Skip to main content

MCP Server Analyzer for Python 🐍🔍

SafeSkill 92/100

CI/CD Pipeline PyPI version Python 3.13+ Docker License: MIT Code Coverage AgentSeal MCP Docs

A powerful Model Context Protocol (MCP) server that provides comprehensive Python code analysis using Ruff for linting, ty for type checking, and Vulture for dead code detection. Perfect for AI assistants, IDEs, and automated code review workflows.

🚀 Quick Start

VS Code Integration (One-Click Install)

For quick installation, use one of the one-click install buttons below...

Install with UV in VS Code Install with UV in VS Code Insiders

Install with Docker in VS Code Install with Docker in VS Code Insiders

For manual installation, add the following JSON block to your User Settings (JSON) file in VS Code. You can do this by pressing Ctrl + Shift + P and typing Preferences: Open User Settings (JSON).

Optionally, you can add it to a file called .vscode/mcp.json in your workspace. This will allow you to share the configuration with others.

Note that the mcp key is needed when using the mcp.json file.

Using uvx (recommended):

{
  "mcp": {
    "servers": {
      "analyzer": {
        "command": "uvx",
        "args": ["mcp-server-analyzer"]
      }
    }
  }
}

Using Docker:

{
  "mcp": {
    "servers": {
      "analyzer": {
        "command": "docker",
        "args": ["run", "-i", "--rm", "ghcr.io/anselmoo/mcp-server-analyzer"]
      }
    }
  }
}

Universal Installation

# Install with uvx (recommended)
uvx install mcp-server-analyzer

# Install with pip
pip install mcp-server-analyzer

# Run with Docker
docker run ghcr.io/anselmoo/mcp-server-analyzer:latest

# Install from source
git clone https://github.com/anselmoo/mcp-server-analyzer.git
cd mcp-server-analyzer
uv sync --dev
uv run mcp-server-analyzer

📋 Features

  • 🔍 RUFF Analysis: Comprehensive Python linting with auto-fixes
  • 🧠 ty Type Checking: Fast Python type analysis with rule-based diagnostics
  • 🧹 Dead Code Detection: Find unused imports, functions, and variables with VULTURE
  • ⚡ Biome JS/TS Analysis: Fast linting and formatting for JavaScript and TypeScript
  • 📊 Quality Scoring: Combined analysis with quality metrics
  • 🚀 FastMCP Framework: High-performance MCP server implementation
  • 🐳 Docker Ready: Multi-architecture containers with security signing
  • 🔒 Secure: All releases signed with Sigstore for supply chain security

📈 Analysis Examples

RUFF Linting Preview

See comprehensive linting analysis examples: 📋 RUFF Analysis Preview

VULTURE Dead Code Detection Preview

Explore dead code detection capabilities: 🧹 VULTURE Analysis Preview

🛠️ Available Tools

Tool Description Use Case
ruff-check Lint Python code with RUFF Style violations, potential errors
ruff-format Format Python code with RUFF Code formatting and consistency
ruff-check-ci CI/CD optimized RUFF output GitHub Actions, GitLab CI
ty-check Type-check Python code with ty Type safety, incorrect return values
vulture-scan Dead code detection Unused imports, functions, variables
biome-check Lint JS/TS code with Biome Style violations, potential errors
biome-format Format JS/TS code with Biome Code formatting and consistency
analyze-code Combined Ruff + ty + Vulture analysis Complete code quality assessment

🔧 Configuration

Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "analyzer": {
      "command": "uvx",
      "args": ["mcp-server-analyzer"]
    }
  }
}

Zed

Add to your Zed settings.json:

"context_servers": {
  "analyzer": {
    "command": "uvx",
    "args": ["mcp-server-analyzer"]
  }
}

Claude Code (project-level)

Place .mcp.json at your project root:

{
  "mcpServers": {
    "analyzer": {
      "command": "uvx",
      "args": ["mcp-server-analyzer"]
    }
  }
}

🧪 Development

Prerequisites

  • Python 3.13+
  • uv (recommended) or pip
  • Node.js 22+ (for Biome JS/TS analysis)
  • Docker (optional)

Setup

# Clone repository
git clone https://github.com/anselmoo/mcp-server-analyzer.git
cd mcp-server-analyzer

# Install Python dependencies
uv sync --dev

# Install Biome (JS/TS analyzer)
npm ci

# Run tests
uv run pytest

# Run type checks
uv run ty check src tests

# Run pre-commit hooks
uv tool run pre-commit run --all-files

# Build Docker image
docker build -t mcp-server-analyzer .

Testing

# Run all tests
uv run pytest tests/ -v

# Run with coverage
uv run pytest --cov=src/mcp_server_analyzer --cov-report=html

# Test specific functionality
uv run pytest tests/test_server.py::TestAnalyzers::test_ruff_with_sample_code

📊 Quality Metrics

The server provides quality scoring based on:

  • Ruff Issues: Style violations, potential bugs, complexity metrics
  • ty Diagnostics: Static typing errors and warnings
  • Dead Code Detection: Unused imports, functions, variables
  • Combined Score: Weighted quality assessment (0-100)

🔒 Security

  • Signed Releases: All releases signed with Sigstore
  • Container Signing: Docker images signed with Cosign
  • Trusted Publishing: PyPI releases use GitHub OIDC trusted publishing
  • Vulnerability Scanning: Automated security scanning in CI/CD
  • Supply Chain Security: SLSA Build Level 3 compliance
  • Security Policy: See SECURITY.md for vulnerability reporting

🔍 Data Handling & Transparency

  • In-memory only: Code passed to tools is written to a temporary file, analyzed, and the file is deleted immediately — nothing is persisted between calls.
  • No network calls: The server makes no outbound network connections during analysis.
  • No telemetry: No usage data, analytics, or crash reports are collected.
  • Subprocess isolation: ruff, ty, and vulture are invoked with fixed argument lists — no shell expansion or arbitrary command execution.

📚 Documentation

🤝 Contributing

Contributions are welcome! Please see CONTRIBUTING.md for details.

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes using Conventional Commits
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

📝 License

This project is licensed under the MIT License - see the LICENSE file for details.

🙏 Acknowledgments


Made with ❤️ for better Python code quality

Metadata

Release files for mcp-server-analyzer 0.4.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mcp-server-analyzer 0.4.1
File Size Uploaded
mcp_server_analyzer-0.4.1.tar.gz 16.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mcp-server-analyzer 0.4.1
File Interpreter ABI Platform
mcp_server_analyzer-0.4.1-py3-none-any.whl Python 3 none any Details

Total release size: 35.9 kB

Release files / mcp_server_analyzer-0.4.1.tar.gz

Download URL mcp_server_analyzer-0.4.1.tar.gz
Size 16.2 kB
Tags Source
SHA-256 checksum
How to use checksums
8c33d708659b508c6613e96f6a2b54b91e8a12f6267f9a09e309acd9304db7ab
BLAKE2b-256 checksum
How to use checksums
4950a85b2399319fa3daa0440b14c8ad0736a134467876376d948adbd28b8560
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.

Transparency log

Release files / mcp_server_analyzer-0.4.1-py3-none-any.whl

Download URL mcp_server_analyzer-0.4.1-py3-none-any.whl
Size 19.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
070692a829f9e8aae088b306aa6e12e0030c8b967dc97cc13b3505a213b87f41
BLAKE2b-256 checksum
How to use checksums
c4f2e22252546e77d272fe813246c67b2edd5fa6dbe42e03ed374002a827ab16
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.4.1 This release

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page