also documents Homebrew, pre-built binaries, and building from source. Rules are downloaded automatically from a CDN, and the README states that no API keys or cloud accounts are required.

Check that it works

Run `pathfinder serve --project .`, then confirm the call graph, data flow, and security rule query tools from Code Pathfinder appear in the MCP tool list of Claude Code, Cursor, or Cline.

Troubleshooting

  1. Verify that codepathfinder is installed and start the stdio server with pathfinder serve --project ..
  2. Verify that --project points to the intended project root and that the directory is readable.
  3. Check network connectivity for rule downloads and confirm that the selected ruleset name is valid.
  4. If coverage is unexpected, verify whether the target language is within the README's stated stable support.

Things to try

Once connected, you can ask your AI assistant things like:

  • Find all functions that call cursor.execute
  • Trace how user input flows across files into database queries
  • Run the PYTHON-DJANGO-SEC-001 rule on my project
  • Search for all call sites of request.GET.get

Use cases

Query call graphs, symbols, and data flows during AI-assisted code review.
Trace user-controlled input across files into security-sensitive sinks such as SQL execution.
Run security rules for Python, Dockerfiles, and Docker Compose.
Create custom Python security rules using the dataflow analysis engine.

Supported clients

Claude CodePartial support
CursorPartial support
ClinePartial support

Listed from the project's documentation, not tested by this site.

Overview

Code Pathfinder is an open-source static analysis and security scanning engine that can also run as an MCP server. It builds abstract syntax trees, call graphs, and variable dependency graphs for Python projects, then performs cross-file and cross-function dataflow and taint analysis. The README describes caller and callee queries, dataflow tracing, structural search, and security-rule scanning. The manifest also describes call graphs, type inference, and symbol search for Python/Go; the README marks Python, Dockerfiles, and Docker Compose as stable, while Go is coming soon.

Similar servers

Context7 80 · B

Upstash's official server providing up-to-date third-party library docs for AI coding assistants

★ 62.9k · Tools 2 Compare with this →

Source revision 460d0d3b4d86 Data synced 2026-10-11 Read the FMRS scoring method