Codebase Memory MCP
A local DeusData MCP server that indexes codebases into a searchable knowledge graph for coding agents.
- Skill Road
- Codebase Memory MCP
Categories
Description
Codebase Memory MCP is an open-source MCP server from DeusData for coding agents that need to understand the structure of an entire codebase rather than merely search individual files. The project runs as a local native application and builds a persistent knowledge graph from a repository. Instead of repeatedly feeding an agent directory listings, isolated files, and text-search results, MCP tools can search symbols, trace call chains, generate architecture overviews, or assess how a Git diff affects nearby code. The direct product link points to DeusData’s official product documentation; source, installers, releases, and security documentation are in the linked repository.
What Codebase Memory MCP analyzes
According to the provider, the server combines Tree-sitter parsing for 162 programming languages with additional semantic resolution for selected languages, including Python, TypeScript, JavaScript, PHP, C#, Go, C, C++, Java, Kotlin, Rust, and Perl. The result is more than text matches: it models relationships between functions, classes, imports, calls, HTTP routes, and in some cases cross-service links. The README says the MCP interface exposes 15 tools. They cover architecture and impact analysis, structural and full-text search, call graphs, dead-code discovery, Cypher-like queries, and Architecture Decision Record management.
That is useful when an agent takes over an unfamiliar application. Questions such as “Which request reaches this function?”, “Which files are affected by my change?”, or “Where is this service called?” otherwise require many small file operations and consume substantial model context. Codebase Memory MCP can query the previously built graph instead. It does not replace engineering judgment, but it can reduce the search effort and make the result more traceable because it relies on detected code relationships rather than name similarity alone.
Local operation and supported agents
The project ships native executables for macOS, Linux, and Windows according to the provider. It needs neither Docker, a language runtime, nor an API key. The official installer detects available coding agents and can write matching MCP configuration entries. For a more controlled setup, that configuration can be skipped and the server registered manually in the selected client. The repository lists many supported surfaces; Claude Code, OpenAI Codex, and Cursor are particularly relevant on Skill Road. Client support should still be checked in that client’s own MCP documentation before installation, since configuration formats and security prompts change over time.
The server can also provide a local graph viewer. Per the README, it runs on localhost by default and visualizes the resulting knowledge graph in a browser. For teams, that can complement agent queries: architectural assumptions can be examined together without exporting the full source code. The provider states that processing happens entirely locally. That does not automatically mean every connected AI model is local, however. Results passed from MCP to an agent can be sent to that client’s model provider, depending on the client and model in use.
Data, security, and boundaries
Codebase Memory MCP reads source code and, when automatic setup is selected, writes coding-agent configuration files. That behavior is intentional according to the provider, and it is precisely why a piped installation should not be run without review. The project itself advises users to inspect installers and source when appropriate. For published binaries, DeusData says it links hashes and VirusTotal results in release notes. Those are useful verification points, but not a substitute for an organization’s own security approval.
Its built-in coordination service can share indexes, watchers, and the local viewer across multiple agent sessions. This avoids duplicate background processes, but it also means teams should deliberately configure the cache location, workstation access, and automatic indexing. For particularly sensitive repositories, test in an isolated working copy before enabling persistent watching. A local server can still index secrets if they live in a repository, so sensitive files should never be committed and should not be included in a broadly configured analysis scope without review.
License, GitHub stars, and context
Codebase Memory MCP is licensed under MIT. When checked on 2026-09-07, the GitHub API reported 42,454 GitHub stars; this is a point-in-time figure, not proof of quality or security. The release marked “Latest” there was v0.10.8. The MCP server itself is available without a separate license charge according to the project. Indirect costs can still arise from the selected AI client, local compute resources, or an organization’s security-scanning requirements.
Who benefits most
The strongest fit is for medium-sized and large repositories where agents repeatedly need to resolve architecture questions, refactoring effects, or dependencies. Persistent graph queries can also lead to the relevant area faster than a sequence of unstructured searches in monorepos and cross-service changes. For a small script or a single file, building an index is usually unnecessary overhead; classic search and direct file tools are enough. Start with read-only analysis tasks, validate results against actual files, and only then enable automatic indexing or watchers for production projects.
Requirements
A local machine on a supported operating system (macOS, Linux, or Windows), an MCP-capable coding agent, and access to the repository to index. For the native installation path, the provider lists no Docker, language-runtime, or API-key requirement.
Installation instructions
Inspect the official installer before running it. By default it detects installed coding agents and configures their MCP entries. Use --skip-config for a binary-only installation, then register the server manually following the documentation of your own client. Restart the agent after installation and begin with a read-only task such as “Index this project.”
curl -fsSL https://raw.githubusercontent.com/DeusData/codebase-memory-mcp/main/install.sh | bash
Authentication
For local analysis, the provider lists no account login or API key. Access to a codebase is governed by the file permissions of the executing user account.
Required access permissions
The server needs read access to the repository being indexed. During automatic setup, the installer writes MCP configuration and accompanying agent files; manual setup can avoid or control that write access.
Transmitted or stored data
DeusData states that indexing and the knowledge graph are processed locally. Cache data, logs, indexes, and an optional local viewer reside on the user’s machine. Depending on the connected client, MCP results can be passed to its language model; that should be assessed separately from local indexing.
Security risks
The tool reads code and can write agent configuration during automatic installation. Review installers before running them, validate releases and hashes, and test sensitive repositories in isolation first. Enable automatic watchers only after deciding the cache location, access permissions, and handling of secrets present in a repository.
License and costs
- License
- MIT
- Cost
- free
According to the repository, the MCP server is freely usable under the MIT license. Costs can arise from the AI client used, local hardware, or internal security and operating requirements. See the provider for current information on optional products or services.
Alternatives
Not recorded yet.
At a glance
- Provider
- DeusData
- Status
- Official server
- Deployment
- Local
- Current version
- 0.10.8
- GitHub stars
- 45,070
- Last reviewed
- 07.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up Mapbox MCP Server
Set up the Mapbox MCP Server: hosted endpoint or local token, a first test, and sensible limits.
30.09.2026
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026