Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

AIContextBuilder

NUGET · AICB-ROSLYN-MCP · SCANNED OCT 4

Symbol-aware C# and .NET code context for AI coding assistants.

Available components

71 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security100
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • No production dependencies, so there is no dependency health to assess. View diagnostics → Pass
Provenance & Transparency35
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Build provenance not yet verified. View diagnostics → Unverified
  • Licence could not be checked: the licence is shipped as a file inside the package, not declared as a standard (SPDX) licence identifier, so we cannot tell whether it is OSI-approved.Unverified
  • Actively maintained (last published 0 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability76
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 29267 tokens (~496/item across 59 items; 54 tools + 5 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management13
  • Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 54 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 56 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the AIContextBuilder MCP server?

AIContextBuilder runs locally as a NuGet package, launched with dnx aicb-roslyn-mcp@0.5.500.1 --yes. Ready-made configuration for Claude, Cursor, VS Code, Codex and 3 more is on this page, copied from each client's own documentation.

nuget · aicb-roslyn-mcp

# add to Claude Code
claude mcp add gregordadera-aicb-roslyn-mcp -- dnx aicb-roslyn-mcp@0.5.500.1 --yes
// .cursor/mcp.json
{
  "mcpServers": {
    "gregordadera-aicb-roslyn-mcp": {
      "command": "dnx",
      "args": [
        "aicb-roslyn-mcp@0.5.500.1",
        "--yes"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "gregordadera-aicb-roslyn-mcp": {
      "command": "dnx",
      "args": [
        "aicb-roslyn-mcp@0.5.500.1",
        "--yes"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add gregordadera-aicb-roslyn-mcp -- dnx aicb-roslyn-mcp@0.5.500.1 --yes
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "gregordadera-aicb-roslyn-mcp": {
      "type": "local",
      "command": [
        "dnx",
        "aicb-roslyn-mcp@0.5.500.1",
        "--yes"
      ],
      "enabled": true
    }
  }
}
# ~/.hermes/config.yaml
mcp_servers:
  gregordadera-aicb-roslyn-mcp:
    command: "dnx"
    args: ["aicb-roslyn-mcp@0.5.500.1", "--yes"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "gregordadera-aicb-roslyn-mcp": {
      "Transport": "stdio",
      "Command": "dnx",
      "Arguments": [
        "aicb-roslyn-mcp@0.5.500.1",
        "--yes"
      ]
    }
  }
}
// mcp.json
{
  "mcpServers": {
    "gregordadera-aicb-roslyn-mcp": {
      "command": "dnx",
      "args": [
        "aicb-roslyn-mcp@0.5.500.1",
        "--yes"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Oct 26 +2
    • Tool safety: pass → unverified ▼ security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Capabilities: pass → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • Schema quality: 100 → unverified ▼ functional
    • Schema quality: 556 → 496 ▲ functional
    • Stability: unverified → 0.13 ▲ functional
    • Package version: 0.5.465.11 → 0.5.500.1 functional
  • 1 Oct 26 +15
    • Malware scan: unverified → pass ▲ security
  • 30 Sept 26 54

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 8 Oct 2026 · Analysed nuget/aicb-roslyn-mcp@0.5.500.1

Provenance Inconclusive

We could not complete the check, so nothing is claimed either way. This is a gap on our side, not a finding about the package.

Result Inconclusive
Ecosystem nuget
Reason Signature present, unverified

Signer

Signed as Repository signature, names nuget.org
Subject CN=NuGet.org Repository by Microsoft,O=NuGet.org Repository by Microsoft,L=Redmond,ST=Washington,C=US
Issuer CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1,O=DigiCert\, Inc.,C=US
Valid from 23 Feb 2024
Valid until 18 May 2027
Service index https://api.nuget.org/v3/index.json
Owners GregorDadera

Background: How many MCP packages publish verified provenance →

Dependencies 0 packages
Packages resolved 0
Tree resolution Complete

Background: SBOMs and build attestations, explained →

Registry declarations For information only

What the registry and the package's own manifest say about this version. The publisher or the registry writes these, nothing here is verified, and none of it affects the score.

Project URL https://github.com/gregordadera/aicb-roslyn-mcp
MCP tools · 54 exposed · ~28,448 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
save_session ~348

Persist the current session's analyzed model as a named Manual snapshot in an aicb DB, so a later session can diff against it with compare_with_previous. Use it BEFORE a bulk mechanical change (a rename sweep, a signature migration) and call compare_with_previous afterwards. An ordinary edit needs no snapshot: git diff and the tests cover it. Returns JSON: snapshotId, sessionId, solutionId, name, lineNumbersAvailable and totalSnapshots (the snapshots that DB now holds for this solution). It writes to the aicb DB, not to the solution's source or configuration: one new snapshot row, plus the solution's record when the DB does not know the solution yet; a DB file that does not exist is created. Nothing is overwritten: every call adds a snapshot under a fresh id, and name is a label, not a key. Note: snapshots lose line numbers (StartLine/EndLine) on the DB round-trip. Parameters: sessionId is a live or recalled session's id or an absolute .sln path. Omit dbPath to use the server's standard config DB (the same one the GUI uses); when the server resolved none, the call fails with 'dbPath is required'.

NameTypeReqDescription
dbPathstring|null–Optional absolute path to the aicb SQLite DB to persist into. Omit to use the server's standard config DB.
namestringyesHuman-readable name for this snapshot (e.g. 'before refactor').
sessionIdstringyesThe session_id whose current state to snapshot. Also takes an absolute .sln/.slnx/.slnf path, analyzed on first use.

No output schema declared.

No examples provided.

server_info ~459

Report this SERVER's own identity and health: name, version, build commit, the config DB's schema version, and drift warnings about the server binary. Needs no session - a reachability smoke-check. Call it first after connecting and after an update or restart: the commit answers the question the version number cannot - 'is the binary I am talking to built from the code I just landed?'. It says nothing about a solution's configuration (solution_config_status: what is active; check_solution_config_drift: does it still fit the code), about which tools exist (list_skills) or about how they were used (usage_report). Returns plain text, not JSON. Line 1 is the identity: 'aicb MCP server (AIContextBuilder) v<version> (commit <sha>)'. Compare the commit against `git rev-parse HEAD` (the full sha is reported, so a short hash is a prefix of it): one version number can cover DIFFERENT builds. A build with no resolvable git revision omits the commit. 'Config DB schema: user_version=N (<path>)' follows when a config DB is resolved. Then, only when they apply: ANALYZER DRIFT - this build's commit against the HEAD of the repo holding the analyzed solution; it also reports in-sync and ahead, and is silent without an analyzed session and on a repo that does not know this commit (any foreign solution). SCHEMA DRIFT - the config DB's schema is newer than this binary: rebuild or reinstall. PENDING MIGRATION - the reverse: the DB is older; the line says how to migrate it. TOOL POOL DRIFT - the active profile lists tools this binary does not register: a newer build wrote it (rebuild or reinstall) or the tool was retired (re-save the profile). That check is tool-NAME level; a new parameter on an existing tool is not detected, the commit is the finer signal. CONFIG DRIFT - the active MCP profile changed since this server started: restart or reconnect to load the current tools and instructions. Read-only: it reads the config DB's schema version and, for the analyzer line, queries git i…

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

solution_config_status ~383

Check whether a solution's Layer Profile, Exclude-Namespaces and Test Profile have been initialized via the guided setup, and which Layer Profile / Exclusion List / Test Profile is currently active. 'initialized' is an explicit marker for all three slots (stamped by apply_solution_config - it is NOT inferred from having an active id, which a user can also set manually via the Settings panel); the testProfile slot additionally reports the effective per-solution active test-detection profile. Pass the session_id; dbPath is optional - omit it to use the server's default config DB (the same one the GUI uses), if the server resolved one. Each slot names the config IN FORCE for the analysis - resolved exactly as analyze_solution resolves it - and its source: 'db' (the per-solution row or the app-global default), 'sidecar' (the committed .aicb.json applies, which it does whenever the DB configured nothing for the axis - a built-in default is not configuration), 'built-in' (the DB's fallback exclusion list, applied only when no sidecar names one) or 'none' (the heuristic). A repo with a valid .aicb.json sidecar but no DB row reads initialized=true, source:sidecar, not a misleading uninitialized. Use this on solution start: if a slot is not initialized, offer to run init_solution_config + apply_solution_config.

NameTypeReqDescription
dbPathstring|null–Absolute path to the aicb config/master SQLite DB that holds the per-solution configuration. Omit to use the server's default config DB (the same one the GUI uses), if the server resolved one.
sessionIdstringyesThe session_id returned by analyze_solution. Also takes an absolute .sln/.slnx/.slnf path, analyzed on first use.

No output schema declared.

No examples provided.

solution_metrics ~570

The solution-wide quality rollup in one call - the numbers the CLI '--fail-on' quality gate evaluates. symbol_metrics ranks single methods; list_insights shows the findings behind the severity counts. Use it for a before/after number on a refactoring, or to try a gate expression. Returns metrics {typeCount, methodCount, complexityMax, complexityAvg, methodsOverComplexityThreshold, ceMax, caMax}, scope (always 'production'), testMethodCount, testTypeCount, severities {critical, warning, info, ok}, debtMinutes, debtRating, complexityThreshold, qualityProfile, layerProfile (when one is in force), knownGateMetrics and, with failOn, gate {expression, passed, violatedClauses}. degradedProducers appears when an insight producer failed; severities and debt are then incomplete. PRODUCTION code only - test projects, per the session's test profile, are excluded from every number, and testMethodCount / testTypeCount give the excluded side. Types are logical (partial fragments merged, multi-TFM deduplicated); methods exclude constructors and accessors. methodsOverComplexityThreshold counts STRICTLY greater than complexityThreshold, while symbol_metrics' minComplexity is inclusive. ceMax / caMax: coupling maxima. severities count insights - one per producer that found something - not findings. The rollup is NOT triage-filtered: suppressed and dismissed findings still count, as in the CLI gate, so debt and severities can be higher than what list_insights shows. failOn is evaluated over the tokens in knownGateMetrics; the gate is advisory - the blocking gate stays the CLI. It reads the active QualityProfile of the config DB in force (see dbPath). The layer profile behind the layer-violation severity is the session's, else that DB's. It writes nothing of its own, but opening a config DB whose schema is behind this binary migrates it. Works on a recalled session.

NameTypeReqDescription
dbPathstring|null–Optional path to an AIContextBuilder SQLite DB. When set, the complexity threshold and producer toggles come from that DB's active QualityProfile (same semantics as list_insights); omit to fall back…
failOnstring|null–Optional quality-gate expression to evaluate against the rollup (CLI '--fail-on' syntax, e.g. 'critical>0 OR debt>120min OR ce-max>50'). An invalid expression or unknown metric is rejected with the k…
sessionIdstringyesThe session_id returned by analyze_solution. Also takes an absolute .sln/.slnx/.slnf path, analyzed on first use.

No output schema declared.

No examples provided.

symbol_metrics ~708

Report method complexity: McCabe CYCLOMATIC complexity (independent paths) and COGNITIVE complexity (how hard the method is to follow: nesting is penalised, boolean-operator runs collapse), plus the parameter count - for one method by name, or as a ranking of the hotspots. solution_metrics gives the solution-wide rollup. Use it before touching an unfamiliar method, and to find where the complexity sits. Both metrics measure CODE SHAPE, not runtime cost; for a hot path use a profiler. With symbol (mode 'symbol'): every method unit of that exact, case-sensitive name - bare for all same-named ones, 'Type.Member' for one type's. scope, includeTests, minComplexity and rankByCognitive are ignored. Accessors, constructors and operators answer by metadata name ('get_Items', '.ctor', 'op_Equality'); '.ctor' is every constructor unit of the solution, 'Type..ctor' one type's. Without symbol (mode 'ranked'): methods only, sorted by cyclomatic complexity descending - by cognitive with rankByCognitive=true - and filtered to complexity >= minComplexity (inclusive; 0 = no floor). Returns scope, mode, metricMeaning, minComplexity, methodsScanned, methods - at most 200 items (name, declaringType, namespace, cyclomaticComplexity, cognitiveComplexity, parameterCount) - and when they apply 'note', minComplexityBoundary, 'nearest' (a close declared name when a lookup matched no method) and testMethodsFiltered. In a ranking, test-project methods are excluded by default (includeTests=true includes them); testMethodsFiltered counts those that cleared the floor, and the note names the strongest one when it would have ranked inside the shown list. The note also says when the two axes would have listed different methods. An empty ranking means nothing cleared the floor - or the scope matched nothing: methodsScanned 0 is the only sign. An empty lookup means no METHOD of that name; a bare property or type name gets a note saying so. Read-only; works on a recalled session.

NameTypeReqDescription
includeTestsboolean–When ranking: include test-project methods (default false - production hotspots; CC-heavy test harnesses would otherwise skew the top-N). Ignored in the by-name symbol lookup (which always returns th…
minComplexityinteger–When ranking (no symbol): only include methods whose ranking complexity (cyclomatic, or cognitive when rankByCognitive=true) >= this. 0 (default) = no filter.
rankByCognitiveboolean–When ranking: rank + filter by COGNITIVE complexity instead of cyclomatic (default false). Both numbers are always present per method; this only changes the sort + minComplexity axis. Ignored in the…
scopestring–When ranking: 'solution' (default) or a namespace prefix to narrow scope. Ignored when symbol is given.
sessionIdstringyesThe session_id returned by analyze_solution. Also takes an absolute .sln/.slnx/.slnf path, analyzed on first use.
symbolstring|null–Exact (case-sensitive) method name to report - bare (every same-named method) or in the qualified Type.Member form (that type's member only). Omit to rank all methods by complexity.

No output schema declared.

No examples provided.

symbol_signature ~417

Return a symbol's signature(s) WITHOUT the body: the type declaration, the method/operator signature or a member's declaration (property, field, event, enum member - the last as its qualified Enum.Member form), plus its XML <summary> doc and its declaring file + start line - for understanding an API without reading the whole file/body, and for navigating straight to it. 'file' is the fragment's OWN file (for a partial type a method points at the file the METHOD lives in, not at the first type fragment); it is omitted only when the snapshot carries no path, and a member's 'line' is null (no line fact is modeled for members). Exact (case-sensitive) name match; multiple results for overloads or name collisions. A member also takes 'Type.Member' (that type's only) and a type a qualified name ('Ns.Type', 'Outer.Inner'). A user-defined operator matches by its METADATA name ('op_Equality' / 'op_Implicit' / …). Leaner than get_context (which returns the full source). Returns a capped envelope (items/count/totalFound/truncated), max 50. Matching is EXACT, so a typo or case-mismatch returns an empty list rather than an error - when nothing matched, the response therefore carries a 'nearest' suggestion (the closest declared name), which distinguishes 'you spelled it differently' from 'this symbol genuinely has no signature' - and, where the run skipped generated C# under obj/, a 'generatedSourcesNote' naming the third possibility: the declaration exists in code this index never read.

NameTypeReqDescription
sessionIdstringyesThe session_id returned by analyze_solution. Also takes an absolute .sln/.slnx/.slnf path, analyzed on first use.
symbolstringyesThe exact (case-sensitive) type, method, property, field, event, enum-member or operator name (e.g. 'op_Equality'), bare or qualified ('Type.Member', 'Ns.Type').

No output schema declared.

No examples provided.

usage_report ~513

Report the server-side tool-call telemetry: what the CallTool filter recorded into the config DB's tool_calls table, across every client that used this DB - not this conversation's transcript. list_skills shows the pool; this shows what was called. Use it to see how heavily, how reliably and at what cost each tool is used. READ THE SCOPE FIRST: the filter sits on the tools/call pipeline ONLY. A sub-query inside batch or measure records the PARENT call and no child row, and a one-shot `aicb call` invocation records nothing at all - both measured with planted probes. So every count here is a LOWER BOUND, and a tool at 0 was not called THROUGH THIS DOOR rather than not called. A batch parent's row does carry a tally of its sub-queries, returned as subQueries: read it before calling a tool unused. Returns totals (totalCalls, errorCalls, errorRatePct, distinctTools, distinctSessions, firstTs, lastTs, clients, serverVersions); tools, ranked by calls, each with errors, duration (ms) and result size (chars) as average, p50, p90 and max, plus - when non-zero - errorClasses (exception type names; McpException is a failure the tool raised on purpose), argumentBindingErrors (the caller named an argument the tool does not have) and aliasApplied; protocolVersions and clientEras (who called, on which protocol revision); facets; subQueries; recordedVia; and poolCoverage (poolSize, poolToolsFired, poolToolsNeverCalled, outOfPoolTools). Read coverage THERE, not from distinctTools: that figure counts every tool called including ones outside the pool, so holding it against the pool size overstates coverage. The answer carries shapes only - names, counts, exception type names - no code, no argument values and no session reference. Without a readable config DB it answers available:false. Read-only and session-less. sinceDays narrows every figure to the last N days (1..3650, so 0 means one day; omit it for the whole log); the cutoff comes back as windowSinceIso.

NameTypeReqDescription
sinceDaysinteger|null–Only count calls from the last N days (omit for the whole log; clamped to 1..3650).
topToolsinteger–Cap on the per-tool breakdown, ranked by call count (default 30; clamped to 1..200).

No output schema declared.

No examples provided.

verify_claim ~567

Verify a structured claim about a change by diffing two analyzed sessions (baseline → changed). Supported claim types (MVP): 'no_new_api' (no types/methods were ADDED AND no method signatures changed) and 'symbol_removed_unused' (the named symbol was removed AND had no usages in the baseline's static fan-in graph). Returns a verdict of confirmed / refuted / indeterminate with a reason + evidence. NOTE THE SCOPE OF 'no_new_api': it is about ADDITIONS and SIGNATURE CHANGES, so a REMOVAL does not refute it - a change set that only deletes public API is legitimately 'confirmed'. Removals are therefore never silent: the reason states the boundary and every removal the same diff records is listed as evidence, prefixed '-'. For the removal question ask verify_claim(symbol_removed_unused), or diff_public_contract (outside the default profile's pool). Conservative in BOTH directions: what the diff cannot prove is never falsely confirmed - and never falsely refuted either, because 'was not removed' is a claim about the change that is only made once the string resolves to something this diff could report on. A name that resolves to nothing, a property/field/event/enum member (the diff models types and methods only), and the simple name of a removed type the diff had to render by its FULL name because it is ambiguous, each return 'indeterminate' naming that cause - not a confident 'was not removed'. A removed method whose only baseline callers called an interface or abstract member it implemented (find_usages' viaContract) is 'indeterminate' too: such a call ran its body only when the instance was of its type, and the reason says whether that credit was exact. Unsupported claim types return indeterminate.

NameTypeReqDescription
baselineSessionIdstringyesThe baseline session_id (before the change).
changedSessionIdstringyesThe changed session_id (after the change).
claimTypestringyesClaim type: 'no_new_api' or 'symbol_removed_unused'.
symbolstring|null–The symbol name the claim is about (required for symbol_removed_unused) - a bare name or the qualified Type.Member form, the same strings find_usages / impact_of_change / find_tests_for resolve. A re…

No output schema declared.

No examples provided.

Common questions

What is the AIContextBuilder MCP server?

AIContextBuilder is an MCP server listed in the public MCP registry as io.github.gregordadera/aicb-roslyn-mcp. Symbol-aware C# and .NET code context for AI coding assistants. This page covers its NuGet package (aicb-roslyn-mcp).

Is the AIContextBuilder MCP server safe to use?

AIContextBuilder scores 71 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the AIContextBuilder MCP server expose?

AIContextBuilder exposes 54 tools: coverage_gaps, impact_of_change, install_agent_hooks, docs, apply_solution_config, and 49 more. Their descriptions and schemas cost roughly 28,448 tokens of context every time the server is loaded.

Is the AIContextBuilder MCP server still maintained?

AIContextBuilder is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.