Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/GetKlai/klaiInstalling this writes the configuration, not the program: `serena` has to be on your PATH already, or the server will not start.
Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/mcp/getklai/klai/serena)<a href="https://agentmods.dev/mcp/getklai/klai/serena"><img src="https://agentmods.dev/badge/mcp/getklai/klai/serena/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/mcp/getklai/klai/serena"><img src="https://agentmods.dev/badge/mcp/getklai/klai/serena.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
serena scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 14d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"serena": {
"$comment": "Semantic code navigation (find_symbol, find_referencing_symbols, replace_symbol_body) over LSP for Python and TypeScript. --project . binds Serena to the directory Claude Code spawns it in, which is the worktree root; --project-from-cwd guesses instead, and guesses wrong when Agent Teams spawn inside a worktree (oraios/serena#1496). --context claude-code drops Serena's own read/search/shell tools so it only adds the symbolic ones on top of Claude Code's native Read/Grep/Bash. no-onboarding suppresses the onboarding tool: this repo's knowledge lives in AGENTS.md and .claude/rules, and a per-worktree onboarding run would rebuild a throwaway copy of it every session. --open-web-dashboard False stops Serena opening a browser tab on every server start, which with one server per session per worktree is every session. It does not control whether the dashboard runs: web_dashboard in ~/.serena/serena_config.yml does, it is false on this machine, and nothing listens on 24282 as a result. Install and troubleshooting: docs/setup/mcp-servers.md Section 1.",
"type": "stdio",
"command": "serena",
"args": [
"start-mcp-server",
"--context",
"claude-code",
"--project",
".",
"--add-mode",
"no-onboarding",
"--open-web-dashboard",
"False"
],
"env": {}
}
}What else .mcp.json configures
This page is one entry in a file that holds 5. Installing the file brings all of them; each is measured and scanned on its own page.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 14d ago First seen · 19 lines scan A 4d47c545e977
serena is an MCP server published in the GitHub repository GetKlai/klai (11 stars, last pushed today), licensed MIT. Its token cost is not measured: an MCP server costs its tool schemas, not its config file. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-16.
Other mcp servers, from other repositories
pathfinder
MCP server "pathfinder" as configured in himkt/pathfinder. Launched with pathfinder -w . -e py -e pyi -s uvx ty server. Needs 1 environment variable to run.
prospector
Prospector is a tool to analyse Python code by aggregating the result of other tools. Runs locally from the prospector Python package.
codebase-index
CLI tool for quick summarization of JavaScript/TypeScript codebases with symbol extraction. Runs locally from the codebase-index npm package.
ohm-mcp
AST-based Python refactoring MCP server with safe automated refactorings and rollback. Runs locally from the ohm-mcp npm package.
ts-diagnostics-mcp
TypeScript diagnostics MCP server with monorepo support - live type checking without constant recompilation. Runs locally from the ts-diagnostics-mcp npm package.
python-code-guardian-mcp
Python code quality guardian - automated linting, complexity analysis, and code health monitoring via MCP. Runs locally from the python-code-guardian-mcp Python package.