
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
Compiler-backed C#/.NET code intelligence for coding agents. Explore symbols and call graphs, inspect diagnostics, analyze complexity, dependencies, and impact, and safely edit and refactor solutions through MCP.
Glider is a semantic C#/.NET MCP server for code navigation, diagnostics, analysis, and refactoring. It gives your coding agent what your IDE gives you: go to definition, find references, safe rename. These are compiler-backed facts, not text search and guesswork. Your agent spends fewer tokens and returns better answers.
Prerequisite: .NET 10 SDK.
dotnet tool install --global glider
If install fails, run dotnet --version first. If dotnet is missing or below 10, install .NET 10 from:
https://dotnet.microsoft.com/download/dotnet/10.0
load, sync, reload, unloadfind_code, search_symbols, resolve_symbol, get_symbol_info, get_symbol_at_positionfind_references, find_overrides, find_implementations, get_type_hierarchy, find_callersget_diagnostics, diagnostic_hotspots, semantic_query, search_textrename_symbol, move_type, move_member, add_member, add_type, organize_usings, format_document, write_fileanalyze_change_impact, get_cascade_impact, get_project_graph, find_package_usagesbatchFor general code navigation, find_code is the recommended first tool to try. The full tool reference lives at https://glidermcp.com/glider/tools.
search_text searches only the loaded solution or project. It skips a file that no loaded project references.
For repo-wide, all-language search, add Scout as its own MCP server and call its find tool. It is the fastest search you can give a coding agent. In our benchmarks, on a warm index, it answered every text search faster than ripgrep (1.9–2.2×). It ran 42–51× faster than GNU grep.
Scout also answers questions no text search can express. An agent asks in plain English: "where request retries are limited". Scout finds the code even when the code uses none of those words. Your agent no longer guesses at grep patterns. Structural search matches the shape of the code, not its text. Fuzzy search finds a file from a name you remember only in part.
Plain-English search is opt-in. Start Scout with --semantic, or set semantic.enabled = true in its config. Scout then embeds the workspace once, in the background. That pass took about 10 hours for 0.87 GB of code in our benchmark. Lexical search does not wait for it. The text index is ready in seconds, and Scout answers plain-English questions with text search until the embeddings are ready.
glider
glider --transport http
Default HTTP MCP endpoint: http://localhost:5001/mcp
Useful flags:
glider --default-timeout 30m
glider --build-host netframework
glider --msbuild-path "C:\Program Files\Microsoft Visual Studio\2022\Community\MSBuild\Current\Bin"
glider --port 8080
glider --solution "C:\repos\app\src\App.sln"
glider --solution "C:\repos\app\src\App.sln" --workspace "C:\repos\app"
glider --solution "C:\repos\app\src\App.sln" --no-watch
glider --verbose
glider --help
glider --version
--default-timeout — supports ms, s, and m suffixes. Use 0 to disable the server-side timeout.
--build-host — accepts auto, netframework, and netcore. It changes Roslyn's remote build-host selection, not the Glider server runtime.
--msbuild-path — points Roslyn's remote build-host process at a specific MSBuild installation by setting its MSBUILD_EXE_PATH environment.
--solution — loads a .sln, .slnx, or .csproj automatically at startup, so agents don't need to call the load tool first.
load.server_status reports progress under workspaceLoading, with an ETA from this workspace's previous load time.--workspace — sets the root directory that the file watcher monitors for auto-sync.
--workspace with a narrower directory, or --no-watch, if the refreshes become too frequent.load result's fileWatcher.error.--no-watch — disables the file watcher and auto-sync for the startup load. Do not combine it with --workspace.
Why you might need --build-host and --msbuild-path:
--build-host netframework when Roslyn auto-selects the wrong host family for legacy Windows solutions. This is common for older ASP.NET, desktop, test, and non-SDK projects that evaluate better inside the .NET Framework build host than the .NET Core one.--msbuild-path when the host family is correct but Roslyn still picks the wrong toolset inside that host. This matters when multiple MSBuild installs exist on the machine and a solution only loads cleanly with one specific Visual Studio or SDK toolset.--build-host answers "which Roslyn build-host process should evaluate the project?" and --msbuild-path answers "which MSBuild install should that process use once it starts?"Use installation and host-specific setup guides on the website:
Each Glider version expires 1 month after release date.
dotnet tool update --global glider
glider is not found after install, ensure ~/.dotnet/tools is on PATH.load fails with MSBuild initialization errors, rerun with --verbose and inspect returned diagnostics.--build-host netframework when auto selects an incompatible Roslyn build host.--msbuild-path. Point it at the Visual Studio or SDK MSBuild location you want.Free for personal use, open-source work, education, and a 30-day organizational evaluation under the GliderMCP EULA. Commercial use requires a paid license once plans are on sale; until then the EULA permits it free of charge. The full terms are in the LICENSE file inside this package.
FAQs
Compiler-backed C#/.NET code intelligence for coding agents. Explore symbols and call graphs, inspect diagnostics, analyze complexity, dependencies, and impact, and safely edit and refactor solutions through MCP.
We found that glider demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.