Best for
- Security teams that need local code-structure analysis and security scanning.
- Projects using Python, Dockerfiles, or Docker Compose.
- Development teams that want Claude Code, Cursor, or Cline to access call-graph and security analysis.
The supplied sources identify Code Pathfinder as an Apache-2.0 open-source security analysis MCP server, version 2.1.1, distributed through PyPI and OCI and using stdio transport. Its main capability is cross-file and cross-function dataflow and taint analysis. The sources do not provide concrete MCP tool identifiers, client configuration examples, or client authentication details.
Strongest · Documentation 13/20 Weakest · Reliability 8/20
Static review · not runListed 2026-08-14
Read the FMRS scoring method →Runtime:Python · Prebuilt binary · Docker
Install codepathfinder from PyPI, or use the manifest's Docker image docker.io/shivasurya/code-pathfinder:v2.1.1. Start the stdio server with pathfinder serve --project .; --project selects the project root to index and defaults to the current directory. The README also documents Homebrew, pre-built binaries, and building from source. Rules are downloaded automatically from a CDN, and the README states that no API keys or cloud accounts are required.
Run `pathfinder serve --project .`, then confirm the call graph, data flow, and security rule query tools from Code Pathfinder appear in the MCP tool list of Claude Code, Cursor, or Cline.
Once connected, you can ask your AI assistant things like:
Listed from the project's documentation, not tested by this site.
Code Pathfinder is an open-source static analysis and security scanning engine that can also run as an MCP server. It builds abstract syntax trees, call graphs, and variable dependency graphs for Python projects, then performs cross-file and cross-function dataflow and taint analysis. The README describes caller and callee queries, dataflow tracing, structural search, and security-rule scanning. The manifest also describes call graphs, type inference, and symbol search for Python/Go; the README marks Python, Dockerfiles, and Docker Compose as stable, while Go is coming soon.
Upstash's official server providing up-to-date third-party library docs for AI coding assistants
AI-powered NPM package analysis MCP server
An independent control layer that gives AI coding agents budgets, brakes, and receipts
GitHub's official MCP server for managing repos, issues, PRs, and workflows via natural language
Source revision 460d0d3b4d86 Data synced 2026-10-11 Read the FMRS scoring method