Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

ai.papyruslabs/seshat-mcp

NPM · @PAPYRUSLABSAI/SESHAT-MCP · SCANNED OCT 7

Structural code intelligence for AI agents: real call graphs, blast radius, and change history.

70 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 92 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability75
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4070 tokens (~150/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 27 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the ai.papyruslabs/seshat-mcp server?

ai.papyruslabs/seshat-mcp runs locally as an npm package, launched with npx -y @papyruslabsai/seshat-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @papyruslabsai/seshat-mcp

# add to Claude Code
claude mcp add ai-papyruslabs-seshat-mcp -- npx -y @papyruslabsai/seshat-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "ai-papyruslabs-seshat-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@papyruslabsai/seshat-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "ai-papyruslabs-seshat-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@papyruslabsai/seshat-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add ai-papyruslabs-seshat-mcp -- npx -y @papyruslabsai/seshat-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "ai-papyruslabs-seshat-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@papyruslabsai/seshat-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add ai-papyruslabs-seshat-mcp --command npx --arg -y --arg @papyruslabsai/seshat-mcp
# ~/.hermes/config.yaml
mcp_servers:
  ai-papyruslabs-seshat-mcp:
    command: "npx"
    args: ["-y", "@papyruslabsai/seshat-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "ai-papyruslabs-seshat-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@papyruslabsai/seshat-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add ai-papyruslabs-seshat-mcp -t stdio -c npx -a -y @papyruslabsai/seshat-mcp
// mcp.json
{
  "mcpServers": {
    "ai-papyruslabs-seshat-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@papyruslabsai/seshat-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Oct 26 +15
    • Malware scan: unverified → pass ▲ security
  • 2 Oct 26 55

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 9 Oct 2026 · Analysed npm/@papyruslabsai/seshat-mcp@0.20.2

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Dependencies 92 packages
Packages resolved 92
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 27 exposed · ~3,185 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
find_by_constraint ~220

Find every function with a specific syntactic constraint tag — AUTH (requires authentication), DB_ACCESS (touches database), THROWS (explicit throw statement), PURE (no side effects), NETWORK_IO (makes HTTP calls), VALIDATED (has input validation). Also supports table-level queries: pass table="walks" to find every function that reads or writes the walks table (answers "what touches this table?" for schema migrations). Constraints are extracted from source syntax, not inferred. For semantic/behavioral properties (e.g., "can fail transitively"), use query_traits instead.

NameTypeReqDescription
constraintstringyesConstraint tag to search for: AUTH, VALIDATED, PURE, THROWS, DB_ACCESS, NETWORK_IO, IMP, etc.
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.
tablestring–Optional: filter to functions that touch a specific database table (e.g., "walks", "users"). Returns structured db_operations showing read/write/mutate per function.

No output schema declared.

No examples provided.

find_dead_code ~94

Find functions that nothing calls. Walks the call graph from all entry points (routes, exports, tests) and flags symbols that are unreachable. Use this during cleanup or before a release to find safe deletion candidates.

NameTypeReqDescription
include_testsboolean–Include test entities in dead code results (default: false)
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

find_entry_points ~117

List the ways into the system: route/controller handlers, test entries, framework plugin registrations, and exported symbols (the public API surface), classified by kind and ranked by reach. Call it first when orienting in an unfamiliar codebase — it answers "where does execution start, and what is the public surface?" Complements list_modules (structure) and find_dead_code (its exact inverse: these are the reachability roots).

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

find_error_gaps ~77

Find crash risks: functions that throw or have network/DB side effects whose callers don't catch errors. Returns the specific caller→callee pairs where exceptions can propagate unhandled. Use this before shipping to find missing error handling.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

find_exposure_leaks ~65

Find places where public/API code directly accesses private internals, bypassing the intended abstraction boundary. Use this during API design reviews or before extracting a module.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

find_layer_violations ~68

Find places where the architecture is broken — a database repository calling a route handler, a utility importing a component. Returns every backward or skip-layer dependency that violates clean architecture.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

find_ownership_violations ~95

Find memory and lifecycle issues — entities with complex ownership, unsafe blocks, escaping references, or illegal mutability on borrowed data. Returns 0 for most JS/Python codebases — a non-zero result in those languages indicates a serious boundary violation worth investigating. Most detailed results for Rust and C++.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

find_semantic_clones ~94

Find duplicated logic across the codebase. Normalizes variable names and compares code structure to catch identical algorithms in different files — even across different languages. Use this before a DRY refactor.

NameTypeReqDescription
min_complexitynumber–Minimum logic expressions to count as a match (default: 5)
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_account_status ~40

See your current plan, available tools, and credit balance. Call this if a tool returns a tier error or you want to know what tools are available.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_auth_matrix ~152

Audit authentication coverage. Shows which API routes and controllers require auth and which don't, plus inconsistencies like database access without auth checks. For large codebases, use the module parameter to drill into a specific module/directory. Most useful for backend codebases with middleware-based auth. Frontend frameworks (React, Vue) handle auth via component wrappers, which this tool won't detect as AUTH constraints.

NameTypeReqDescription
layerstring–Filter to a specific layer: "route" or "controller" (optional).
modulestring–Filter to routes/controllers in a specific module or directory path (optional).
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_blast_radius ~126

Before modifying a function, call this to see everything that could break. Returns all transitively affected symbols — both upstream callers and downstream callees — with distance from the change point. Like git log --follow but for runtime impact. Designed for repeated use: as you discover new symbols with other tools, call this again on them to expand your understanding of the affected surface.

NameTypeReqDescription
entity_idsarrayyesArray of entity IDs or names to compute blast radius for
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_co_change_clusters ~129

The codebase's hidden modules: groups of symbols that historically change together (≥3 shared commits, sweep commits excluded), computed from real commit history. Clusters that span multiple directories reveal coupling the file tree doesn't show. Call it when planning a change or splitting work across agents — touching one member of a cluster usually means touching the rest, even when no static dependency connects them. Correlation evidence, honestly framed; complements get_blast_radius (static reach) with empirical reach.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_coupling_metrics ~124

Measure how tangled your code is. Returns coupling (cross-boundary dependencies), cohesion (within-group dependencies), and instability scores. High coupling + low cohesion = refactoring candidates. Start with group_by: "layer" for the architectural health view ("are my controllers more coupled than my services?"), then drill into group_by: "module" for specific hotspots.

NameTypeReqDescription
group_bystring–Group entities by module or layer (default: module)
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_data_flow ~86

See what data a function reads, returns, and mutates (DB writes, state changes). Use this when debugging data bugs or when you need to verify whether a function has side effects before refactoring it.

NameTypeReqDescription
entity_idstringyesEntity ID or name
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_dependencies ~132

Trace who calls a function and what it calls, up to N levels deep. Use this instead of grep-for-function-name when you need the actual call chain — returns the dependency graph, not text matches. Covers callers (upstream), callees (downstream), or both.

NameTypeReqDescription
depthnumber–How many levels deep to traverse (default: 2)
directionstring–Which direction to traverse (default: both)
entity_idstringyesEntity ID or name
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_entity ~106

Get everything about one function or class — its signature, callers, callees, data flow, constraints, source location, and database operations (which tables it reads/writes). Use this when you need to deeply understand a single symbol before modifying it. Returns more than reading the source file because it includes the dependency context.

NameTypeReqDescription
idstringyesEntity ID or name
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_hotspots ~138

Project-level change-history orientation: the most-changed entities (and what kind of change dominates each), low-survival thrash spots where changes don't stick, heavily-depended-on entities that haven't changed all window (interface freeze), and directories with no recent changes. Call it after list_modules when orienting in a codebase — it answers "where does development actually happen, and where does it fail?" from commit history rather than current structure. Complements get_lineage (one entity's story) with the project-wide map.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_lineage ~147

The change history of one symbol, typed by what kind of change each commit made (body, calls, data, signature, constraints…), with CI verdicts, reverts, rename tracking, co-change partners, and rejected PRs that touched it. Call before modifying anything load-bearing: it answers "how does this entity usually change, and what happened last time someone tried?" — which no text diff can. Complements get_blast_radius (current impact) with history (past behavior).

NameTypeReqDescription
entity_idstringyesEntity ID or name to fetch change history for
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

get_optimal_context ~169

Before working on a function, call this to get the most relevant related code ranked by importance and fitted to a token budget. Returns a prioritized reading list of symbols you should understand — better than guessing which files to open. Designed for iterative use: call it on your target, read the top results, then call it again on any surprising dependencies to build a complete picture.

NameTypeReqDescription
max_tokensnumber–Token budget for the context window (default: 8000)
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.
strategystring–Traversal strategy: bfs (faster, local neighborhood) or blast_radius (full affected set)
target_entitystringyesEntity ID or name to build context around

No output schema declared.

No examples provided.

get_test_coverage ~99

See which production functions are actually exercised by tests via the call graph — semantic coverage, not line coverage. Optionally ranks uncovered functions by blast radius so you know which missing tests are riskiest.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.
weight_by_blast_radiusboolean–Rank uncovered entities by blast radius to prioritize testing (default: false, slower)

No output schema declared.

No examples provided.

get_topology ~82

Get the full API surface map in one call — all routes, middleware, auth patterns, and database tables. Use this when you need to understand the overall architecture without reading every file. Returns the information you'd normally piece together from dozens of file reads.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

list_modules ~96

Get a bird's-eye view of how the codebase is organized. Groups all symbols by architectural layer (route/service/component), module, file, or language with counts. Use this to orient yourself in an unfamiliar codebase before diving into specifics.

NameTypeReqDescription
group_bystring–How to group entities (default: layer)
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

list_projects ~50

Start here. Returns all synced codebases with their size, language, and project name. You need the project name for every other tool. If this returns empty, use sync_project to import the current repo.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

query_entities ~193

Like grep but for code structure. Find functions, classes, and routes by name, architectural layer (route/service/component), or module. Returns matching symbols with their type, file, and layer — use this instead of grep when you need to find code by what it does, not by text content.

NameTypeReqDescription
languagestring–Filter by source language: javascript, typescript, python, go, rust, etc.
layerstring–Filter by architectural layer: route, controller, service, repository, utility, hook, component, schema
limitnumber–Max results to return (default: 50)
modulestring–Filter by module (partial match)
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.
querystring–Search term — matches against symbol name, ID, source file, and module

No output schema declared.

No examples provided.

query_traits ~144

Find functions by inferred behavioral trait — "fallible" (can fail, including transitively via callees that throw), "asyncContext" (carries async state), "generator" (yields values). Traits are semantic properties inferred from the call graph, not just syntax. Use this when you need to find all code with a specific capability. For syntactic tags (explicit throw statements, DB access), use find_by_constraint instead.

NameTypeReqDescription
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.
traitstringyesThe trait or capability to search for (e.g., "fallible", "asyncContext")

No output schema declared.

No examples provided.

sync_project ~161

Import a public GitHub repo into Seshat for structural analysis. Call this when list_projects returns empty or when the user wants to analyze a new repo. Detects the git remote automatically if no URL is provided. Extraction typically takes 5-30 seconds. After syncing, call list_projects to confirm the project is available. Use force: true to re-extract even if a cached snapshot exists (useful after code changes or when Seshat extraction has been updated).

NameTypeReqDescription
forceboolean–Force re-extraction even if a cached snapshot exists. Default: false.
repo_urlstring–Public GitHub repo URL (e.g., https://github.com/org/repo). If omitted, tries to detect from the current git remote.

No output schema declared.

No examples provided.

trace_data_path ~181

Follow data from one function through the call graph to its sinks. From a start entity it walks callees, records the data each hop consumes/produces/mutates, and reports the chain from the start to every sink the data reaches — database writes, network egress, filesystem writes — plus the tables touched. Call it before changing a function that handles real data: it answers "where does this data end up?", the cross-call composition get_data_flow (one entity) cannot give. Flags untrusted inputs at the source.

NameTypeReqDescription
entity_idstringyesEntity ID or name to trace data flow from
max_depthnumber–How many call hops to follow downstream (default: 5, max: 8)
projectstring–Project name (required in multi-project mode). Use list_projects to see available projects.

No output schema declared.

No examples provided.

Common questions

What is the ai.papyruslabs/seshat-mcp server?

ai.papyruslabs/seshat-mcp is listed in the public MCP registry as ai.papyruslabs/seshat-mcp. Structural code intelligence for AI agents: real call graphs, blast radius, and change history. This page covers its npm package (@papyruslabsai/seshat-mcp).

Is the ai.papyruslabs/seshat-mcp server safe to use?

ai.papyruslabs/seshat-mcp scores 70 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 7 October 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the ai.papyruslabs/seshat-mcp server expose?

ai.papyruslabs/seshat-mcp exposes 27 tools: get_account_status, list_projects, sync_project, query_entities, get_entity, and 22 more. Their descriptions and schemas cost roughly 3,185 tokens of context every time the server is loaded.

Is the ai.papyruslabs/seshat-mcp server still maintained?

ai.papyruslabs/seshat-mcp is still listed as active in the MCP registry. We last reached this channel on 7 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the ai.papyruslabs/seshat-mcp server under?

ai.papyruslabs/seshat-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.