MITBenAHammond/code-auditor-mcp

Stop Shipping Broken Code.

You built it fast. Now make sure it actually works. Code Auditor reads your whole project, finds the bugs, and fixes them before you ship.

npm install -g code-auditor-mcp
code-audit install --agent all

What It Catches

Your site is going to crash.

for (const org of orgs) {
  const users = await db.select().from(users)
  org.users = users
}

This loop runs a database query for every single item. If you have 1,000 items, your site runs 1,000 queries. It will slow to a crawl and time out.

Code Auditor flattens this into one single query.

Your password is public.

const TEST_PASSWORD = "vvy8AUVvish34Fq"
await page.type("#password", TEST_PASSWORD)

That password is now stored in your Git history. Anyone who finds your repo has your credentials. It's not just a bug—it's a security breach.

Code Auditor catches this and tells you to move it to an environment variable.

Your app is stuck in a loop.

useEffect(() => {
  fetchData()
}) // Missing []

This runs on every single render. Your app will freeze, and your API bill will explode.

Code Auditor catches missing dependencies and infinite re-renders.

You just broke the architecture.

// In src/components/Header.tsx
import { chargeCustomer } from '../services/payment'

You're calling a payment service from a UI component. This creates a tangled mess that's impossible to refactor.

Code Auditor enforces module boundaries and blocks these imports.

Your colors are a mess.

color: #273828;
background-color: #1e2328;

You have 47 different shades of gray. Half of them are near-duplicates that don't match your design system. Dark mode will look broken.

Code Auditor catches style drift and tells you to use your design tokens.

Half your code is useless.

// 563 lines of code
// 0 imports anywhere

You have entire files that nothing uses anymore. They slow down your AI agent and waste tokens on every context window.

Code Auditor finds dead modules and tells you to delete them.

These are just examples. Code Auditor ships seven rule kinds plus built-in analyzers across TypeScript, JavaScript, Go, and CSS—from SQL injection and React mistakes to dead code and dependency cycles.

How It Works

  1. Audit Once

    Run it on your whole project. See every hidden bug.

  2. Install the Skill

    Your AI agent checks its own work. Works with Claude Code, Cursor, Codex, Gemini CLI, VS Code / Copilot, and ZCode.

  3. Ship Clean

    Critical mistakes are blocked before they hit your repo.

Fix It Before You Ship It.

One command. Your agent runs it on every edit.