Multi-language SAST and AI-powered fuzzing MCP server for Claude Code integration, enabling static and dynamic security analysis of code.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.DCS_BRIDGE_MAX_TARGETS— 10 Max fuzz targets produced by SAST-to-Fuzz bridgeDCS_FUZZ_ALLOWED_PLUGINS— export =python,cANTHROPIC_API_KEY— "": "your-api-key-here"GOOGLE_CLOUD_PROJECT— (none) GCP project ID for Vertex AI (optional)CLOUD_ML_PROJECT_NUMBER— (none) GCP project number for Vertex AI (optional)ANTHROPIC_VERTEX_PROJECT_ID— (none) Vertex AI project override (optional)DCS_FUZZ_C_COMPILE_FLAGS— "" Comma-separated gcc flags (e.g., -O2,-march=native)DCS_FUZZ_C_INCLUDE_PATHS— "" Comma-separated include paths for C harness compilationDCS_SCANNER_BACKEND— auto Scanner backend: semgrep, treesitter, or auto (prefer semgrep if available)DCS_REGISTRY_PATH— "": "/path/to/deep-code-security/registries",DCS_ALLOWED_PATHS— "": "/path/to/projects",DCS_SANDBOX_TIMEOUT— 30 Per-exploit timeout in secondsDCS_CONTAINER_RUNTIME— "": "auto",DCS_MAX_CONCURRENT_SANDBOXES— 2 Concurrency limit for sandbox executionDCS_MAX_FILES— 10000 Max files per scanDCS_MAX_RESULTS— 100 Max findings returned per hunt operationDCS_MAX_VERIFICATIONS— 50 Max findings to verify in auditor phaseDCS_QUERY_TIMEOUT— 5.0 Tree-sitter query timeout in secondsDCS_QUERY_MAX_RESULTS— 1000 Max results per tree-sitter queryDCS_SEMGREP_TIMEOUT— 120 Maximum seconds for Semgrep subprocessDCS_SEMGREP_RULES_PATH— registry>/semgrep Path to DCS Semgrep rule filesDCS_FUZZ_MODEL— claude-sonnet-4-6 Claude model for input generationDCS_FUZZ_MAX_ITERATIONS— 10 Max fuzzing iterationsDCS_FUZZ_INPUTS_PER_ITER— 10 Inputs generated per iterationDCS_FUZZ_TIMEOUT_MS— 5000 Per-input execution timeoutDCS_FUZZ_MAX_COST_USD— 5.0 API cost budgetDCS_FUZZ_OUTPUT_DIR— ./fuzzy-output Corpus and report output directoryDCS_FUZZ_GCP_REGION— us-east5 GCP region for Vertex AIDCS_FUZZ_MCP_TIMEOUT— 120 Hard wall-clock timeout for MCP fuzz invocationsDCS_OUTPUT_DIR[](https://m8ven.ai/mcp/backspace-shmackspace-deep-code-security-14quqk)