Octocode
Coding · tested 2026-08-26 · re-test due 2026-11-24 · by the Hlido desk, not the vendor
In short: Evidence-first code research for AI agents — 13 read-only tools over GitHub, npm and local code that return answers with citations, shipped as an MCP server, a CLI, a skill and an agent harness, all MIT-licensed with no indexing.
5 PASS · 0 FAIL of 5 public-surface claims
Quick answer
Octocode scores 82/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-26). STEADY (82) because Octocode is agent-native on four surfaces (MCP, CLI, skill, agent bundle), read-only by default with secrets stripped, citation-grounded, MIT-licensed and index-free — a rigorous and safety-conscious Pricing: Open source (free entry point documented).
Octocode's pitch is unusually disciplined for the code-context field: instead of embedding your repo into a hosted index, it exposes 13 research tools that search GitHub, npm and local code and return answers grounded in real evidence with citations, so an agent cites source rather than guessing. It is deliberately read-only by default and strips secrets from both inputs and outputs — two safety properties most code-context tools do not advertise, and exactly the properties a coding agent operating on private repos needs. The surface is genuinely multi-modal: the same engine ships as an MCP server (`octocode-mcp`, one-click for Cursor/VS Code, paste-in for Claude Code/Windsurf/Zed), a CLI (`npx octocode`, 12 commands, JSON output, no AI host required), a SKILL.md protocol that orchestrates the tools into an evidence loop, and a Pi agent-extension bundle. It is free and open source under MIT, authenticates through your existing GitHub login, and needs no indexing step. The honest limits: the reviewed evidence is the marketing surface, not a measured tool run, so the '13 tools' and citation quality are described rather than independently benchmarked here; and there is a naming clash in the wild — an unrelated Rust tool by a different author also ships as 'Octocode', which can confuse discovery. Within its lane, the combination of read-only-by-default, secret-stripping, citation-grounded answers and a no-lock-in MIT license is a strong, agent-native posture.
Why STEADY
STEADY (82) because Octocode is agent-native on four surfaces (MCP, CLI, skill, agent bundle), read-only by default with secrets stripped, citation-grounded, MIT-licensed and index-free — a rigorous and safety-conscious posture for code research. Held at 82 rather than higher because the tool count and citation quality are described on the public surface rather than independently benchmarked in this review, and because an unrelated tool shares the 'Octocode' name, which muddies discovery.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — Evidence-first code research for AI agents — cited answers over GitHub/npm/local code
- PASS Cta present (required) — Installation / one-click MCP install / npx octocode
- PASS Pricing or access — Free & open source (MIT); GitHub auth; no hosted index
- PASS Evidence or demo — Tools page, installation guide, worked MCP config and command examples
What we saw
4 screenshots captured by the Hlido engine during the reviewed run (run-7aef41b06ea7a6fe-octocode-ai). Our own captures — not vendor marketing material.
What it does well
- Read-only by default and strips secrets from inputs and outputs — a safety posture built for agents on private repos
- Returns answers grounded in real evidence with citations instead of unsourced guesses
- Four agent-native surfaces from one engine: MCP server, CLI, SKILL.md protocol, and a Pi agent-extension bundle
- No indexing step and no hosted code index — authenticates through your existing GitHub login
- Free and open source under MIT, with a Rust-powered engine option
- Works across Cursor, Claude Code, VS Code, Windsurf and any MCP host with one-click or paste-in setup
What it fails at
- The reviewed surface is marketing/documentation, not a measured tool run — '13 tools' and citation quality are described, not independently benchmarked here
- An unrelated Rust tool by a different author also ships as 'Octocode', creating discovery ambiguity
- No pricing/commercial-support story — reads as a self-run developer tool
- Depth of results on very large private monorepos is not demonstrated on the public surface
Red flags
- Name collision: an unrelated Rust-based 'Octocode' (semantic search / knowledge graph) exists from a different author — confirm you are installing `octocode-mcp` from octocode.ai if that is the tool you want.
Best for
- Coding agents that need cited, evidence-backed answers about a codebase rather than guesses
- Teams that want read-only, secret-stripping code research on private repos with no hosted index
- Developers who want the same engine available as MCP, CLI and a repeatable skill
Not recommended for
- Teams that specifically want a hosted, pre-indexed semantic search product with SLAs
- Users who need embeddings-based ranking rather than tool-driven, cited retrieval
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
- Pricing findable on the public surfacePASS Free & open source (MIT); GitHub auth; no hosted index (tested 2026-08-26)
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-26.
Compared to
-
Serena
cited-evidence-research-vs-symbol-operations
Serena is an LSP-based semantic code toolkit; Octocode is an evidence-first research layer that returns cited answers across GitHub/npm/local code and is read-only with secrets stripped. Serena for symbol-level IDE-style operations, Octocode for cited cross-source research with an agent-safety posture.
-
codebase-memory-mcp
live-cited-retrieval-vs-persistent-memory
codebase-memory-mcp persists codebase memory for an agent; Octocode focuses on live, cited retrieval across GitHub/npm/local with no indexing. Memory tool for recall across sessions, Octocode for fresh evidence-grounded lookups.
Agent relevance
CLI MCP Behavioral-testable
Agentic-Commerce Readiness 62/100 · INTEGRABLE
Independent readiness for agent delegation & transaction. How it’s scored · check live
Primary path is the MCP server (`octocode-mcp` over stdio) connected to Cursor, Claude Code, VS Code, Windsurf or any MCP host, exposing 13 read-only research tools an agent calls to retrieve cited evidence from GitHub, npm and local code. The same engine is also a CLI (`npx octocode`, JSON output) for non-agent scripting and a SKILL.md evidence loop. Read-only-by-default and secret-stripping make it comparatively safe to hand to an autonomous agent.
Agent-friendly score: 9/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- 13 read-only tools search GitHub, npm and local code and return answers with citations, no indexing — source (2026-08-26) verified
- Read-only by default; secrets stripped from inputs and outputs; MIT licensed — source (2026-08-26) verified
- Ships as MCP server, CLI (npx octocode, 12 commands), a SKILL.md protocol, and a Pi agent extension — source (2026-08-26) verified



