Back to Browse

Repo Mapper MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

Deterministic repository structure mapping for onboarding agents.

About

Deterministic repository structure mapping for onboarding agents.

Security Report

4.8
Use Caution4.8High Risk

This is a well-structured MCP server for static repository analysis with no authentication requirements (appropriate for its use case as a grounded code inspection tool). The codebase demonstrates good security practices: no hardcoded credentials, no network calls, no code execution, proper input validation via Pydantic models, and comprehensive test coverage. Permissions are appropriately scoped to filesystem read operations. Minor findings around exception handling and resource cleanup do not materially impact security. Supply chain analysis found 6 known vulnerabilities in dependencies (1 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-lovranran-mcp-repo-mapper": {
      "args": [
        "mcp-repo-mapper"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

mcp-repo-mapper

mcp-repo-mapper is a FastMCP server for deterministic repository structure mapping. It scans a local codebase and exposes file structure, language counts, Python import dependencies, circular dependency detection, framework detection, entry point candidates, and a cached repo structure resource.

The server does not call an LLM and does not execute user code. It is intended as a grounded structure tool for codebase onboarding agents such as wayfinder.

Codebase Onboarding Stack

mcp-repo-mapper is the structure layer in a three-server MCP tool stack for Project 6 wayfinder, a codebase onboarding agent.

  • mcp-repo-mapper maps repository structure, languages, entry points, framework evidence, and Python dependency edges.
  • mcp-ast-explorer provides symbol-grounded Python definition, signature, reference, call-chain, and class-hierarchy lookups.
  • mcp-test-runner runs local pytest/Jest checks and coverage summaries so agent claims can be verified against execution.

In wayfinder, this server feeds the architecture-mapping step before semantic explanation or test verification begins.

Features

  • scan_repo(path) returns a typed repo scan with files, language breakdown, entry points, Python dependency graph, and detected frameworks.
  • find_circular_deps(path) returns circular dependencies from the static dependency graph.
  • language_breakdown(path) returns language counts by file count and bytes.
  • detect_framework(path) detects FastAPI, Flask, Django, Express, and Spring using registry-based markers.
  • find_entry_points(path) returns ranked entry point candidates such as Python mains, FastAPI apps, package start scripts, Dockerfiles, and Node indexes.
  • repo-structure://{url_hash} returns a cached JSON scan result after a tool call has populated the cache.

Install

uv sync --extra dev

Run the server locally:

uv run mcp-repo-mapper

Development

uv run ruff check .
uv run mypy
uv run pytest

Resource Flow

Resource reads use a cache populated by tool calls:

  1. Call scan_repo(path) or another scan-backed tool.
  2. Compute the repo hash with the same path.
  3. Read repo-structure://{url_hash}.

The public resource uses repo-structure://... because URL schemes cannot contain underscores.

Scope And Limitations

  • Dependency graph support is currently Python-only and based on static ast parsing.
  • Import graph resolution only records modules that exist inside the scanned repo.
  • Framework detection is heuristic marker matching, not a full build-system analysis.
  • The resource cache is in-memory and process-local.
  • The server scans local filesystem paths only.

License

MIT

Reviews

No reviews yet

Be the first to review this server!