7
/ 100
1 month ago
github_topic

delimit-mcp-server

The merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 5 credentials: ANTHROPIC_API_KEY, DELIMIT_AUTH_TOKEN, OPENAI_API_KEY, RAPIDAPI_KEY, XAI_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies3 high3 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highminimatch@5.1.0GHSA-23c5-xmqv-rm74

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

highminimatch@5.1.0GHSA-3ppc-4f35-3m26

minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

highminimatch@5.1.0GHSA-7r86-cg39-jmmj

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

lowexpress@4.18.0GHSA-qw6h-vgh9-j6wx

express vulnerable to XSS via response.redirect()

lowexpress@4.18.0GHSA-rv95-896h-c2vc

Express.js Open Redirect in malformed URLs

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretANTHROPIC_API_KEY
configCLAUDE_TOOL_EXIT_CODE
configCLAUDE_TOOL_NAME
configCLAUDE_TOOL_PARAMS
configCLAUDE_TOOL_RESULT
configDELIMIT_AGENT_PORT
configDELIMIT_API_FALLBACK
🔐 secretDELIMIT_AUTH_TOKEN
configDELIMIT_CONTINUITY_ROOT
configDELIMIT_DEBUG
configDELIMIT_DEBUG_CONTINUITY
configDELIMIT_GATEWAY_ROOT
configDELIMIT_HANDOFF_ID
configDELIMIT_HOME
configDELIMIT_MODEL
configDELIMIT_NAMESPACE_ROOT
configDELIMIT_NO_TELEMETRY
configDELIMIT_ORG_POLICY_URL
configDELIMIT_REPO_BASE
configDELIMIT_REPO_GOVERNANCE_ROOT
configDELIMIT_RESOLVED_ACTOR
configDELIMIT_RESOLVED_VENTURE
configDELIMIT_SCOPE
configDELIMIT_SESSION_TYPE
configDELIMIT_SETUP_UPDATED
configDELIMIT_VENTURE
configDELIMIT_WORKER_RUN_ID
configDELIMIT_WORKER_STARTED_AT
configDELIMIT_WRAPPED
configGCLOUD_PROJECT
configGITHUB_ACTIONS
configGITHUB_ACTOR
configGITHUB_USER
configGITLAB_CI
configGOOGLE_APPLICATION_CREDENTIALS
configGOOGLE_CLOUD_PROJECT
configJENKINS_URL
configNO_COLOR
🔐 secretOPENAI_API_KEY
🔐 secretRAPIDAPI_KEY
configTRAVIS
🔐 secretXAI_API_KEY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/delimit-ai-delimit-mcp-server-1e2xmp)](https://m8ven.ai/mcp/delimit-ai-delimit-mcp-server-1e2xmp)
commit: ba7637c85021cd9057944cea92526ce86cd8f994
code hash: a70e3287940344df0f3694c2715b67838d255be4f34426a891fc16c7ae54382b
verified: 6/10/2026, 11:08:16 AM
view raw JSON →