Code MCP Server

Code Quality Auditor: Analyze code for SOLID principles, DRY violations, and more

Local serverstdioTypeScript

What is the Code MCP server?

Connect Code to Claude, Cursor or any other MCP client and it stops being a tab you switch to. Code Quality Auditor: Analyze code for SOLID principles, DRY violations, and more. The code mcp server is what makes that connection.

What the server does

Architectural invariants enforced inside your AI agent's edit loop. When the agent writes code that breaks a project rule, Code Auditor catches it and blocks the edit. The agent sees the rule's message and fixes itself.

Available tools

The toolset is worth reading before you wire it up, because it tells you what the integration is really for:

  • Kind — What it blocks
  • import-ban — Banned module imports
  • call-constraint — Function calls from unauthorized files
  • module-boundary — Imports across module boundaries
  • naming — Exported symbols not matching a pattern
  • ast-pattern — AST nodes matching an ast-grep pattern
  • style-mechanism — Unapproved style mechanisms per file/glob
  • no-raw-values — Hardcoded values for specific CSS properties
  • Agent — Skill
  • Cursor — code-audit install --agent cursor (project-only)
  • Codex — code-audit install --agent codex + plugin
  • Category — Meaning

Installation

Installation goes through your MCP client rather than a global install: point it at code-auditor-mcp on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

Where it fits

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Code's toolset — Kind, import-ban, call-constraint and 11 more — is a fair guide to whether it matches your workflow. It is maintained by BenAHammond; worth a glance at recent repository activity before you build anything load-bearing on it.

This entry was verified against Code's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.

Worth knowing first

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • With 14 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch Code.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

Available tools

ToolWhat it does
KindWhat it blocks
import-banBanned module imports
call-constraintFunction calls from unauthorized files
module-boundaryImports across module boundaries
namingExported symbols not matching a pattern
ast-patternAST nodes matching an ast-grep pattern
style-mechanismUnapproved style mechanisms per file/glob
no-raw-valuesHardcoded values for specific CSS properties
AgentSkill
Cursorcode-audit install --agent cursor (project-only)
Codexcode-audit install --agent codex + plugin
CategoryMeaning
DeterministicStructural fact — an engineer would act on every finding
AdvisoryHeuristic signal — may be wrong depending on domain

How to install the Code MCP server

{
  "mcpServers": {
    "code-auditor": {
      "command": "npx",
      "args": ["-y", "code-auditor-mcp"]
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Example prompts to try

  • Use Code to Kind.
  • Use Code to import-ban.
  • Use Code to call-constraint.

Frequently asked questions

It connects Code to MCP-compatible AI assistants such as Claude and Cursor, exposing 14 tools (Kind, import-ban, call-constraint, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Code directly.