bsl-ls-mcp
An MCP wrapper over the BSL Language Server: 1C code diagnostics, call search, definitions and method complexity across the whole configuration
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- Only reads and statically analyzes the 1C sources, never writes to the database
- The local unauthenticated HTTP port needs to stay closed to the network
Install
Manual install
set BSL_WORKSPACE=C:\1c\src\cf
run.cmd --selftest
run.cmdRunning the ready dist\bsl-ls-mcp bundle, starts a streamable-http server on port 8081.
This is third-party code. Review the repository files before installing.
What it does
The server runs a daemon that indexes a 1C configuration export in CR format (the src/cf folder) and exposes seven tools over MCP: diagnostics for a module or an arbitrary file outside the configuration, finding callers and callees, jumping to a definition, finding all usages of a method, scoring cognitive and cyclomatic complexity, and a full corpus reindex. Objects are addressed by their full 1C name, like ОбщийМодуль.ОбщегоНазначения.Метод, while code outside the configuration, such as external processing, is addressed via a path parameter. Diagnostics work without an index in 5-8 seconds, and the first navigation call waits about a minute and a half for the graph to build, then responds instantly.
Who it is for. For 1C developers and reviewers who need static BSL analysis and navigation across a large configuration directly from an agent.
Good fit when
- You need to check a module or external processing for errors and outdated constructs before submitting
- You need to see who calls a function and what it calls before changing it
- You need method complexity scoring for a code review
Not a fit when
- You have no CR source export of your 1C configuration or the roughly 14 GB of free RAM the navigation index needs
- You need remote access without your own authenticated reverse proxy: the daemon listens on localhost only by default
Example request
Check the ОбщийМодуль.РаботаСФайлами module for errors and show who calls its ЗаписатьФайл functionLimitations
The author states plainly that the project is developed on a leftover-time basis with no support guarantees or issue turnaround, though the tool is functional and used in production. Windows only, and full navigation needs around 14 GB of free RAM. The daemon does not authenticate calls and listens on 127.0.0.1 by default; network access needs your own reverse proxy and the explicit BSL_MCP_HOST and BSL_ALLOW_REMOTE variables.
How to disable. Stop the bsl-ls-mcp service (or close run.cmd) and remove it from autostart if you installed it via install-service.ps1, then remove the server from the client's .mcp.json.
MCP
- Transport
- http
- Authentication
- not required
| Environment variables | |
|---|---|
| BSL_WORKSPACE required | Path to the CR source export folder of the 1C configuration (src/cf). |
| BSL_MCP_HOST | The daemon's listen address; 0.0.0.0 is blocked unless BSL_ALLOW_REMOTE=1. |
| BSL_ALLOW_REMOTE | Explicit permission to listen on more than localhost. |
| BSL_ALLOWED_ROOTS | The list of allowed directories for path-based requests outside the configuration corpus. |
Security check
- Only reads and statically analyzes the 1C sources, never writes to the database
- The local unauthenticated HTTP port needs to stay closed to the network
README in short
The README lists requirements (a 1C CR export, around 14 GB of RAM, Java 17+), two ways to run it (a ready self-contained bundle or a source install via pip) and how to connect an MCP client via streamable-http. It separately warns about the daemon's lack of authentication and advises against exposing the port without a reverse proxy. A table lists seven tools with their parameters and purpose, followed by each tool's response format. Details are moved to README_full.md. MIT license, and the project status is explicitly marked as maintained on a leftover-time basis.
FAQ
Do I need Python or Java installed?
No, if you use the ready-made dist\bsl-ls-mcp bundle, it already bundles Python and Java. Installing from source needs Python 3.10+ and Java 17+.
Is it safe to expose the port on the network?
Not without extra protection. The daemon does not check call authorization, so the author recommends putting an authenticated reverse proxy in front rather than exposing the port directly.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything