Multi-language SAST and AI-powered fuzzing MCP server for Claude Code integration, enabling static and dynamic security analysis of code.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
backspace-shmackspace
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
DCS_BRIDGE_MAX_TARGETS10 Max fuzz targets produced by SAST-to-Fuzz bridgeDCS_FUZZ_ALLOWED_PLUGINSexport =python,cANTHROPIC_API_KEY"": "your-api-key-here"GOOGLE_CLOUD_PROJECT(none) GCP project ID for Vertex AI (optional)CLOUD_ML_PROJECT_NUMBER(none) GCP project number for Vertex AI (optional)ANTHROPIC_VERTEX_PROJECT_ID(none) Vertex AI project override (optional)DCS_SCANNER_BACKENDauto Scanner backend: semgrep, treesitter, or auto (prefer semgrep if available)DCS_REGISTRY_PATH"": "/path/to/deep-code-security/registries",DCS_ALLOWED_PATHS"": "/path/to/projects",DCS_SANDBOX_TIMEOUT30 Per-exploit timeout in secondsDCS_CONTAINER_RUNTIME"": "auto",DCS_MAX_CONCURRENT_SANDBOXES2 Concurrency limit for sandbox executionDCS_MAX_FILES10000 Max files per scanDCS_MAX_RESULTS100 Max findings returned per hunt operationDCS_MAX_VERIFICATIONS50 Max findings to verify in auditor phaseDCS_QUERY_TIMEOUT5.0 Tree-sitter query timeout in secondsDCS_QUERY_MAX_RESULTS1000 Max results per tree-sitter queryDCS_SEMGREP_TIMEOUT120 Maximum seconds for Semgrep subprocessDCS_SEMGREP_RULES_PATHregistry>/semgrep Path to DCS Semgrep rule filesDCS_FUZZ_MODELclaude-sonnet-4-6 Claude model for input generationDCS_FUZZ_MAX_ITERATIONS10 Max fuzzing iterationsDCS_FUZZ_INPUTS_PER_ITER10 Inputs generated per iterationDCS_FUZZ_TIMEOUT_MS5000 Per-input execution timeoutDCS_FUZZ_MAX_COST_USD5.0 API cost budgetDCS_FUZZ_OUTPUT_DIR./fuzzy-output Corpus and report output directoryDCS_FUZZ_GCP_REGIONus-east5 GCP region for Vertex AIDCS_FUZZ_MCP_TIMEOUT120 Hard wall-clock timeout for MCP fuzz invocationsDCS_FUZZ_C_COMPILE_FLAGS"" Comma-separated gcc flags (e.g., -O2,-march=native)DCS_FUZZ_C_INCLUDE_PATHS"" Comma-separated include paths for C harness compilationDCS_OUTPUT_DIRLicense file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Shell command execution
13 child_process/subprocess calls in production code — runs shell commands (src/deep_code_security/architect/guidance_generator.py:200, src/deep_code_security/architect/guidance_generator.py:201, src/deep_code_security/architect/guidance_generator.py:206)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/backspace-shmackspace-deep-code-security-14quqk)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check