← Back to directory
C

Codescene MCP Server

Official
Expose CodeScene's Code Health analysis as local AI-friendly tools.
Category
Dev Tools #295 of 438
Stars
★ 68 Popular
Transport
stdio (local process)
Runtime
Node.js 18+ · Prebuilt binary
Credentials
Optional API key
License
Other / unspecified
Last commit
Tools
5
46FMRS · D

The CodeScene MCP Server provides AI assistants with code health analysis capabilities, emphasizing local execution and AI-friendly tools. It is suitable for teams combining AI development with code quality improvement, but requires a CodeScene account. Officially maintained with detailed documentation, it carries risks related to model dependency and configuration complexity.

Strongest · Documentation 13/20 Weakest · Maintenance 6/20

Reliability
7/20
Security and permissions
8/20
Maintenance
6/20
Documentation
13/20
Setup experience
12/20
Why each score
Reliability 7/20
Only README and manifest can be reviewed: the manifest is well-formed and declares an npm stdio package, and the README describes npx startup and tool use cases. However, no source code, CI, or tests are supplied; server version 1.1.0 mismatches npm package 0.3.1, and error/dependency behavior is unverifiable. Under static calibration, absent execution evidence caps reliability below 12, and uncertainty lowers it further.
Security and permissions 8/20
No red-line issue is evident: no real tokens in install examples, and the README claims token-based auth via CS_ACCESS_TOKEN, local analysis, and REST communication only with the user's own CodeScene account. However, no code-level audit, least-privilege/confirmation mechanism, or network-boundary implementation is available, so the claim cannot be fully verified and full marks are not justified.
Maintenance 6/20
The repository is not archived and the README implies releases, a version-update check, and multiple distribution channels; however, the License field is NOASSERTION and there is no verifiable commit cadence, dependency-update history, or security-response channel. These governance/licensing gaps lower the score.
Documentation 13/20
The README is layered and covers installation, authentication, use cases, FAQ, and links to tools.md and configuration-options docs. The supplied evidence lacks actual tool parameter schemas, limits, costs, or troubleshooting detail, and the referenced docs are only claims, so the documentation score is below maximum.
Setup experience 12/20
The README provides many installation paths (npx, Claude Code, Claude Desktop, VS Code, Homebrew, Windows, Docker) with straightforward commands and env-var auth. It lacks concrete client MCP JSON config examples, and the first-run binary download plus missing CI/test evidence make setup less reproducible; under static calibration it is capped at 15.

Static review · not runListed 2026-08-07

Read the FMRS scoring method →

Fit and risk

What it can accessReads local filesUses the network

Best for

  • Teams integrating AI-driven development with code quality analysis
  • Developers aiming to safely refactor legacy code with AI assistance
  • Organizations embedding code health checks in CI/CD pipelines

Not for

  • Users without a CodeScene account or standalone license (though a standalone Code Health MCP is available)
  • Scenarios requiring zero network dependency after setup (analysis is local but fetches data from CodeScene)
  • Teams needing a complete replacement for CodeScene's platform features

Required permissions

  • Requires CS_ACCESS_TOKEN to fetch data from a CodeScene instance
  • Read access to the local codebase for analysis
  • Volume mount for Docker installations to access code
  • Environment variables for custom SSL certificates (e.g., REQUESTS_CA_BUNDLE)
  • Can set CS_DISABLE_VERSION_CHECK to disable version checks

Risks and side effects

  • Transmission risk: Analysis results are fetched via REST from your own CodeScene account; source code is not sent externally, but token security is critical.
  • Dependency risk: A valid access token is required; token leakage could expose data.
  • Model limitations: Older models may not adhere to MCP constraints, affecting refactoring quality.
  • Path hallucination: IntelliJ's AI assistant may provide incorrect MCP paths, causing connection issues.

Setup

Before you start

Runtime:Node.js 18+ · Prebuilt binary

CS_ACCESS_TOKEN optionalsecret CodeScene personal access token that unlocks the full feature set (hotspots, technical debt goals, ownership); create it in your CodeScene Cloud or on-prem instance.
Other optional settings (4)
REQUESTS_CA_BUNDLE optional Path to an internal CA certificate file (PEM format) for custom SSL certificate setups.
SSL_CERT_FILE optional Alternative to REQUESTS_CA_BUNDLE, also pointing to a CA certificate file.
CURL_CA_BUNDLE optional Another alternative environment variable pointing to a CA certificate file.
CS_DISABLE_VERSION_CHECK optional Set to any non-empty value (e.g. 1) to disable the background GitHub version-update check.
  1. Obtain an access token: Create a personal access token in your CodeScene instance (CS_ACCESS_TOKEN).
  2. Choose installation method: Use npx (npx @codescene/codehealth-mcp), global npm, Homebrew (brew install cs-mcp), Windows script, manual download, or Docker (docker pull codescene/codescene-mcp).
  3. Configure your AI assistant: Add the MCP server to your assistant (e.g., Claude Desktop, VS Code).
  4. Copy the agent guidance file (AGENTS-full.md or AGENTS-standalone.md) to your repository, and add relevant skills.
  5. Verify the tools are available.

Check that it works

After installation, tools such as code_health_review and hotspots should appear in the client's tool list; alternatively, ask the AI to run a Code Health review on the current repository — receiving a score proves the connection works.

Troubleshooting

  1. Check that CS_ACCESS_TOKEN is set and valid.
  2. For Docker, ensure the correct code directory path is mounted.
  3. If using custom SSL certificates, set REQUESTS_CA_BUNDLE to your CA cert file.
  4. If IntelliJ gives wrong path, try manually specifying the correct MCP server path.
  5. Refer to docs for common issues like disabling version update check.

Things to try

Once connected, you can ask your AI assistant things like:

  • Run a Code Health review on this repository and point out the main maintainability issues.
  • List the hotspot files in this codebase along with their health scores.
  • Check our progress against the configured technical debt goals.
  • Compare the Code Health score before and after my change with a delta review to confirm the refactor helped.

Tools 5

code_health_review read-only
Performs a focused Code Health review on specified code segments, identifying design issues.
hotspots read-only
Lists hotspot areas in the codebase that are frequently changed and have high complexity.
technical_debt_goals read-only
Retrieves technical debt goals to prioritize tech debt reduction.
code_ownership read-only
Shows code ownership information to understand module responsibilities.
delta_review read-only
Reviews code changes to assess impact on code health.

Use cases

Safeguard AI-generated code: Prevent AI from introducing technical debt by flagging maintainability issues.
Uplift unhealthy code for AI readiness: Improve code modularity via focused Code Health reviews and incremental refactoring.
Make targeted refactoring: Use Code Health tools to determine what to fix and measure progress with updated scores.
Understand existing code before acting: Use Code Health reviews to inform AI-driven summaries and diagnostics.

Supported clients

Claude Desktop
VS Code
JetBrains IntelliJPartial support
GitHub Copilot
Cursor

Listed from the project's documentation, not tested by this site.

Overview

The CodeScene MCP Server exposes CodeScene's Code Health analysis as local AI-friendly tools for AI assistants like GitHub Copilot, Cursor, and Claude Code. It provides code health insights, including maintainability issues, complexity, and technical debt. The server runs fully locally, ensuring code and analysis data stay on-premises. Requires a CodeScene account or standalone license.

Similar servers

Context7 80 · B

Upstash's official server providing up-to-date third-party library docs for AI coding assistants

★ 62.9k · Tools 2 Compare with this →

Source revision 96aad9180a42 Data synced 2026-10-11 Read the FMRS scoring method