Back to Browse

Codna Cli MCP Server

Developer ToolsLow Risk8.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Repo intelligence: triage, fix PRs, SARIF reachability, recall. Free codna login to execute.

About

Repo intelligence: triage, fix PRs, SARIF reachability, recall. Free codna login to execute.

Security Report

8.0
Low Risk8.0Low Risk

Valid MCP server (1 strong, 3 medium validity signals). 1 known CVE in dependencies (0 critical, 1 high severity) ⚠️ Package registry links to a different repository than scanned source. Imported from the Official MCP Registry.

7 files analyzed · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Provider key for codna_fix's planner — any one of ANTHROPIC_API_KEY (Anthropic), OPENAI_API_KEY (OpenAI/ChatGPT), or GEMINI_API_KEY (Gemini) works (or store one with `codna key set <provider>`). Every tool also requires the one-time free `codna login` device authorization before executing; introspection (initialize/tools/list) needs no credentials.Required

Environment variable: ANTHROPIC_API_KEY

Write token, only for codna_fix with open_pr=true (opens a pull request) and codna_report_bug (files an issue).Required

Environment variable: GITHUB_TOKEN

Codna key from the one-time free `codna login` (device authorization, free community license). Required to execute any of the five tools; introspection (initialize/tools/list) needs none.Required

Environment variable: CODNA_API_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-thyn-ai-codna": {
      "env": {
        "GITHUB_TOKEN": "your-github-token-here",
        "CODNA_API_KEY": "your-codna-api-key-here",
        "ANTHROPIC_API_KEY": "your-anthropic-api-key-here"
      },
      "args": [
        "codna"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Codna

Understand. Fix. Evolve.

Agents read your code. Codna understands it.

Codna maps a repository before it spends a token. It then reviews pull requests, fixes bugs and proves which scanner findings are reachable. The same codna command runs on your machine, in the GitHub Action and behind the GitHub App.

Runs on your machine or your cloud. Your code never leaves without your key.

Install

pip install codna          # or: pipx install codna · uv tool install codna
codna --version

Python 3.12–3.13. Wheels for macOS on Apple silicon and Linux x86_64. git on your PATH. Nothing else to install: no Node, Bun, Docker or server. The agent runtime ships inside the wheel.

Local commands need no Codna key. fix and review use your own model provider key, stored in the OS keychain and never printed:

codna key set anthropic    # also: openai, gemini, google, groq, mistral, openrouter, xai, cursor

Commands

codna triage . --issue "checkout total is wrong"     # suspect files. Deterministic. 0 LLM tokens.
codna review . --pr 123 --post                        # findings with a verdict on the pull request
codna fix . --tests --apply --max-iterations 3        # patch, re-run your tests, re-fix until green
codna fix <git url> --ref <sha> --issue "…" --open-pr # push a branch and open a pull request
codna secure . --from-sarif results.sarif             # which scanner findings are reachable. 0 LLM tokens.

codna fix prints the root cause, the impacted symbols, the blast radius, its confidence and a regression risk. --open-pr needs a git URL and a GitHub write token. codna review posts one inline comment per finding with severity, category and a suggestion block, and an Approve when the diff is clean at medium and high. codna secure reads SARIF 2.1.0 from CodeQL, Semgrep, Snyk, Trivy or any other scanner.

Other commands: init, status, doctor, login, key, impact, memory export, report. Full reference: docs.codna.ai/reference/cli.

MCP server

Run Codna as a Model Context Protocol server over stdio — the same engine the CLI uses, inside Cursor, Claude Desktop, or your own agent:

pipx install "codna[mcp]"       # or: pip install "codna[mcp]"
codna mcp                       # serve over stdio
codna mcp install --client cursor     # optional: write the client config for you (or --client claude)

Five tools, each returning JSON; a failure comes back as codna_<tool> error: … text and never crashes the server:

ToolWhat it doesNeeds
codna_triageUnderstand a repo and locate the code relevant to an issue. Deterministic, 0 LLM tokens.free codna login
codna_secureProve which SARIF scanner findings (CodeQL, Semgrep, Snyk, Trivy) are reachable. Read-only, 0 LLM tokens.free codna login
codna_recallRecall code from local on-device memory — semantic + lexical search, fully offline.free codna login (which also installs the on-device runtime)
codna_fixRoot-cause and plan a fix (read-only by default); with open_pr=true pushes a branch and opens a real PR.free codna login + provider key (BYOK; + GITHUB_TOKEN for open_pr=true)
codna_report_bugFile a bug, feature, or question to thyn-ai/feedback.free codna login + GITHUB_TOKEN (else returns a pre-filled URL)

Introspection (initialize/tools/list) needs no credentials. Executing any of the five tools requires the one-time free community login (codna login — device authorization, free community license) — fully offline thereafter. codna_fix additionally needs a provider key (BYOK, e.g. ANTHROPIC_API_KEY); codna_report_bug needs GITHUB_TOKEN or it returns a pre-filled issue URL; codna_recall additionally uses the on-device memory runtime that the same codna login installs. Full reference: docs.codna.ai/guides/mcp.

Code memory

Code memory and recall run on your machine after a one-time free codna login (device authorization), which also installs the signed on-device runtime. From then on, recall runs fully offline: no key, no network calls. The optional codna[memory] extra adds the on-device semantic reranker; without it, recall ranks lexically.

What leaves your machine

  • Repository mapping, triage, recall and impact run offline. No model is involved.
  • fix and review send one issue-specific evidence bundle to the provider you chose, under your key. Not the repository.
  • Secret redaction is always on and cannot be turned off.
  • privacy.egress: fail-closed in codna.yaml refuses to run tests without network denial and skips registry lookups during review.
  • Source distributions exclude runtime binaries, keys, .env files and logs.

Links

Reviews

No reviews yet

Be the first to review this server!