Code Quality Auditor: Analyze code for SOLID principles, DRY violations, and more
Connect Code to Claude, Cursor or any other MCP client and it stops being a tab you switch to. Code Quality Auditor: Analyze code for SOLID principles, DRY violations, and more. The code mcp server is what makes that connection.
Architectural invariants enforced inside your AI agent's edit loop. When the agent writes code that breaks a project rule, Code Auditor catches it and blocks the edit. The agent sees the rule's message and fixes itself.
The toolset is worth reading before you wire it up, because it tells you what the integration is really for:
Kind — What it blocksimport-ban — Banned module importscall-constraint — Function calls from unauthorized filesmodule-boundary — Imports across module boundariesnaming — Exported symbols not matching a patternast-pattern — AST nodes matching an ast-grep patternstyle-mechanism — Unapproved style mechanisms per file/globno-raw-values — Hardcoded values for specific CSS propertiesAgent — SkillCursor — code-audit install --agent cursor (project-only)Codex — code-audit install --agent codex + pluginCategory — MeaningInstallation goes through your MCP client rather than a global install: point it at code-auditor-mcp on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.
This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Code's toolset — Kind, import-ban, call-constraint and 11 more — is a fair guide to whether it matches your workflow. It is maintained by BenAHammond; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against Code's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| Kind | What it blocks |
| import-ban | Banned module imports |
| call-constraint | Function calls from unauthorized files |
| module-boundary | Imports across module boundaries |
| naming | Exported symbols not matching a pattern |
| ast-pattern | AST nodes matching an ast-grep pattern |
| style-mechanism | Unapproved style mechanisms per file/glob |
| no-raw-values | Hardcoded values for specific CSS properties |
| Agent | Skill |
| Cursor | code-audit install --agent cursor (project-only) |
| Codex | code-audit install --agent codex + plugin |
| Category | Meaning |
| Deterministic | Structural fact — an engineer would act on every finding |
| Advisory | Heuristic signal — may be wrong depending on domain |
{
"mcpServers": {
"code-auditor": {
"command": "npx",
"args": ["-y", "code-auditor-mcp"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.