deep-code-security (backspace-shmackspace/deep-code-security) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it yet. No publisher has claimed this listing.
Multi-language SAST and AI-powered fuzzing MCP server for Claude Code integration, enabling static and dynamic security analysis of code.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
backspace-shmackspace
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
DCS_BRIDGE_MAX_TARGETSMax fuzz targets produced by SAST-to-Fuzz bridgeDCS_FUZZ_ALLOWED_PLUGINSpython,c and AI-powered harness generation withANTHROPIC_API_KEYAPI key for Claude (required for fuzzing)GOOGLE_CLOUD_PROJECTGCP project ID for Vertex AI (optional)CLOUD_ML_PROJECT_NUMBERGCP project number for Vertex AI (optional)ANTHROPIC_VERTEX_PROJECT_IDVertex AI project override (optional)DCS_SCANNER_BACKENDScanner backend: semgrep, treesitter, or auto (prefer semgrep if available)DCS_REGISTRY_PATHDCS_ALLOWED_PATHSDCS_SANDBOX_TIMEOUTPer-exploit timeout in secondsDCS_CONTAINER_RUNTIMEDCS_MAX_CONCURRENT_SANDBOXESConcurrency limit for sandbox executionDCS_MAX_FILESMax files per scanDCS_MAX_RESULTSMax findings returned per hunt operationDCS_MAX_VERIFICATIONSMax findings to verify in auditor phaseDCS_QUERY_TIMEOUTTree-sitter query timeout in secondsDCS_QUERY_MAX_RESULTSMax results per tree-sitter queryDCS_SEMGREP_TIMEOUTMaximum seconds for Semgrep subprocessDCS_SEMGREP_RULES_PATHPath to DCS Semgrep rule filesDCS_FUZZ_MODELClaude model for input generationDCS_FUZZ_MAX_ITERATIONSMax fuzzing iterationsDCS_FUZZ_INPUTS_PER_ITERInputs generated per iterationDCS_FUZZ_TIMEOUT_MSPer-input execution timeoutDCS_FUZZ_MAX_COST_USDAPI cost budgetDCS_FUZZ_OUTPUT_DIRCorpus and report output directoryDCS_FUZZ_GCP_REGIONGCP region for Vertex AIDCS_FUZZ_MCP_TIMEOUTHard wall-clock timeout for MCP fuzz invocationsDCS_FUZZ_C_COMPILE_FLAGSComma-separated gcc flags (e.g., -O2,-march=native)DCS_FUZZ_C_INCLUDE_PATHSComma-separated include paths for C harness compilationDCS_OUTPUT_DIRLicense file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/backspace-shmackspace/deep-code-security)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check