Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Topos

PYPI · TOPOS-MCP · SCANNED SEP 28

Structural code-quality tools for AI coding agents.

Available components

+34 this week 87 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security100
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • No production dependencies, so there is no dependency health to assess. View diagnostics → Pass
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to Krv-Labs/topos). View diagnostics → Pass
  • Clear OSI-approved license (BSD-3-Clause).Pass
  • Actively maintained (last published 11 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability81
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4143 tokens (~172/item across 24 items; 17 tools + 7 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management40
  • Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage98
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 93% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 17 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the Topos MCP server?

Topos runs locally as a PyPI package, launched with uvx topos-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · topos-mcp

# add to Claude Code
claude mcp add krv-labs-topos -- uvx topos-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "krv-labs-topos": {
      "command": "uvx",
      "args": [
        "topos-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "krv-labs-topos": {
      "command": "uvx",
      "args": [
        "topos-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add krv-labs-topos -- uvx topos-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "krv-labs-topos": {
      "type": "local",
      "command": [
        "uvx",
        "topos-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add krv-labs-topos --command uvx --arg topos-mcp
# ~/.hermes/config.yaml
mcp_servers:
  krv-labs-topos:
    command: "uvx"
    args: ["topos-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "krv-labs-topos": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "topos-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add krv-labs-topos -t stdio -c uvx -a topos-mcp
// mcp.json
{
  "mcpServers": {
    "krv-labs-topos": {
      "command": "uvx",
      "args": [
        "topos-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 +14
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 +15
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 −14
    • Malware scan: pass → unverified ▼ security
  • 23 Sept 26 +3
    • Stability: unverified → 0.23 ▲ functional
  • 22 Sept 26 +15
    • Malware scan: unverified → pass ▲ security
  • 21 Sept 26 −15
    • Malware scan: pass → unverified ▼ security
  • 20 Sept 26 +15
    • Malware scan: unverified → pass ▲ security
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 28 Sept 2026 · Analysed pypi/topos-mcp@0.6.0

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem pypi
Reason Verified
Discovered via Registry attestation endpoint
Source repo Krv-Labs/topos
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/Krv-Labs/topos/.github/workflows/release.yml@refs/tags/v0.6.0
Rekor log index 2860894984
Predicate type PyPI publish attestation https://docs.pypi.org/attestations/publish/v1
Subject digest sha256:b098a806d12e00d44990e66b3d5a6ba4ebc6b9ad33454d499a635bb3973cfd6d

Background: How many MCP packages publish verified provenance →

Dependencies 0 packages
Packages resolved 0
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 17 exposed · ~3,720 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
topos_assess_changeset ~171

Assess a multi-file changeset against a git baseline and roll the per-file verdicts into a project before/after (read-only). Use for a module split or any edit spanning several files. Each file is compared to `baseline_ref` (new files have no baseline). Flags `complexity_relocated_within_file` and `project_regression`. Returns a ChangesetResult.

NameTypeReqDescription
allowarray–One-off acknowledged dangerous-call patterns.
baseline_refstring–Git baseline ref each file is compared against.
filesarrayyesEdited file paths (working tree) that make up the changeset.
gitnexus_dirstring|null––
include_security_findingsboolean––
preferences––Optional generator ranking.

No output schema declared.

No examples provided.

topos_assess_improvement ~209

Compare a baseline to a side-by-side proposed variant (read-only). For normal edit-in-place loops, use `topos_assess_worktree_change` or snapshot first with `topos_begin_refactor` then `topos_assess_snapshot`. This tool is for variants supplied as `proposed_code` or `proposed_filepath`. Returns an AssessmentResult with `status` and score/metric deltas.

NameTypeReqDescription
allowarray–One-off acknowledged dangerous-call patterns.
current_codestring|null–Inline baseline source; COMPOSABLE is unavailable.
filepathstring|null–Baseline file path for side-by-side assessment.
gitnexus_dirstring|null––
include_security_findingsboolean–Include SECURE findings.
languagestring––
preferences––Optional generator ranking.
proposed_codestring|null–Proposed source.
proposed_filepathstring|null–Proposed file path.

No output schema declared.

No examples provided.

topos_assess_snapshot ~129

Assess the current file against a baseline captured by topos_begin_refactor. Loads the stored baseline by `snapshot_id` and compares it to the current on-disk file, with the same status semantics as `topos_assess_improvement`. A missing or expired snapshot is reported via `blocked_by`.

NameTypeReqDescription
allowarray–One-off acknowledged dangerous-call patterns.
filepathstringyesEdited file path.
include_security_findingsboolean–Include SECURE findings.
snapshot_idstringyesSnapshot id from topos_begin_refactor.

No output schema declared.

No examples provided.

topos_assess_worktree_change ~168

Assess an in-place edit against a git revision — the common refactor loop. Stateless: the baseline is read from git (`git show <baseline_ref>:<path>`, default `HEAD`) and compared to the current working-tree file. No prior call required. For untracked/new files or an uncommitted pre-edit baseline, use `topos_begin_refactor` + `topos_assess_snapshot`.

NameTypeReqDescription
allowarray–One-off acknowledged dangerous-call patterns.
baseline_refstring–Git baseline ref.
filepathstringyesEdited file path.
gitnexus_dirstring|null––
include_security_findingsboolean–Include SECURE findings.
preferences––Optional generator ranking.

No output schema declared.

No examples provided.

topos_begin_refactor ~112

Persist the file's current source as a baseline snapshot before you edit it (writes a snapshot record — its only side effect). Returns a `snapshot_id`; edit the file in place, then call `topos_assess_snapshot(snapshot_id, filepath)`. Use this when the baseline is not a committed git revision.

NameTypeReqDescription
filepathstringyesFile path to snapshot.
gitnexus_dirstring|null–.gitnexus directory.
preferences––Optional generator ranking.

No output schema declared.

No examples provided.

topos_calculate_coverage ~187

Measure how well a test suite exercises its program-under-test, via structural (UAST) coverage (read-only). A standalone signal, separate from the four-pillar quality lattice; for a quality verdict use `topos_evaluate_*` instead. Computes UAST bipartite declaration matching and k-gram path recall. Returns a CoverageResult.

NameTypeReqDescription
coverage_thresholdnumber–Minimum threshold for the declaration coverage policy.
include_unknownboolean–Whether to include Unknown UAST nodes in the analysis.
kinteger–Length of kind n-grams for path recall.
languagestring–Programming language (for parsing).
put_filesarrayyesPaths to the program-under-test files (relative to project root).
test_filesarrayyesPaths to the test suite files (relative to project root).

No output schema declared.

No examples provided.

topos_compare_code ~190

Compute the AST (tree-edit) distance between two source-code strings. Read-only and idempotent; parses both snippets in memory, never writes or scores. Use for clone detection or to measure refactor impact; the `topos_assess_*` tools already fold this in as an anti-gaming check, so call it directly only for the raw number. Returns a ComparisonResult: `normalized_distance` in [0, 1], `similarity` (= 1 - it), `raw_distance`, an `operations` edit-count map, and `source_valid`/`target_valid` (`error` set if either fails to parse).

NameTypeReqDescription
languagestring–python, rust, javascript, typescript, cpp, or go.
source_codestringyesBaseline code.
target_codestringyesProposed/target code.

No output schema declared.

No examples provided.

topos_compare_files ~98

Compute the AST (tree-edit) distance between two source files on disk. Read-only; parses both files, never writes or scores. Use for clone detection or refactor impact; use `topos_assess_*` for a quality verdict. Returns a ComparisonResult (see `topos_compare_code`).

NameTypeReqDescription
sourcestringyesBaseline file path.
targetstringyesComparison file path.

No output schema declared.

No examples provided.

topos_depgraph_status ~126

Report `.gitnexus` availability and freshness (read-only). Distinguishes a missing graph from a stale one and from a load/schema failure, so an agent knows whether COMPOSABLE can be trusted and what to do next. Never shells out and never mutates state.

NameTypeReqDescription
directorystring|null–Repo root to inspect (default: MCP file root / process project root).
gitnexus_dirstring|null–`.gitnexus` store under the project root (default: `<project root>/.gitnexus`).

No output schema declared.

No examples provided.

topos_evaluate_code ~204

Score a raw code string on the SIMPLE / SECURE / NAVIGABLE quality lattice (read-only; never writes or runs the code). Use for a snippet not yet on disk. SIMPLE, SECURE, and NAVIGABLE are reachable here (CFG/CPG/UAST); COMPOSABLE needs a module dependency graph, so for it use `topos_evaluate_file` with `gitnexus_dir`, or `topos_evaluate_project` for a whole tree. Returns an EvaluationResult: the lattice verdict (SLOP…IDEAL), per-generator scores, and a next-step agent contract.

NameTypeReqDescription
allowarray–One-off acknowledged dangerous-call patterns.
codestringyesSource code to evaluate.
languagestring–Language: python, rust, javascript, typescript, cpp, or go.
preferences––Optional generator ranking.
verboseboolean–Include raw metrics.

No output schema declared.

No examples provided.

topos_evaluate_file ~382

Score a file on disk on the SIMPLE / COMPOSABLE / SECURE / NAVIGABLE lattice — the only evaluate tool that can reach COMPOSABLE (side-effecting). Unless `no_composable` is set, this generates/refreshes `.gitnexus` (given by `gitnexus_dir` or auto-detected at `<root>/.gitnexus`) when it's missing or stale, then attaches the resulting ModuleDependencyGraph — the same default behavior as the CLI's `topos evaluate`. SIMPLE/SECURE/NAVIGABLE always run. When GitNexus isn't installed or generation fails, `coupling_available` is false and `warnings` explains why; the rest of the evaluation still succeeds.

NameTypeReqDescription
allowarray–One-off acknowledged dangerous-call patterns.
filepathstringyesSource file path.
gitnexus_dirstring|null–`.gitnexus` store under the MCP file root (default: `<file root>/.gitnexus`). Freshness and regeneration always use the file root as the project root; this only selects the store path inside it. If m…
include_security_findingsboolean–Include SECURE findings.
no_composableboolean–Skip GitNexus detection/generation; score SIMPLE/SECURE/NAVIGABLE only, exactly like a missing `.gitnexus` did before this tool started generating it automatically.
preferences––Optional generator ranking.
refactor_targetsinteger–Ranked edit targets to return, gate failures first (default 3; 0 = off; capped at 25).
verboseboolean–Include raw metrics.

No output schema declared.

No examples provided.

topos_evaluate_project ~558

Recursively score every supported source file in a directory on the SIMPLE / COMPOSABLE / SECURE / NAVIGABLE lattice, with a project rollup (side-effecting). Autodetects all supported languages (Python, Rust, JavaScript, TypeScript, C++, Go) in one walk — no language argument — and skips unsupported files. The rollup takes the project-wide minimum per dimension (weakest file floors it). Returns page-global named lists (`hard_fails`, `leaf_composable_zeros`, `maintainability_giants`) plus a paginated per-file table (gate failures first); page with `limit` / `offset`. Unless `no_composable` is set, generates/refreshes `.gitnexus` when missing or stale before scoring, same as `topos_evaluate_file` and the CLI's `topos evaluate` — `coupling_available`/`warnings` explain it when that isn't possible, without failing the evaluation.

NameTypeReqDescription
allowarray–Dangerous-call patterns to acknowledge for this run only.
gitnexus_dirstring|null–`.gitnexus` store under the MCP file root (default: `<file root>/.gitnexus`). Freshness and regeneration always use the file root as the project root; this only selects the store path inside it. If m…
include_security_findingsboolean–When true, attach per-file SECURE findings to each entry; off by default to keep responses compact.
limitinteger–Per-file rows to return per page (1–500, default 25).
no_composableboolean–Skip GitNexus detection/generation; score SIMPLE/SECURE/NAVIGABLE only, exactly like a missing `.gitnexus` did before this tool started generating it automatically.
offsetinteger–Zero-based row offset for pagination; pass the response's `next_offset` to fetch the next page.
pathstringyesDirectory to evaluate, walked recursively. Must resolve inside the trusted file root; paths outside it are refused. All supported languages are autodetected — no language argument is needed.
preferences––Optional ranking of simple/composable/secure (best first). The top-ranked generator sets scorer priority; omit to default to SIMPLE priority.
verboseboolean–When true, include each file's raw metric values alongside scores.

No output schema declared.

No examples provided.

topos_generate_depgraph ~114

Generate the `.gitnexus` dependency graph via GitNexus (side-effecting). Ensures the graph by default: no-ops when current, otherwise runs `gitnexus analyze`. `force=true` always regenerates.

NameTypeReqDescription
directorystring|null–Repo root to analyze (default: MCP file root / process project root).
forceboolean–Regenerate even when current.
gitnexus_dirstring|null–`.gitnexus` store under the project root.

No output schema declared.

No examples provided.

topos_get_doc ~155

Return a Topos documentation page as Markdown. Use when your MCP client does not expose resource fetching to the agent. Clients that do surface resources should prefer the equivalent resource URI for efficiency: `topos://docs/{topic}`. Topics: `agent-contract` (compact loop contract, read first for refactors), `lattice` (the 16-element H(G_qual) over four generators), `metrics` (every metric key, thresholds, interpretation), `preferences` (strict generator rankings and preference walks), `priority` (priority profiles), `workflows` (the expanded refactor loop guide).

NameTypeReqDescription
topic–yesagent-contract | lattice | metrics | preferences | priority | workflows

No output schema declared.

No examples provided.

topos_inspect_code ~496

Full metric breakdown for a single code unit (inline string or file). Provide exactly one of `code` or `filepath`. Use when you need the per-function detail behind a verdict; use `topos_evaluate_*` when the medal alone is enough. Returns an InspectionResult: the lattice `evaluation`, a *top-N* function complexity table (`top_n_functions`, default 10), `total_functions`, and entropy details. With `filepath`, the verdict is scored on all four generators and agrees with `topos_evaluate_file`: unless `no_composable` is set, this generates/refreshes `.gitnexus` (given by `gitnexus_dir` or auto-detected at `<root>/.gitnexus`) when missing or stale, then attaches the ModuleDependencyGraph — so this tool is side-effecting. With inline `code` there is no module to place in the graph, so only SIMPLE/SECURE/NAVIGABLE are reachable, as in `topos_evaluate_code`.

NameTypeReqDescription
allowarray–One-off acknowledged dangerous-call patterns for this inspection.
codestring|null––
filepathstring|null–Path to the source file inside the project root. Prefer this for large files.
gitnexus_dirstring|null–`.gitnexus` store under the MCP file root (default: `<file root>/.gitnexus`). Freshness/regeneration use the file root as the project root; this only selects the store path. Only used with `filepath`…
languagestring–Language for inline `code`; ignored for `filepath`, which is autodetected from the file extension.
no_composableboolean–Skip GitNexus generation; score whatever `.gitnexus` is already there, or SIMPLE/SECURE/NAVIGABLE only when there is none.
preferences––Strict total order on the four generators; see `topos://docs/preferences`.
top_n_functionsinteger–Return at most this many functions, sorted by descending cyclomatic complexity. Keeps agent context lean on large files.
verboseboolean–Include raw probe metric floats under each file in the response.

No output schema declared.

No examples provided.

topos_preference_walk ~197

Turn a generator ranking into a preference-ordered relaxation walk. Pure and read-only (lattice math only; no files, no scoring). Call after an evaluation to pick the next verdict to aim for, or to relax the goal gracefully under a token/time budget. Returns a PreferenceWalkResult: `walk` (steps from target down to just above `current`), `next_step`, `progress` in [0, 1], `aspirational_target`/`fallback_target`, and `induced_order` (all 16 verdicts ranked).

NameTypeReqDescription
current––Optional current verdict; truncates the walk to steps strictly above it and sets `next_step`. Defaults to the full walk.
rankingarrayyesPermutation of {simple, composable, secure}, most-preferred first.
target––Optional aspirational-target override; defaults to IDEAL.

No output schema declared.

No examples provided.

topos_refactor ~224

Rank structural refactor hotspots for one file (read-only, advisory). Does not score the four pillars — use `topos_evaluate_*` for medals and `topos_assess_*` to verify edits afterward. `target` selects the engine: `cycles` (CFG loop/branch bodies), `dependencies` (MDG Forman curvature on imports; needs `.gitnexus`), or `process` (execution choke points; needs `.gitnexus`). Returns a RefactorResult with ranked `hotspots` (`kind`, `label`, `score`, `suggestion`, optional lines).

NameTypeReqDescription
filepathstringyesSource file path relative to the MCP file root.
gitnexus_dirstring|null–Override `.gitnexus` directory (`dependencies` / `process` targets).
limitinteger–Maximum hotspots to return (default 5).
target–yesWhich analysis engine to run: `cycles` (CFG), or `dependencies` / `process` (need `.gitnexus`).

No output schema declared.

No examples provided.

Common questions

What is the Topos MCP server?

Topos is an MCP server listed in the public MCP registry as io.github.Krv-Labs/topos. Structural code-quality tools for AI coding agents. This page covers its PyPI package (topos-mcp).

Is the Topos MCP server safe to use?

Topos scores 87 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 28 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Topos MCP server expose?

Topos exposes 17 tools: topos_assess_changeset, topos_assess_improvement, topos_assess_snapshot, topos_assess_worktree_change, topos_begin_refactor, and 12 more. Their descriptions and schemas cost roughly 3,720 tokens of context every time the server is loaded.

Is the Topos MCP server still maintained?

Topos is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the Topos MCP server under?

Topos declares the BSD-3-Clause licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.