codebadger — security grade SAFE, quality 77/100

Security audit verdict: SAFE · quality 77/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by Lekssays · MCP Server · ★ 158

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is codebadger safe to install? View the security audit →

About codebadger

🦡 codebadger A containerized Model Context Protocol (MCP) server providing static code analysis using Joern's Code Property Graph (CPG) technology with support for Java, C/C++, JavaScript, Python, Go, Kotlin, C#, Ghidra, Jimple, PHP, Ruby, and Swift. Prerequisites Before you begin, make sure you have: Docker and Docker Compose installed Python 3.10+ (Python 3.13 recommended) pip (Python package manager) To verify your setup: Quick Start Install Python Dependencies Start the Docker Services (Joern) This starts: Joern Server: Static code analysis engine (runs CPG generation and queries) Verify services are running: Start the MCP Server The MCP server will be available at . Stop All Services Cleanup Script Use the provided cleanup script to reset your environment: This will: Stop and remove Docker containers Kill orphaned Joern/MCP processes Clear Python cache (pycache

agent-skillsagentic-workflowagentsjoernmcp-serverprogram-analysisstatic-analysistaint-analysis

Quick Facts

Stars158
Forks19
LanguagePython
CategoryMCP Server
LicenseGPL-3.0
Quality Score76.8342392910123/100
Last Updated2026-08-21
Created2025-10-01
Platformsdocker, mcp, python
Est. Tokens~15k

codebadger alternative? Top 6 similar tools

Looking for a codebadger alternative? If you're comparing codebadger with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • codebadger by qcri · ⭐ 162

    🦡 codebadger is a containerized Model Context Protocol (MCP) server that gives AI agents and LLMs deep, query

  • concierge by concierge-hq · ⭐ 531

    🚀 Universal SDK for building next-gen MCP servers

  • opentaint by seqra · ⭐ 160

    The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and se

  • comfyui-mcp by artokun · ⭐ 778

    Local-first, agent-native control plane for ComfyUI — MCP server + sidebar agent that generates images, video

  • claude-code-tresor by alirezarezvani · ⭐ 776

    A world-class collection of Claude Code utilities: autonomous skills, expert agents, slash commands, and promp

  • sonarqube-mcp-server by SonarSource · ⭐ 654

    Official SonarQube MCP Server for code quality and security in AI agents

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is codebadger?

codebadger is 🦡 codebadger is a containerized Model Context Protocol (MCP) server that gives AI agents and LLMs deep, queryable access to a codebase's structure and data flow through Joern Code Property Graphs (CP. It is categorized as a MCP Server with 158 GitHub stars.

What programming language is codebadger written in?

codebadger is primarily written in Python. It covers topics such as agent-skills, agentic-workflow, agents.

How do I install or use codebadger?

You can find installation instructions and usage details in the codebadger GitHub repository at github.com/Lekssays/codebadger. The project has 158 stars and 19 forks, indicating an active community.

What license does codebadger use?

codebadger is released under the GPL-3.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to codebadger?

The top alternatives to codebadger on Agent Skills Hub include codebadger, concierge, opentaint. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools