Back to Home
3D-Tech-Solutions icon

code-scalpel

Verified Safe

by 3D-Tech-Solutions

Overview

Code Scalpel provides a robust, multi-language code analysis and transformation platform for AI agents, integrating deep static analysis, security scanning, refactoring, and project-wide insights to enable AI to understand and modify code effectively.

Installation

Run Command
scalpel-server --host 127.0.0.1 --port 8080 --transport http

Environment Variables

  • SCALPEL_ROOT
  • CODE_SCALPEL_LICENSE_KEY_PATH
  • CODE_SCALPEL_LICENSE_KEY
  • CODE_SCALPEL_TIER
  • CODE_SCALPEL_GOVERNANCE_CONFIG_DIR
  • CODE_SCALPEL_AUDIT_SECRET
  • SCALPEL_LOG_LEVEL
  • PATH
  • PYTHONPATH
  • DOCKER_HOST
  • MCP_SERVER_HTTP_ALLOW_LAN_HOST

Security Notes

The server implements extensive internal security controls, including a robust policy engine (OPA-based with Rego rules), cryptographic verification of policies, tamper resistance for critical configurations, strict input validation, and secure path resolution. It proactively analyzes security vulnerabilities *in* the code it processes rather than exposing direct code execution risks. However, processing arbitrary code strings and file paths, even for analysis, carries inherent risks such as potential resource exhaustion (DoS) or exploitation of parser vulnerabilities if not adequately sandboxed and monitored externally.

Similar Servers

Stats

Interest Score0
Security Score8
Cost ClassHigh
Stars0
Forks0
Last Update2026-01-19

Tags

AI AgentsCode AnalysisStatic AnalysisSecurity AuditingCode RefactoringPolyglotASTPDGSymbolic ExecutionGovernance