codebase-memory-mcp
An MCP server that builds a code graph of functions, classes, calls and routes and answers the agent's structural queries locally
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads the whole codebase and writes settings into agent configurations
- Runs a background daemon, a file watcher and a local web UI
Install
Manual install
curl -fsSL https://raw.githubusercontent.com/DeusData/codebase-memory-mcp/main/install.sh | bashmacOS and Linux. The installer downloads the binary and configures detected agents. Restart the agent afterward.
This is third-party code. Review the repository files before installing.
What it does
The server indexes a repository and builds a graph of code relationships: functions, classes, call chains, HTTP routes and cross-service links. Parsing goes through tree-sitter grammars for a large set of languages, and several languages add type resolution. The agent asks structural queries, for example what calls a function, where dead code is, or how a change affects other parts, instead of reading files one by one. Everything runs locally, with no API keys and no external service, and the code never leaves the machine. It has a built-in 3D graph visualization in the browser and a team-shared graph snapshot that can be committed to the repository.
Who it is for. For developers who want the agent to navigate a large codebase by structure rather than by rereading files.
Good fit when
- You need to quickly grasp the architecture and links in a large repository
- You need to find who calls a function and assess the impact of changes
- You want code and graph search without reading many files into context
- You want a local tool with no API keys and no external services
Not a fit when
- You want a ready natural-language answer without an agent: the server only builds and serves the graph
- The project is tiny and plain file search is enough
- You cannot run a local binary and a background process
Example request
Index the project and show what calls the ProcessOrder functionLimitations
The server is only an analysis backend; it contains no model and relies on the agent as the intelligence layer. It reads your codebase and writes settings into the agent's configuration, which is what it is designed to do. On Windows Microsoft Defender may flag the binary as a false positive, which the author explains in the docs. The shared graph snapshot, if committed on every change, bloats git history heavily, so it is better to commit it on a schedule.
How to disable. Run codebase-memory-mcp uninstall: the command removes the entries in agent configs, the hooks and the binary itself, and deletes indexes only after confirmation.
MCP
- Transport
- stdio
- Authentication
- not required
| Environment variables | |
|---|---|
| CBM_CACHE_DIR | Cache and index directory, default ~/.cache/codebase-memory-mcp. |
| CBM_DIAGNOSTICS | Enables a diagnostics log for memory and performance reports. |
Security check
- Reads the whole codebase and writes settings into agent configurations
- Runs a background daemon, a file watcher and a local web UI
README in short
The README describes codebase-memory-mcp as a local code-analysis engine for agents, shipped as an MCP server and a native binary with no language runtime. It parses code via tree-sitter for a large set of languages and builds a persistent knowledge graph of functions, classes, calls, routes and cross-service links. Around 15 MCP tools are available: search, call tracing, architecture overview, change-impact assessment, Cypher-style queries, dead-code detection and more. Installation is via a script, npm, PyPI, Homebrew and other managers, with a built-in 3D graph visualization and a team-shared snapshot. Everything runs locally, with no API keys and no telemetry.
FAQ
Does it need an API key or the internet?
No. Indexing and queries run locally, no API keys are needed, and the code never leaves the machine.
Does the server answer questions in words itself?
No. It builds and serves the graph, while your agent phrases the answer by calling the server's tools.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything