srinivasan-sundaresan95/orihime
by Various
Cross-repo code knowledge graph for Java/Kotlin/JS/TS — MCP server, taint analysis, call graph, OWASP reports. 95% fewer tokens than source-reading.
MCP
srinivasan-sundaresan95/orihime
Added 1 June 2026
Overview
A cross-repo code knowledge graph that serves as an MCP server for Java, Kotlin, JavaScript, and TypeScript. It performs taint analysis, builds call graphs, and generates OWASP security reports, claiming to use 95% fewer tokens than direct source code reading.
Best for
Best for
Developers needing efficient cross-repo vulnerability analysis and call graph visualization for Java, Kotlin, or JavaScript/TypeScript projects.
Use cases
- Analyze cross-repo code dependencies and call graphs
- Detect security vulnerabilities via taint analysis
- Generate OWASP-compliant security reports for multi-repo projects
How to use
Install
pip install -e . Tools exposed
serve-ssewrite-serverinstall-skillsORIHIME_DB_PATHORIHIME_SERVER_URLCALLS_RESTUNRESOLVED_CALLCONTAINS_CLASSCONTAINS_METHODDEPENDS_ONHAS_RELATIONOBSERVED_ATfind_callers
Tested with
Claude Desktop, Claude Code, Cursor
Notes
A cross-repo code knowledge graph that serves as an MCP server for Java, Kotlin, JavaScript, and TypeScript. It performs taint analysis, builds call graphs, and generates OWASP security reports, claiming to use 95% fewer tokens than direct source code reading.
0 stars on GitHub. Last updated 2026-05-15.
Use cases
- Analyze cross-repo code dependencies and call graphs
- Detect security vulnerabilities via taint analysis
- Generate OWASP-compliant security reports for multi-repo projects
Pros
- Dramatically reduces token consumption for LLM-based code analysis
- Covers multiple major languages (Java, Kotlin, JS/TS)
- Produces actionable OWASP security reports
Cons
- Zero GitHub stars indicates early stage or limited adoption
- Potential lack of community support and documentation
- Taint analysis accuracy may vary for complex codebases
Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.
Pros
- Dramatically reduces token consumption for LLM-based code analysis
- Covers multiple major languages (Java, Kotlin, JS/TS)
- Produces actionable OWASP security reports
Cons
- Zero GitHub stars indicates early stage or limited adoption
- Potential lack of community support and documentation
- Taint analysis accuracy may vary for complex codebases
Open-source & AI alternatives
Swap-in tools that solve the same job. Weigh the trade-offs before you commit.
Get the free Developer’s Field Guide
A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.
Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.
