No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by qcri · MCP Server · ★ 162
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is codebadger safe to install? View the security audit →
🦡 codebadger codebadger is a containerized Model Context Protocol (MCP) server that gives AI agents and LLMs deep, queryable access to a codebase's structure and data flow through Joern Code Property Graphs (CPGs). Point it at a Git repository, a local path, or even a pasted code snippet, and codebadger builds a CPG and exposes it over MCP — so an assistant can run CPGQL queries, trace data flow and taint, slice programs, and hunt for vulnerabilities across Java, C/C++, JavaScript, Python, Go, Kotlin, C#, Ghidra, Jimple, PHP, Ruby, and Swift. It's a general-purpose foundation for both program analysis (understanding code structure, call graphs, and data flow) and vulnerability analysis (taint tracking, bug hunting, and PoC development) — useful for academic research as well as industry security and engineering work. It's built to scale to large analysis batches with per-CPG worker pools, memory-aware scheduling, and a Postgres/Redis backend. News codebadger and its paper - Bridging Code Property Graphs and Language Models for Program Analysis - were accepted at the Software Vulnerability Management Workshop @ ICSE 2026.
| Stars | 162 |
| Forks | 19 |
| Language | Python |
| Category | MCP Server |
| License | GPL-3.0 |
| Quality Score | 62.7714223079922/100 |
| Last Updated | 2026-08-31 |
| Created | 2025-10-01 |
| Platforms | mcp, python |
| Est. Tokens | ~14k |
These tools work well together with codebadger for enhanced workflows:
Looking for a codebadger alternative? If you're comparing codebadger with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
🦡 codebadger is a containerized Model Context Protocol (MCP) server that gives AI agents and LLMs deep, query
🚀 Universal SDK for building next-gen MCP servers
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and se
Local-first, agent-native control plane for ComfyUI — MCP server + sidebar agent that generates images, video
A world-class collection of Claude Code utilities: autonomous skills, expert agents, slash commands, and promp
Official SonarQube MCP Server for code quality and security in AI agents
Explore other popular mcp server tools:
codebadger is 🦡 codebadger is a containerized Model Context Protocol (MCP) server that gives AI agents and LLMs deep, queryable access to a codebase's structure and data flow through Joern Code Property Graphs (CP. It is categorized as a MCP Server with 162 GitHub stars.
codebadger is primarily written in Python. It covers topics such as agent-skills, agentic-workflow, agents.
You can find installation instructions and usage details in the codebadger GitHub repository at github.com/qcri/codebadger. The project has 162 stars and 19 forks, indicating an active community.
codebadger is released under the GPL-3.0 license, making it free to use and modify according to the license terms.
The top alternatives to codebadger on Agent Skills Hub include codebadger, concierge, opentaint. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: