grasp-mcp-server a

by ashfordeou

Not rated
GitHub

About

36 tools for dependency graphs, architecture analysis, security scanning, refactoring, and CI tracking for LLM agents

Details

Author
ashfordeou
Categories
Developer Tools, AI

Setup

Install grasp-mcp-server a in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/ashfordeou/grasp

Follow the installation instructions in the repository README, then restart your MCP client.

150 MCP tools + 8 Resources + 2 Prompts · 35 languages · 11 AI providers + 200+ models via OpenRouter · 10 graph views · multimodal knowledge graph · zero data collection

🌐 Browser App·📦 MCP Server·🐛 Report Bug·✨ Request Feature·🔒 Privacy

New — Multimodal Knowledge Graph (MCP server).Seven new MCP tools ingest your documents — PDF, DOCX, XLSX, HTML, images (OCR), audio/video (local Whisper via@xenova/transformers+ ffmpeg), YouTube, and URLs — alongside your code into a queryable knowledge graph, then answer natural-language questions with citations:grasp_ingest,grasp_kg_ask,grasp_kg_trace,grasp_kg_explain,grasp_kg_stats,grasp_kg_export,grasp_llm_status. Alocal-firstmulti-LLM layer auto-detects Ollama before any cloud key and falls back to a zero-credential deterministic engine. Server-side only (Node MCP server, not the browser app) — seeMultimodal Knowledge GraphunderCode Intelligence.

+3 native AST languages— Bash, Elixir, and Julia take tree-sitter-backed function extraction, call counting, and complexity scoring to19 languages.

Optional MCP-over-HTTP bridge— setGRASP_HTTP_MCP=1to expose the MCP server over Streamable HTTP (bearer-token auth) so a whole team can share one Grasp instance instead of each running their own stdio server.

Previously in v3.20.0:Full security scanning suite —grasp_vulnerabilitiescovers5 threat vectors(OSV.dev dependency CVEs, NIST NVD container/runtime CVEs, local supply-chain integrity checks, Socket.dev behavioral analysis, and scheduledgrasp_vuln_watchmonitoring) withskip_container/skip_socket/skip_integrityfast-scan flags.

Previously in v3.19.0:Full visual + UX parity betweenteam-dashboard.htmlandindex.html— teal brand sweep, SVG icons, 7-provider auth, mobile More menu, keyboard shortcut popover.

Previously in v3.18.0:9 new MCP tools (graph analytics + LLM-context), 11 graph export formats, TypeScript path-alias + Python import resolvers, Claude Code slash commands, token-reduction eval harness (3,241× ongot@v14).

Total as of v3.21.0:150 MCP tools · 8 Resources · 2 Prompts · 35 languages · 11 graph export formats · 10 graph views · multimodal knowledge graph · 19 themes.

Graspturns any GitHub or GitLab repository — cloud or self-hosted — or local codebase into an interactive architecture map in seconds.150 MCP tools(plus 8 Resources and 2 guided Prompts) expose the full analysis engine to Claude Code, Cursor, and any MCP-compatible agent.

Paste URL / Open Folder → AST Analysis Engine → Architecture Map + 150 MCP Tools

Grasp is intentionally additive to whatever static-analysis or graph tool you already use. The axes that matter:

🕸️ Dependency Graph — see exactly how files connect

🏛️ Architecture Diagram — your codebase by layer

🏢 Team Dashboard — health across all your repos at a glance

git clone https://github.com/ashfordeOU/grasp.git open index.html # Main app open team-dashboard.html # Team Dashboard

No build step. Nonpm install.Two HTML files.

npm install -g grasp-mcp-server grasp ./my-project # Analyse a local folder grasp facebook/react # Analyse a GitHub repo grasp . # Analyse current directory grasp . --watch # Live mode — browser reloads on every file save grasp . --timeline # Time-travel — last 30 commits as a scrubber grasp . --report # Terminal-only report + JSON output grasp . --format=sarif # Export SARIF for GitHub Code Scanning grasp . --pr-comment # Print GitHub PR comment markdown to stdout grasp . --check # Enforce grasp.yml architecture rules (CI gate)

A floatingGraspbutton appears on every GitHub and GitLab page. Supports self-hosted GitLab, GitHub Enterprise, and any custom host via on-demand permission grants.

Every tagged release auto-publishes to all channels:

AI-tool integrations(Grasp called by your assistant via MCP or extension)

curl -sL https://github.com/ashfordeOU/grasp/releases/latest/download/grasp-safari-extension.zip \ -o /tmp/grasp-safari.zip \ && unzip -q /tmp/grasp-safari.zip -d /tmp/grasp-safari \ && mv /tmp/grasp-safari/Grasp.app /Applications/ \ && open /Applications/Grasp.app

Then in Safari:Settings → Extensions → enable Grasp. If it doesn't appear, enableSafari → Develop → Allow Unsigned Extensionsfirst.

┌──────────────────────────────────────────────────────────────────┐ │ Input │ │ github.com/owner/repo · gitlab.com/ns/proj · ./local/path │ └────────────────────────────────┬─────────────────────────────────┘ ▼ ┌──────────────────────────────────────────────────────────────────┐ │ Analysis Pipeline (mcp/src/) │ │ │ │ 1. scan file enumeration + gitignore │ │ 2. parse tree-sitter AST · 35 languages · 19 native │ │ 3. resolvers tsconfig path-alias · Jedi-style Python imports │ │ 4. routes HTTP route detection (Express/FastAPI/Gin) │ │ 5. tools MCP/gRPC tool definition detection │ │ 6. orm ORM query tracking (Prisma/TypeORM/Sequelize/SA) │ │ 7. scope 3-tier call resolver (0.95 → 0.90 → 0.50) │ │ 8. types cross-file type propagation (Kahn topo-sort) │ │ 9. coverage test-file detection → TESTS/COVERS edges (v3) │ │ 10. communities Louvain community detection on import graph │ │ 11. processes BFS execution-flow tracing from entry points │ │ 12. analytics degree centrality · Brandes betweenness · │ │ surprising-edge rarity · knowledge-gap detection │ │ 13. vulns OSV.dev SCA scan (npm/PyPI/Go/Cargo/Maven) │ └───────────┬──────────────────────────┬────────────────────────────┘ │ │ ┌───────▼─────────┐ ┌───────────▼─────────────────┐ │ Browser App │ │ MCP Server (CLI) │ │ index.html │ │ grasp-mcp-server │ │ │ │ │ │ 10 graph views │ │ 150 tools · 8 Resources │ │ 16 color modes │ │ 2 guided Prompts │ │ AI Chat (11p) │ │ Brain + Kuzu Schema v3 │ │ Ask Grasp │ │ Hybrid search (BM25+vector) │ │ Coverage overlay│ │ Graph analytics (5 tools) │ │ VULN tab │ │ LLM-context (4 tools) │ │ Try-it chips │ │ Graph exports (GraphML / │ │ Token indicator │ │ Cypher / Obsidian) │ │ Snapshot URLs │ │ Slash commands (3 in │ │ Compare modal │ │ .claude/commands/) │ │ Mid-fetch retry │ │ grasp setup (5 editors) │ │ Mobile touch │ │ grasp vulns / drift / org │ └─────────────────┘ └──────────────────────────────┘

Analysis flow (v3.18.0):the pipeline is additive — phase 12 (graph analytics) runs after the dependency graph is built and produces the data backinggrasp_hub_nodes,grasp_bridge_nodes,grasp_surprising_connections,grasp_knowledge_gaps, andgrasp_suggested_questions. Phase 13 only runs when a manifest (package.json,requirements.txt,go.mod,Cargo.toml,pom.xml) is present. Both browser and MCP server share the exact same pipeline output via the~/.grasp/brain.db+~/.grasp/graph/pair so a CLIgrasp indexand a browser analyze of the same repo are interchangeable.

InstantA–F gradebased on dead code, circular dependencies, coupling metrics, and security issues. Displayed as a score (0–100) with a visual bar.

Automatic detection of hardcoded secrets & API keys, SQL injection risks, dangerouseval()usage, and debug statements left in production.

🛡️ Dependency & Container Security Scanner(v3.17.0, expanded v3.20.0)

Five-layer security scan viagrasp_vulnerabilities:

- Dependency CVEs— declared deps (npm/PyPI/Go/Cargo/Maven) vsOSV.devpublic CVE database. Resolves pinned versions from lockfiles. Severity-classified with CVSS scores and fix-version suggestions. Health score deducts –5 per critical and –3 per high.
- Container/Runtime CVEs— parsesDockerfile(FROM image:tag),docker-compose.yml, and CI workflow YAML for pinned image versions, then queries
NIST NVD. SetGRASP_NVD_API_KEYfor higher rate limits.
- Supply-chain integrity— local checks (no network): npm lockfile sha512integrityfield coverage,go.sumalongsidego.mod,Cargo.lockalongsideCargo.toml,--hash=pinning inrequirements.txt.
- Behavioral analysis
Socket.devfree API scans npm packages for malware, supply-chain risk, and install-script signals (up to 50 packages per scan).
- Scheduled monitoringgrasp_vuln_watchMCP tool:start/stop/status/historyactions; periodic re-scans viasetInterval; persists scan history + CVE diffs inbrain.db.

Newgrasp vulns <path>CLI exits 1 on critical/high findings (CI-friendly).100% client-side— all API requests go directly from your machine to the respective services, never through a Grasp server.

Identifies Singleton, Factory, Observer/Event patterns, React hooks, and anti-patterns (God Objects, high coupling) — automatically.

"If I change this file, what breaks?"— select any file and see every downstream file that would be affected, highlighted on the graph.

Colors files by commit frequency. Works for GitHub repos (via API) andlocal repos(viagit log— no internet required).

TheDupcolor mode highlights files with exact or near-duplicate code. Thegrasp_similarityMCP tool returns ranked duplicate clusters for targeted refactoring.

🧠 Multimodal Knowledge Graph(MCP server)

Build a queryable knowledge graph from your codebaseandexternal documents, then ask natural-language questions with cited answers. Runs entirely inside the Node MCP server —notthe browser app.

grasp_ingestparses PDF, DOCX, XLSX, HTML, images (OCR), audio/video (local Whisper via@xenova/transformers+ ffmpeg), YouTube, and URLs; heavy parsers are optional, lazy-loaded dependencies. Entities and relations are taggedEXTRACTEDvsINFERREDwith source locators and persisted to SQLitekg.db; retrieval is hybrid BM25 + vector. Alocal-firstmulti-LLM layer auto-detects Ollama before any cloud key and falls back to a deterministic engine that needs zero credentials (Anthropic / OpenAI / Gemini / DeepSeek / Kimi / Azure / Bedrock / Ollama). The whole server can optionally be shared across a team over HTTP (GRASP_HTTP_MCP=1, optionalGRASP_HTTP_API_KEY, port7333,/health).

Top contributors per file from git history, with line-percentage breakdowns. One-click jump to GitHub Blame.

Paste a PR URL to see which files it touches and calculate the blast radius of proposed changes before merging.

Converts every architectural issue into developer-hours using configurable estimates — circular dep = 4h, god file = 16h, critical security = 8h — with a coupling multiplier. Shown in the health panel and Team Dashboard.

Click⋯ → 🔗 Embedfor a ready-to-paste<iframe>, README badge, React snippet, and direct link — share live health reports in docs, wikis, or dashboards.

🎯 Connection Confidence Scoring(v3.16.0)

Every cross-file connection is scored 0–1: explicit static imports = 1.0, same-folder = 0.8, cross-folder inferred = 0.6, low-frequency = 0.4. The force graph overlays confidence as edge opacity — use the slider in ⚙ settings to filter out low-confidence edges.

Click the 🔍 toolbar button to search files, functions, and edges in-browser without leaving the graph. Matches update live — click any file result to jump to it on the graph.

Toggle theƒ()button to switch the force graph from file-level to function-level nodes — see individual function call relationships, capped at 300 nodes for performance.

The right panel🗄️ DBtab scans file content for ORM patterns (Django, TypeORM, raw SQL), mapping which files reference which tables. Instantly spot god-tables and high-coupling files.

The🎯 GFItab surfaces isolated, low-complexity, untested files — ideal contribution targets for new engineers or AI coding agents.

🔐 PII Detection & Security Subcategories(v3.16.0)

The Security tab now has subcategory pills —ALL / SECRETS / INJECTION / PII / EVAL— to filter findings. The PII pill scans file content for email, phone, SSN, credit card, and API key patterns in source files.

📸 Architecture Drift Detection(v3.17.0)

Snapshot your codebase architecture and detect drift over time — automatically.

grasp snapshot ./my-project --name before-refactor # ... make changes ... grasp drift ./my-project # exits 1 if drift is CRITICAL (CI-friendly)

Snapshots are stored in~/.grasp/brain.dband persist across analysis sessions.

Find the functions most likely to cause production incidents — highest call count, zero test coverage.

grasp_coverage_gaps # via MCP — returns uncovered_functions sorted by call_count DESC

The dependency graph gains a🧪 Coverage overlaytoggle — uncovered functions render in red, partially-covered in amber, covered in green. Coverage is estimated by static analysis: Grasp detects test files (.test.,.spec.,test_,_test.) and traces which source functions they reference.

Analyse an entire GitHub organisation in one command:

grasp org my-github-org --token ghp_xxx --format html # Self-contained HTML dashboard grasp org my-github-org --format json # CI-consumable JSON grasp org my-github-org --format md # Markdown for wikis

Aggregates health grades, security findings, most-churned files, and language distribution across all repos (up to 500, 5 concurrent). The HTML output embeds Chart.js inline — no external dependencies.

Add automated architectural impact analysis to every pull request:

# .github/workflows/grasp-pr-impact.yml - uses: ashfordeOU/grasp/.github/actions/grasp-pr-impact@main with: github-token: ${{ secrets.GITHUB_TOKEN }} min-risk-to-comment: LOW # LOW / MEDIUM / HIGH / CRITICAL fail-on-risk: CRITICAL # fail the CI check at this risk level

The action posts a structured PR comment showing:

- Risk badge(LOW / MEDIUM / HIGH / CRITICAL) with colour coding
- Changed files with function-level blast radius
- Affected execution processes (with step counts)
- Suggested reviewers fromgit blame(top 2 contributors per affected file)
- Test coverage gaps: which changed functions have no test file touching them

Built-in AI assistant that knows your entire codebase. Ask"why is auth.ts a hotspot?","which files are safest to refactor?", or"explain the security issues in this call chain"— answers reference your live dependency graph, security findings, and architectural layers.

- Multi-turn conversation memory — persisted inlocalStorageacross page refreshes
- Selected-file context — layer, functions, complexity, and issues injected automatically when a file is selected
- Rich codebase context — top 80 files with metadata, all issues, security findings, circular deps, layer breakdown
- Markdown rendering with syntax-highlighted code blocks
- API key stays in your browser only, never sent anywhere except the chosen provider

Grasp Brain — Persistent Architecture Intelligence(v3.16.0)

Grasp Brain combines two persistent stores that work together:

- SQLite Brain(~/.grasp/brain.db) — file metadata, coupling, security, and issue index. Includes a FTS5 full-text index over functions and an in-process 384D vector embedding store (Xenova/all-MiniLM-L6-v2 — no cloud dependency). Index once, query instantly.
- Kuzu Graph DB(~/.grasp/graph/) — native graph database with Cypher query support. Stores the full function call graph, file imports, and type relationships as a traversable property graph.

Index once, then query instantly — no re-analysis needed. Every function is tagged with the execution processes it participates in (BFS from entry points), so search results include aprocesses[]field grouping matches by flow.

grasp index ./my-project → analysis stored in ~/.grasp/brain.db grasp context src/api.ts → instant file context from the stored index grasp diff ./my-project → compare current state vs stored baseline grasp daemon ./my-project → watch for changes, re-index automatically
grasp index <path> # Analyse and persist a repo to the brain grasp context <src> <file> # Get rich context for any file grasp setup [path] # Install hooks in Claude Code / Cursor / Windsurf grasp diff <path> # Compare current analysis vs brain baseline grasp daemon <path> # Watch directory and auto-reindex on changes grasp drift [path] # Snapshot + diff vs last snapshot; exits 1 on CRITICAL (CI-friendly) grasp org <github-org> # Org-level dashboard (--format json|html|md --token ghp_xxx) grasp vulns [path] # OSV.dev dependency vulnerability scan

Ask Grasp — Natural Language Architecture Queries

Both the browser app (Ask Grasp panel) andgrasp_askMCP tool support plain-English questions about your codebase.grasp_askrecognises structural intents directly; for open-ended queries it falls back tohybrid semantic search— BM25 full-text + 384D vector embeddings merged with Reciprocal Rank Fusion.

For pure semantic search without the question-answering layer, usegrasp_searchdirectly — results include aprocesses[]field showing which execution flows each match belongs to.

grasp_registry_listandgrasp_registry_statusexpose the full Brain index:

# Via MCP grasp_registry_list # all repos: health grade, files, functions, active sessions grasp_registry_status # aggregate: indexed count, session count, grade distribution # Via HTTP (when MCP server runs with --http) curl http://localhost:7332/api/v1/registry

The Team Dashboard🗂️ Registry panelauto-fetches this on load — no session_id needed.

grasp diff(andgrasp_arch_diffMCP tool) compares your current codebase against the stored brain baseline and surfaces:

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.