dotnet-sherlock-mcp
ILSpy, LLM kodlama ajanları için. .NET derlemelerini, NuGet paketlerini, türleri, üyeleri, nitelikleri ve XML dokümanlarını keşfetmek için 31'den fazla araç içeren yansıma tabanlı MCP sunucusu.
Dokümantasyon
Sherlock MCP for .NET
Sherlock MCP for .NET is a comprehensive Model Context Protocol (MCP) server that provides deep introspection capabilities for .NET assemblies. It enables Language Learning Models (LLMs) to analyze and understand your .NET code with precision, delivering accurate and context-aware responses for complex development scenarios.
This tool is essential for developers who want to harness LLM capabilities for:
- Deep codebase analysis - Understanding complex .NET architectures and dependencies
- Precise type information - Getting detailed metadata about types, members, and their signatures
- Automated documentation - Extracting and utilizing XML documentation and attributes
- Custom tooling - Building sophisticated tools that interact with .NET assemblies
- Code generation - Creating accurate code based on existing type structures
Key Features
- Comprehensive MCP Server: Provides 40 specialized tools for .NET assembly analysis, with an optional 20-tool
coreprofile - Advanced Assembly Introspection: Deep reflection-based analysis of types, members, and metadata
- Rich Member Analysis: Detailed inspection of methods, properties, fields, events, and constructors
- Smart Filtering & Pagination: Advanced filtering by name/attributes with efficient pagination for large datasets
- XML Documentation Integration: Automatic extraction of summary, parameters, returns, and remarks
- Performance Optimized: Caching, pagination, and memory-efficient processing
- Stable JSON API: Consistent envelopes with versioning and structured error codes
- .NET 9.0 Native: Built on the latest .NET platform with modern C# features
- Project Integration: Solution and project file analysis with dependency resolution
- Workflow Prompts:
explore_package,explain_typeandwho_callsprompts give one-click entry points into common analysis workflows - Current MCP SDK: Built on
ModelContextProtocol2.1.0 (GA) - Current MCP Specification: Speaks protocol revision
2026-07-28, and negotiates down automatically for clients on earlier revisions
What's New in 2.14.0
- Claude Code plugin:
/plugin marketplace add jcucci/dotnet-sherlock-mcpand/plugin install sherlock@dotnet-sherlock-mcpinstall the server plus a skill that teaches agents the Sherlock workflow. See Claude Code plugin. get_type_membersand tool profiles: one paginated, filterable tool lists every member kind, and--profile core/SHERLOCK_TOOL_PROFILE=coretrims the surface to the essential tools. The per-kind member tools are deprecated.- Structured output and error guidance: the core browsing tools publish an
outputSchemaand returnstructuredContent, and failed calls carryisError: truewith did-you-mean candidates and fix-it suggestions. - Cancellation, progress and elicitation: long scans can be cancelled and report progress, and an ambiguous simple type name prompts the client to choose. See
CHANGELOG.mdfor full details.
Installation
Run with dnx (.NET 10 SDK)
With the .NET 10 SDK, dnx downloads the package from NuGet and runs it directly — no install step:
dnx -v q --yes Sherlock.MCP.Server@2.14.0
--yes skips the interactive confirmation prompt, which an MCP client launching the server over stdio can't answer. -v q stops dnx from printing a "Skipping NuGet package signature verification." notice to stdout the first time it downloads a version, which would otherwise corrupt the MCP stream and fail that first connection. Both are dnx options, so they must come before the package id; anything after it is passed to the server. Pinning the version keeps launches reproducible; bump it when you want to upgrade. The package is published with the McpServer package type, so it is also listed as an MCP server on NuGet.org.
Install as a global tool
On any supported SDK (.NET 8 or later), install the global tool from NuGet (adds sherlock-mcp to your PATH):
dotnet tool install -g Sherlock.MCP.Server
Alternatively, during development you can run the server locally:
dotnet run --project src/server/Sherlock.MCP.Server.csproj
Configure Your MCP Client
Sherlock runs as a standard MCP server that communicates over stdio.
Claude Code plugin
This repository is also a Claude Code plugin marketplace. The sherlock plugin bundles the server (launched with dnx, so it needs the .NET 10 SDK) and a skill that teaches the agent the locate → orient → drill-in → relationships workflow:
/plugin marketplace add jcucci/dotnet-sherlock-mcp
/plugin install sherlock@dotnet-sherlock-mcp
The plugin starts the server with the core tool profile, which matches the tools the skill covers. To expose every tool, set SHERLOCK_TOOL_PROFILE=full in the environment Claude Code is launched from.
Each user runs these commands once; restart Claude Code (or run /reload-plugins) afterwards. To pick up a new release, run /plugin marketplace update dotnet-sherlock-mcp. If you previously registered Sherlock with claude mcp add, remove that entry (claude mcp remove sherlock) so the tools aren't loaded twice.
Team setup
To offer the plugin to everyone working in a repository, commit the following to that repository's .claude/settings.json. Claude Code prompts each teammate to install it when they trust the folder, so nobody has to type the commands above:
{
"extraKnownMarketplaces": {
"dotnet-sherlock-mcp": {
"source": {
"source": "github",
"repo": "jcucci/dotnet-sherlock-mcp"
}
}
},
"enabledPlugins": {
"sherlock@dotnet-sherlock-mcp": true
}
}
Teammates still need the .NET 10 SDK on their PATH for dnx.
Using dnx
- Claude Code:
claude mcp add sherlock -- dnx -v q --yes Sherlock.MCP.Server@2.14.0
- VS Code (
.vscode/mcp.json):
{
"servers": {
"sherlock": {
"type": "stdio",
"command": "dnx",
"args": ["-v", "q", "--yes", "Sherlock.MCP.Server@2.14.0"]
}
}
}
Using the global tool
- Cursor: Settings → MCP / Custom tools → Add tool → Command:
sherlock-mcp - Claude Desktop / other MCP clients: Add a server entry pointing to the
sherlock-mcpcommand. Example JSON entry (refer to your client’s docs for exact file location/format):
{
"servers": {
"sherlock": {
"command": "sherlock-mcp"
}
}
}
No arguments are required. The server self-registers all tools when launched.
Tool profiles
Large tool lists cost agents context and discoverability (Claude Code switches to deferred Tool Search once tool descriptions grow past roughly 10% of the context window). Sherlock can start with a smaller surface:
| Profile | Tools | Contents |
|---|---|---|
full (default) | 40 | Every tool, including the deprecated per-kind member tools |
core | 20 | Discovery (find_assembly_by_class_name, find_assembly_by_file_name, find_assembly_by_nuget_package, get_project_output_paths, open_assembly), orientation (get_assembly_info, get_types_from_assembly, get_type_info, get_type_hierarchy), members and docs (get_type_members, search_members, analyze_method, get_xml_docs_for_type, get_xml_docs_for_member) and relationships (find_implementations_of, find_methods_returning, find_extension_methods_for, find_references_to, get_method_calls) and decompilation (decompile_member) |
Select a profile with the --profile argument or the SHERLOCK_TOOL_PROFILE environment variable (the argument wins). An unknown profile name stops the server with an error.
{
"servers": {
"sherlock": {
"command": "sherlock-mcp",
"args": ["--profile", "core"]
// or: "env": { "SHERLOCK_TOOL_PROFILE": "core" }
}
}
}
Auto-Configure for .NET Projects
You usually don't need to paste anything. Sherlock ships its usage guidance in the MCP instructions field returned at initialize, and most MCP clients (including Claude Code) surface that to the agent automatically — so the guidance stays correct and versioned with the package, with no copy-paste to maintain.
The snippets below are optional reinforcement. Keep them short and principle-based rather than enumerating tool names and workflows: a static list pasted into your repo will drift as Sherlock's tools evolve, whereas the tools' own descriptions (and the server instructions) always match the version you're running.
Tool names are exposed in
snake_case(get_type_members,search_members, …); argument names stay camelCase (projection,nameContains).
Claude Code (CLAUDE.md)
If you installed the Claude Code plugin, its skill already covers this. Otherwise, you can add a short, optional pointer to your project's CLAUDE.md:
## .NET Assembly Analysis
Use the Sherlock MCP tools (`get_type_members`, `search_members`, …) for .NET type/assembly
questions instead of guessing. Locate DLLs with the `find_assembly_by_*` / `get_project_output_paths`
tools rather than hardcoding bin paths. Start lean — `search_members` or `get_types_from_assembly`,
then drill in — and pass `projection='full'` only when you need parameters/attributes/modifiers.
The tools' own descriptions cover the specifics.
Cursor (.cursor/rules)
The single-file .cursorrules format is deprecated (and silently ignored in Cursor's Agent mode).
Add a Project Rule at .cursor/rules/sherlock.mdc instead:
---
description: Use Sherlock MCP for .NET assembly/type analysis
alwaysApply: true
---
- Prefer the Sherlock MCP tools (snake_case, e.g. `get_type_members`, `search_members`) over guessing about .NET APIs.
- Find DLLs with `find_assembly_by_*` / `get_project_output_paths`; don't hardcode `bin/Debug/<tfm>/*.dll`.
- Start lean (`search_members` / `get_types_from_assembly`); request `projection='full'` only when you need parameters/attributes/modifiers.
Other agents (AGENTS.md)
For tools that follow the cross-editor AGENTS.md convention, the same short pointer works — drop the Claude Code snippet above into your AGENTS.md.
Global configuration
For system-wide usage, add to your global agent settings:
For .NET work, use the Sherlock MCP tools (snake_case) to analyze assemblies, types, and members instead of guessing. Start lean and opt into projection='full' only when you need detail.
How To Prompt It
Below are compact prompt snippets you can paste into your chat to get productive fast. Adjust paths to your local DLLs.
General setup
You have access to an MCP server named "sherlock" that can analyze .NET assemblies. Prefer these tools for .NET questions and include short reasoning for which tool you chose. Ask me for the assembly path if missing.
Enumerate members for a type
Analyze: /absolute/path/to/MyLib/bin/Debug/net9.0/MyLib.dll
Type: MyNamespace.MyType
List methods, including non-public, filter name contains "Async", include attributes, return JSON.
Get XML docs for a member
Use GetXmlDocsForMember on /abs/path/MyLib.dll, type MyNamespace.MyType, member TryParse. Summarize the summary + params.
Find types and drill in
List types from /abs/path/MyLib.dll; then get type info for the first result and list its nested types.
Tune paging and filters
Use GetTypeMembers on /abs/path/MyLib.dll, type MyNamespace.MyType, kinds method, sortBy name, sortOrder asc, skip 0, take 25, hasAttributeContains Obsolete.
Browse lean, then get detail (projection)
On /abs/path/MyLib.dll, run GetTypeMembers for MyNamespace.MyType with the default summary projection to see signatures. Then re-call GetTypeMembers with kinds method, nameContains and projection='full' only for the methods I name to get their parameters and attributes.
Trace relationships and call sites
On /abs/path/MyLib.dll: FindImplementationsOf MyNamespace.IMyService. Then FindReferencesTo that interface with analysisDepth='il' to find callers, and GetMethodCalls on the most relevant method to see what it invokes.
Tools Overview
Tool names: MCP clients call these tools in
snake_case—GetTypeMembers→get_type_members,SearchMembers→search_members, and so on. The PascalCase names used throughout this README match the underlying C# methods and the tool descriptions your client displays.
Assembly Discovery & Analysis
OpenAssembly: Returns a shortasm_…handle to pass asassemblyHandleinstead ofassemblyPathon any tool that takes an assembly. The handle carriesadditionalAssembliestoo, persists across server restarts (inhandles.jsonunderSHERLOCK_STATE_DIR, default the user's local app-datasherlockfolder) and is pinned to the current build: after a rebuild, calls fail withStaleAssemblyHandleuntil it is reopenedAnalyzeAssembly: Complete assembly overview with public types and metadataGetAssemblyInfo: Assembly-level metadata — identity/version, target framework, and referenced assemblies (projection=fulladds all assembly attributes)FindAssemblyByClassName: Locate assemblies declaring a public type by simple, full or nested name; skipsobj/,ref/,refint/,node_modules/,packages/,TestResults/and dot-directories, and ranksbin/matches firstFindAssemblyByFileName: Find assemblies by file name under a root directory, with the same exclusions and rankingFindAssemblyByNugetPackage: Resolve a DLL from the local NuGet cache by package id (optionalversion/tfm)
Type Introspection
GetTypesFromAssembly: List all public types with metadata (paginated)AnalyzeType(deprecated): Type metadata plus all members; useGetTypeInfo+GetTypeMembers projection=fullGetTypeInfo: Detailed type metadata (accessibility, generics, nested types)GetTypeHierarchy: Inheritance chain and interface implementationsGetGenericTypeInfo: Generic parameters, arguments, and variance informationGetTypeAttributes: Custom attributes declared on typesGetNestedTypes: Nested type declarations
Member Analysis (Filterable & Paginated)
GetTypeMembers: Methods, properties, fields, events and constructors of a type in one paginated list. Narrow withkinds(method|property|field|event|constructor),nameContainsandhasAttributeContains;summaryitems are{ kind, name, signature },projection=fulladds each kind's structured fieldsAnalyzeMethod: Deep method analysis with overloads and attributes- Deprecated, kept for a release or two:
GetTypeMethods,GetTypeProperties,GetTypeFields,GetTypeEvents,GetTypeConstructors(useGetTypeMemberswithkinds) andGetAllTypeMembers(useGetTypeMembers projection=full)
Member Search
SearchMembers: Search a whole assembly for members whose name contains a fragment — the entry point when you know a member name but not its declaring type. Filter bymemberKinds(method|property|field|event|type).
Reverse Lookup
FindImplementationsOf: Types implementing an interface or deriving from a base class (open-generic match supported)FindMethodsReturning: Methods whose return type matches a given type (open-generic match supported)FindExtensionMethodsFor: Extension methods that extend a given type (scans static classes bythis-parameter)FindReferencesTo: Broader sweep across parameters, fields, properties, events, and generic arguments; passanalysisDepth='il'to also resolve inbound callers from method bodies
IL Analysis
GetMethodCalls: Read a method's IL body to list what it calls and which fields it touches — the "what does this method do?" question signature-level tools can't answer (aggregates across overloads; use.ctor/.cctorfor constructors)
Decompilation
DecompileMember: Decompile one member (method, property, field, event or constructor) to C# with ICSharpCode.Decompiler. Returns every overload of the name, or one overload whenparameterTypesis given (e.g.string,int; an empty string selects the parameterless overload). Use.ctor/.cctorfor constructorsDecompileType: Decompile a whole type to C#. Not in thecoreprofile; preferDecompileMember
Both tools page their source by line: maxLines (default 400, max 5000) caps the page size, a page also stops early once it reaches about 90,000 characters so it always fits the response limit, and each page reports startLine, lineCount, totalLines, truncated and a continuationToken for the next page. Lines over 2,000 characters are clipped with a /* … more characters clipped */ marker and counted in clippedLines. Pass additionalAssemblies (or use an assemblyHandle opened with them) when dependencies live outside the assembly's folder; their folders are searched when resolving referenced types and their file stamps are part of the cache key. The full decompilation is cached by file stamp, so later pages are cheap. A type the assembly only forwards (e.g. System.String in a System.Runtime.dll facade) returns TypeForwarded with the defining assembly in recommendedParams.
Attributes & Metadata
GetMemberAttributes: Attributes for specific membersGetParameterAttributes: Parameter-level attribute information
XML Documentation
GetXmlDocsForType: Extract type-level XML documentationGetXmlDocsForMember: Member-specific documentation (summary/params/returns/remarks)
Project & Solution Analysis
AnalyzeSolution: Parse .sln files and enumerate projectsAnalyzeProject: Project metadata, references, and build configurationGetProjectOutputPaths: Resolve output directories for different configurationsResolvePackageReferences: Map NuGet packages to cached assembliesFindDepsJsonDependencies: Parse deps.json for runtime dependencies
Configuration & Runtime
GetRuntimeOptions: Current server configuration and defaultsUpdateRuntimeOptions: Modify pagination, caching, and search behavior
Resources
Three resource templates let clients fetch a single type, doc entry or cached package without another tool call. Every variable is percent-encoded.
sherlock://assembly/{path}/type/{fullName}: Type metadata, the same payload asget_type_infosherlock://assembly/{path}/docs/{memberId}: XML documentation for a documentation id such asT:Ns.TypeorM:Ns.Type.Method(System.String)sherlock://nuget/{packageId}/{version}: The assembly a cached NuGet package version resolves to, the same payload asfind_assembly_by_nuget_package
search_members, get_types_from_assembly and the find_* reverse-lookup tools return a resource_link to the type resource for each distinct type on the page, after the JSON text block. resources/read carries private caching hints; a URI whose assembly, type, doc id or package doesn't exist fails with -32602.
Template variables support completion/complete, returning at most 100 values:
path: recently loaded assemblies, then.dll/.exefiles and subfolders of the folder being typedfullName: type names (metadata form, e.g.List`1) from the assembly in thepathcontext argumentmemberId: documentation ids from the XML file next to thepathassemblypackageId/version: package folders and their versions (newest first) in the local NuGet cache
Prompts
Three prompts encode common tool sequences as one-click entry points (Claude Code lists them as /mcp__sherlock__<name> slash commands). Each returns a single user message that walks the agent through the tools; they only call tools in the core profile, so they work under either profile.
explore_package(packageId,version?): Resolves the package from the local NuGet cache (highest cached version whenversionis omitted), orients on the assembly, and summarizes its main types and entry pointsexplain_type(assemblyPath,typeName): Hierarchy, members, XML docs and usages of one typewho_calls(assemblyPath,typeName,memberName,additionalAssemblies?): Inbound callers of a member from IL, optionally across a comma-separated list of other assemblies
assemblyPath, typeName (with assemblyPath in the completion context), packageId and version (with packageId in the context) support completion/complete the same way as the resource template variables. prompts/list carries the same public caching hints as tools/list.
Advanced Filtering & Pagination
All member analysis tools support comprehensive filtering and pagination:
Filtering Options:
caseSensitive(bool): Case-sensitive type/member matchingnameContains(string): Filter by member name substringhasAttributeContains(string): Filter by attribute type substringincludePublic/includeNonPublic(bool): Visibility filteringincludeStatic/includeInstance(bool): Member type filtering
Pagination:
skip/take(int): Standard offset paginationmaxItems(int): Maximum results per request (default 50;FindReferencesTodefaults to 25)continuationToken(string): Token-based pagination for large datasetssortBy/sortOrder(string): Sort by name/access in asc/desc order
Response Shape (token efficiency)
Most enumerating tools default to a lean summary projection and let you opt into the heavier full payload only when you need it. Reach for full deliberately — summary is usually enough to decide your next call.
projection(summary|full): supported byGetTypesFromAssembly,GetTypeMembers,GetTypeMethods,GetAssemblyInfo,GetMethodCalls,FindImplementationsOf,FindMethodsReturning,FindExtensionMethodsFor, andFindReferencesTo.summaryreturns just enough to browse (e.g.{ kind, name, signature }for members);fulladds structured fields (parameters, attributes, return type, modifiers, etc.). Note: the deprecatedGetTypeProperties/Fields/Events/Constructorshave a single fixed shape and take noprojection.analysisDepth(signatures|il):FindReferencesToonly.signatures(default) scans member declarations;iladditionally scans method bodies for inbound callers (slower).additionalAssemblies(string[]): widen the search scope forGetTypeHierarchyand the reverse-lookup tools.GetTypeHierarchy.derivedTypesstaysnulluntil you pass this.noCache(bool): bypass the response cache for a single call when you suspect stale results. Every tool that reads an assembly or project caches its response, keyed by the file stamps of its inputs (the assembly and anyadditionalAssemblies, the XML doc file beside it, or the project file andobj/project.assets.json), so a rebuild or restore invalidates it automatically. Thefind_assembly_by_*lookups andresolve_package_references(which read the shared NuGet package cache), configuration and handle tools are not cached. Two cases the stamps don't catch, wherenoCache=trueis the fix: a dependency DLL dropped in beside an assembly that previously resolved only partially (keys stamp the assembly, not its siblings), and a restore for a project whoseproject.assets.jsonlives outsideobj/(e.g.UseArtifactsOutputor a customBaseIntermediateOutputPath).assemblyHandle(string): accepted by every tool that takesassemblyPath, as an alternative to it (pass one, not both). Get one fromopen_assembly; it also supplies theadditionalAssembliesit was opened with, and any you pass explicitly are added to them.
Type Resolution:
- Supports full names (
Namespace.Type), simple names (Type), and nested types (Outer+Inner) - Case sensitivity controlled by
caseSensitiveparameter - Automatic fallback resolution for ambiguous type names
Response Schema
All tools return a stable JSON envelope:
{ "kind": "type.list|member.methods|...", "version": "1.0.0", "data": { /* result */ } }
The envelope is serialized as compact (unindented) JSON in the tool's text content block. The core browsing tools also advertise an MCP outputSchema and return the same envelope as structuredContent, so clients can validate and consume results without parsing text: search_members, get_types_from_assembly, get_type_info, get_type_members, get_type_methods, get_assembly_info, get_method_calls, decompile_member, find_implementations_of, find_methods_returning, find_extension_methods_for and find_references_to. Their schemas describe the default summary projection; projection='full' items add fields on top of it. Error results never carry structuredContent.
Error results are flagged with MCP's isError: true, so clients can tell a failure from a result without parsing the text. Errors use a consistent shape. Every error carries kind, version, code, and message; some add details, and guided errors add a suggestion, alternativeTools, or recommendedParams to point the agent at a next step:
{
"kind": "error",
"version": "1.0.0",
"code": "MethodNotFound",
"message": "No method named 'Parse' was found on type 'MyApp.Config' in MyApp.dll.",
"suggestion": "Verify the type and method names. Use get_type_members with kinds=method to list available methods, or set includeNonPublic=true for private methods.",
"alternativeTools": ["get_type_members", "analyze_method"]
}
Error codes:
- Not found:
AssemblyNotFound(recommendedParams.similarFileslists near-miss assemblies in the same folder),TypeNotFound/MemberNotFound(recommendedParams.candidateslists the closest names),MethodNotFound,PackageNotFound,VersionNotFound,XmlNotFound,ProjectNotFound,FileNotFound - Bad input:
AmbiguousTypeName(only for clients that can't elicit;recommendedParams.candidateslists the matching full names),InvalidArgument,InvalidProjection,InvalidAnalysisDepth,InvalidContinuationToken - Loading:
InvalidAssembly(not a managed assembly),DependencyNotFound(a referenced assembly couldn't be loaded),DependencyResolutionFailed,AccessDenied - Limits & internal:
ResponseTooLarge,InternalError
Roadmap
Shipped features and planned work are summarized in src/docs/roadmap.md; the live checklist is tracked in #87.
Contributing
Contributions are welcome. This repo includes an .editorconfig with modern C# preferences (file-scoped namespaces, expression-bodied members, 4-space indentation).
Commit Message Format
This project uses Conventional Commits for automated changelog generation. All commits must follow this format:
type(scope): description
Valid types:
feat- A new featurefix- A bug fixdocs- Documentation only changesstyle- Code style changes (formatting, semicolons, etc)refactor- Code change that neither fixes a bug nor adds a featureperf- Performance improvementtest- Adding or correcting testsbuild- Changes to build system or dependenciesci- Changes to CI configurationchore- Other changes that don't modify src or test filesrevert- Reverts a previous commit
Examples:
git commit -m "feat(tools): add new assembly analysis tool"
git commit -m "fix: resolve null reference in type loader"
git commit -m "docs(readme): update installation instructions"
Development Setup
# Restore .NET tools (versionize, husky)
dotnet tool restore
# Install git hooks for commit validation
dotnet husky install
Guidelines
- Keep changes small and focused; add unit tests for new behavior.
- Follow the response envelope and error code conventions when adding tools.
- Run
dotnet buildanddotnet testlocally before opening a PR.
Creating a Release
Maintainers can create releases using:
# Restore tools if not already done
dotnet tool restore
# Preview what will change
dotnet versionize --dry-run
# Create release (bumps version, updates changelog, creates git tag)
dotnet versionize
# Push changes and tag to trigger release workflow
git push --follow-tags
versionize only bumps the project version. Before pushing, bump both version fields in server.json, the Claude Code plugin's version in plugins/sherlock/.claude-plugin/plugin.json and .claude-plugin/marketplace.json, and the pinned dnx version in plugins/sherlock/.mcp.json (and in this README) in the same release commit, then re-point the tag at it. server.json is packed into the NuGet package as .mcp/server.json.
The release workflow will automatically:
- Verify that the tag,
server.json, the project version and the Claude Code plugin versions all match - Build and test the project
- Create a GitHub Release with changelog notes
- Publish the NuGet package and the MCP Registry entry
MCP Registry
mcp-name: io.github.jcucci/dotnet-sherlock-mcp
License
Sherlock MCP for .NET is licensed under the MIT License.