jscpd
Duplicate code detector for 220+ languages with an MCP server for agents and a token-efficient report
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- The tool only reads project files and never modifies them
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/jscpdDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
npm install -g jscpdInstall the tool with npm install -g jscpd (or run npx jscpd . once without installing). For MCP mode run jscpd --mcp /path/to/project and connect it as a local stdio MCP server.
Other ways from the author
npm install -g jscpdInstalls the jscpd command, a prebuilt binary that needs no Node.js runtime.
This is third-party code. Review the repository files before installing.
What it does
jscpd tokenizes code following each language's own rules for strings and comments, then finds duplicated token sequences across files with a Rabin-Karp hash. Beyond copy-paste, it can find dead code, rank files by complexity and track duplication trends across git history. A dedicated flag starts a built-in MCP server over stdio so an agent can check a code snippet for duplication or look for structurally similar functions on its own.
Who it is for. For developers and code-quality engineers who want to find duplication and dead code by hand or through an agent.
Good fit when
- You need to check a project for duplicate code before merging
- An agent should check a code snippet for matches before refactoring
- You need to wire duplication checks into CI as a GitHub Action
Not a fit when
- You need static analysis of logic bugs rather than code matches
- Your file format is not among the 224 supported ones
Example request
Find and fix code duplication in this codebaseLimitations
The tool only reads the project source and never edits anything itself. MCP mode scans once at startup and keeps the result in memory, so start time can be noticeable on very large monorepos.
How to disable. Remove the package: npm uninstall -g jscpd (or cpd if installed under that name), or remove the binary installed via Homebrew, Cargo or the Docker image.
Security check
- The tool only reads project files and never modifies them
README in short
The README describes jscpd as a duplicate code detector for 220+ languages with a Rust engine, distributed as a self-contained binary via npm, PyPI, Cargo, Homebrew, Nix or Docker. Beyond copy-paste detection, it computes dead code, file complexity, duplication trends over git history, and one overall health score. It also documents an AI mode: a token-efficient report for LLM pipelines and a built-in stdio MCP server. MIT licensed.
FAQ
Do I need Node.js to run it?
No, starting with version five jscpd is a self-contained Rust binary; Node.js is only needed if you install it via npm.
How does MCP mode differ from a normal scan?
The jscpd --mcp command scans the project once and starts an MCP server over stdio, so an agent can check individual snippets for duplication and look for similar functions on demand.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything