No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by Cranot · MCP Server · ★ 518
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is roam-code safe to install? View the security audit →
roam-code The architectural intelligence layer for AI coding agents. Structural graph, architecture governance, multi-agent orchestration, vulnerability mapping, runtime analysis -- one CLI, zero API keys. 147 commands · 106 MCP tools · 27 languages · 100% local What is Roam? Roam is a structural intelligence engine for software. It pre-indexes your codebase into a semantic graph -- symbols, dependencies, call graphs, architecture layers, git history, and runtime traces -- stored in a local SQLite DB. Agents query it via CLI or MCP instead of repeatedly grepping files and guessing structure. Unlike LSPs (editor-bound, language-specific) or Sourcegraph (hosted search), Roam provides architecture-level graph queries -- offline, cross-language, and compact. It goes beyond comprehension: Ro
| Stars | 518 |
| Forks | 50 |
| Language | Python |
| Category | MCP Server |
| License | Apache-2.0 |
| Quality Score | 66.6805607244332/100 |
| Open Issues | 12 |
| Last Updated | 2026-09-20 |
| Created | 2026-02-09 |
| Platforms | cli, mcp, python |
| Est. Tokens | ~25k |
Looking for a roam-code alternative? If you're comparing roam-code with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Structural code intelligence for AI agents — semantic search, knowledge graphs, and a built-in MCP server in o
An AI-powered GitHub code review tool that uses LLMs to detect high-confidence, high-impact issues—such as sec
Supercharge AI Agents, Safely
Framework-aware code intelligence MCP server — 88 framework integrations, 81 languages, 72.7% fewer input toke
Graph-powered code intelligence engine — indexes codebases into a knowledge graph, exposed via MCP tools for A
Codebase intelligence for AI. Detects patterns & conventions + remembers decisions across sessions. MCP server
Explore other popular mcp server tools:
roam-code is Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 287 commands, 246 MCP tools, change-safety gates, audit evidence, zero API keys.. It is categorized as a MCP Server with 518 GitHub stars.
roam-code is primarily written in Python. It covers topics such as ai-agents, ai-coding, cli.
You can find installation instructions and usage details in the roam-code GitHub repository at github.com/Cranot/roam-code. The project has 518 stars and 50 forks, indicating an active community.
roam-code is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to roam-code on Agent Skills Hub include octocode, Gito, mcpproxy-go. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: