Back to Browse

Seshat MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Structural code intelligence for AI agents: real call graphs, blast radius, and change history.

About

Structural code intelligence for AI agents: real call graphs, blast radius, and change history.

Security Report

4.2
Use Caution4.2High Risk

Seshat MCP is a well-structured cloud proxy server for code analysis with reasonable security practices. API key handling is properly done via environment variables, and all tool operations are read-only with appropriate scoping. However, there are moderate concerns around credential persistence to disk and some error handling gaps that users should be aware of. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

3 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

HTTP Network Access

Connects to external APIs or services over the internet.

system_info

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

What You'll Need

Set these up before or after installing:

Your Seshat API key. Get one free at https://seshat.papyruslabs.aiRequired

Environment variable: SESHAT_API_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "ai-papyruslabs-seshat-mcp": {
      "env": {
        "SESHAT_API_KEY": "your-seshat-api-key-here"
      },
      "args": [
        "-y",
        "@papyruslabsai/seshat-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Seshat — structural code intelligence for AI agents

Your agent reconstructs your codebase from likelihood. Seshat compiles it.

Seshat turns a repository into a typed symbol graph (every function, class, route, and table, with its real dependency edges, data flow, and constraints) and serves it to your agent over MCP. So before your agent edits a function, it can ask what will actually break instead of guessing.

Backed by a compiled intermediate representation, not text search or embeddings: if Seshat says a function has three callers, it has exactly three.

Why

AI coding agents are fast but structurally blind. When an agent changes one function, it often cannot see everything that depends on it, so it silently breaks callers it never looked at. A large share of AI-introduced regressions come from exactly this. Seshat gives the agent the map.

Try it first (no install, no login)

Paste any public repo at https://seshat.papyruslabs.ai/try and watch it trace what a change would break.

Install

npx -y @papyruslabsai/seshat-mcp setup <your-key>

Get a free key at https://seshat.papyruslabs.ai (first extraction is free). The setup command writes your MCP config and stores the key.

Or configure manually (Claude Code, Cursor, or any MCP client):

{
  "mcpServers": {
    "seshat": {
      "command": "npx",
      "args": ["-y", "@papyruslabsai/seshat-mcp"],
      "env": { "SESHAT_API_KEY": "your-key" }
    }
  }
}

Tools

Point your agent at a repo with sync_project, then it investigates the way a senior engineer does: orient, trace, verify.

Orient

  • list_projects — what is synced
  • list_modules — how the codebase is organized, by layer or module
  • query_entities — find functions, classes, and routes by name, layer, or module
  • find_entry_points — routes, exports, and the public API surface

Investigate a symbol

  • get_entity — signature, callers, callees, data flow, side effects, and tables touched
  • get_dependencies — the real call chain, callers and callees
  • get_blast_radius — everything that breaks if you change it, transitively
  • get_data_flow — what a function reads, returns, and mutates
  • get_optimal_context — the minimal, ranked set of files to read before editing
  • find_by_constraint — every function that touches a given table (or carries a given trait)
  • find_dead_code — unreachable symbols, safe to delete

Read the history (from the repo's commit record, backfilled on first sync)

  • get_lineage — how one function has actually changed: each commit typed by what moved (body, calls, data, signature), CI pass/fail and reverts, what changes alongside it, and what last forced a change here. Ask it before touching anything load-bearing.
  • get_hotspots — where development happens and where it fails: the most-changed code, thrash spots where changes keep getting reverted or landing on red CI, and heavily used code nobody has touched (stability pressure)
  • get_co_change_clusters — the hidden modules: code that changes together across files even when no import connects it, so a change to one member usually means the rest

Every answer comes from the compiled graph and discloses the coverage behind it. History is commit-resolution correlation and says so; it never claims causation it can't show.

Cross-cutting audit tools (test coverage, topology, semantic clones) are being hardened and will be added to this list as they land.

Privacy

Analysis runs in the Papyrus Labs cloud, by design: the compiled graph is the product's moat, and keeping extraction server-side is how that stays protected. Public repos are cloned from GitHub; private repos require you to connect your GitHub account. Source is processed to build the graph and cached to serve queries. See the privacy policy at seshat.papyruslabs.ai.

Pricing

First extraction is free. $0.03 per query after a free tier; a typical investigation is 5 to 15 queries. Details at https://seshat.papyruslabs.ai.

MIT licensed server. Named for the goddess who kept the records, built so your agent can read them.

Reviews

No reviews yet

Be the first to review this server!