54
/ 100
1 month ago
glama

ArchiScribe MCP Server

Retrieves architectural information from ArchiMate models, enabling AI coding assistants to access architectural context during the software development lifecycle. Supports search and retrieval of views and elements in markdown, JSON, or YAML.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical, 5 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
// known CVEs in dependencies2 critical5 high3 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalfast-xml-parser@5.2.5GHSA-m7jm-9gc2-mpf2

fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

criticalvitest@3.2.4GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highfast-xml-parser@5.2.5GHSA-37qj-frw5-hhjh

fast-xml-parser has RangeError DoS Numeric Entities Bug

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAAD_TENANT_IDEntra tenant ID 24e3b176-9cdb-...
configAUTHORIZATION_SERVER_URLEntra v2 issuer (optional) https://login.microsoftonline.com/{tenantId}/v2.0
configDISCLAIMER_PREFIX
configENABLE_HTTP_ENDPOINTS
configLOG_LEVEL$env:LOG_TARGET='console'; $env:='info'; npm start
configLOG_PATH$env:='C:\\temp\\archiscribe-logs'
configLOG_TARGET$env:='console'; $env:LOG_LEVEL='info'; npm start
configMCP_AUTH_MODEThe environment variable controls enforcement:
configMODEL_PATH$env:='C:\path\to\your\model.xml'; npm start
configOAUTH_AUDIENCEAPI app registration URI api://4c6d54f3-...
configOAUTH_JWKS_URI
configOAUTH_RESOURCE_URI
configOAUTH_SCOPERequired scope api://4c6d54f3-.../user_impersonation
configPORT
configRESPONSE_FORMAT$env:='json'; npm start
configSERVER_PORT$env:=8080; npm start
configVIEWS_FILTER_BY_PROPERTY
configVIEWS_FILTER_PROPERTY_NAME
configWEBSITE_AUTH_AAD_ALLOWED_TENANTS
configWEBSITE_HOSTNAMECloud detection for auto uses App Service environment variables (WEBSITE_INSTANCE_ID, WEBSITE_SITE_NAME, , WEBSITE_RESOURCE_GROUP).
configWEBSITE_INSTANCE_IDCloud detection for auto uses App Service environment variables (, WEBSITE_SITE_NAME, WEBSITE_HOSTNAME, WEBSITE_RESOURCE_GROUP).
configWEBSITE_RESOURCE_GROUPCloud detection for auto uses App Service environment variables (WEBSITE_INSTANCE_ID, WEBSITE_SITE_NAME, WEBSITE_HOSTNAME, ).
configWEBSITE_SITE_NAMECloud detection for auto uses App Service environment variables (WEBSITE_INSTANCE_ID, , WEBSITE_HOSTNAME, WEBSITE_RESOURCE_GROUP).
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/dclnbrght-archiscribe-mcp-14buvv)](https://m8ven.ai/mcp/dclnbrght-archiscribe-mcp-14buvv)
commit: e1249d8f2e2673f0be21f57805367ca4e5da2496
code hash: 653ca92874706384fca1cec1878790116a5399491c2cc80ebae4990310235265
verified: 6/15/2026, 2:12:59 PM
view raw JSON →