Skip to main content

safe-fix-mcp

PyPI License: MIT

A real MCP server that finds dead code in a Python repository and proposes a branch + PR for the one class of finding that's actually safe to auto-remove: unused imports on a single-name import line. Everything else it finds — unused functions, classes, unused dependencies — stays report-only. A human always merges. This tool never merges anything itself.

Why this exists

Most "dead code" tools stop at reporting. The ones that go further usually delete with no safety net. This does neither: it drafts a real, minimal, reviewable PR, gated on the target repo's own full test suite actually passing after the removal — not a heuristic, a real pytest run. If the suite fails, nothing is committed or pushed; the repo is left exactly as it started.

Tools

scan_dead_code(repo_path=".", min_confidence=60)

Read-only. Runs vulture (dead code) and deptry (dependency issues) and returns a human-readable list of findings. Never modifies anything.

propose_removal_pr(repo_path=".")

  • Refuses on a dirty working tree — never edits on top of uncommitted work.
  • Filters to unused imports at ≥90% vulture confidence, on single-name import lines only (from x import y, z is skipped — removing the whole line would silently remove z too).
  • Creates a real branch, removes the qualifying imports, runs the repo's real full test suite.
  • Only on a real pass: commits, pushes, and tries to open a PR via gh pr create.
  • If gh isn't installed/authenticated, the branch is still committed and pushed for real — only PR creation degrades, with the real error returned so you can open it manually.

Install

pip install safe-fix-mcp

Add to your MCP client config (e.g. Claude Code):

claude mcp add safe-fix-mcp -- safe-fix-mcp

Or run directly for local testing:

python -m safe_fix_mcp.server

Installing from source instead of PyPI:

pip install -e .

Skill

A SKILL.md ships inside this same package — not a separate download — and teaches Claude when and how to use the two tools correctly (e.g. that propose_removal_pr only ever auto-removes single-name unused imports, never functions/classes/dependencies). Install it into your project:

safe-fix-mcp-install-skill

Run it from the project root you want the skill active in — it writes to .claude/skills/safe-fix-mcp/SKILL.md relative to your current directory.

Requirements

  • Python ≥ 3.10
  • git on PATH
  • gh (GitHub CLI) on PATH and authenticated, if you want propose_removal_pr to actually open the PR — without it, the branch still gets pushed for real, and the tool tells you to open the PR by hand.

Development

pip install -e ".[dev]"
pytest

Known limitation

vulture flags scan_dead_code/propose_removal_pr themselves as "unused" — a known false-positive class, not a real bug: they're dispatched by the @mcp.tool() decorator at runtime, not called directly anywhere in the source, so static call-graph analysis can't see the real caller (the MCP framework itself).

Verifying it for real

scripts/verify_real_client.py launches the packaged server as a real subprocess and talks to it with the real mcp.client.ClientSession — the same path a real MCP client uses. Useful as a smoke test after any change:

python scripts/verify_real_client.py

Metadata

Release files for safe-fix-mcp 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for safe-fix-mcp 0.1.2
File Size Uploaded
safe_fix_mcp-0.1.2.tar.gz 15.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for safe-fix-mcp 0.1.2
File Interpreter ABI Platform
safe_fix_mcp-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 29.7 kB

Release files / safe_fix_mcp-0.1.2.tar.gz

Download URL safe_fix_mcp-0.1.2.tar.gz
Size 15.6 kB
Tags Source
SHA-256 checksum
How to use checksums
cd245498282b90be4cf671ee923f9b1e9c00ba27a5918d3773dc6083d245a825
BLAKE2b-256 checksum
How to use checksums
d83b07d45cf85f526f3805e098e9699fbe46f5de82b952f4c84adb4acbeccabc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.10.9

Release files / safe_fix_mcp-0.1.2-py3-none-any.whl

Download URL safe_fix_mcp-0.1.2-py3-none-any.whl
Size 14.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
64f7aa25a3ed15e42235796a465eb34b88f0be2516fc1e96d6f6c7a4e331bbf1
BLAKE2b-256 checksum
How to use checksums
8646bd2f43bec761aa44b0a80a2e48601ac313f1f90e9a0c57acd56b84e0b36b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.10.9

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page