A powerful Model Context Protocol server that creates intelligent graph representations of your codebase with comprehensive semantic analysis capabilities, supporting 11 languages and 26 MCP methods.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
er77
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Predictable results in nanoid generation when given non-integer values
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
CLOUDRU_API_KEYCLOUDRU_BASE_URLCLOUDRU_CONCURRENCYCLOUDRU_MAX_BATCH_SIZECLOUDRU_TIMEOUT_MSCONDUCTOR_COMPLEXITY_THRESHOLDCONDUCTOR_LOAD_BALANCING_STRATEGYCONDUCTOR_MANDATORY_DELEGATIONCONDUCTOR_MAX_CONCURRENCYCONDUCTOR_MAX_CONCURRENT_AGENTSCONDUCTOR_MAX_CPU_PERCENTCONDUCTOR_MAX_MEMORY_MBIncrease the coordinator/conductor limits (these gate task routing in-process): set COORDINATOR_MEMORY_LIMIT / CONDUCTOR_MEMORY_LIMIT and COORDINATOR_MAX_MEMORY_MB / , or edit config/default.yaml.CONDUCTOR_MAX_TASK_QUEUE_SIZECONDUCTOR_MEMORY_LIMITIncrease the coordinator/conductor limits (these gate task routing in-process): set COORDINATOR_MEMORY_LIMIT / and COORDINATOR_MAX_MEMORY_MB / CONDUCTOR_MAX_MEMORY_MB, or edit config/default.yaml.CONDUCTOR_PRIORITYCONDUCTOR_TASK_QUEUE_LIMITCOORDINATOR_LOAD_BALANCING_STRATEGYCOORDINATOR_MAX_CONCURRENCYCOORDINATOR_MAX_CONCURRENT_AGENTSCOORDINATOR_MAX_CPU_PERCENTCOORDINATOR_MAX_MEMORY_MBIncrease the coordinator/conductor limits (these gate task routing in-process): set COORDINATOR_MEMORY_LIMIT / CONDUCTOR_MEMORY_LIMIT and / CONDUCTOR_MAX_MEMORY_MB, or edit config/default.yaml.COORDINATOR_MAX_TASK_QUEUE_SIZECOORDINATOR_MEMORY_LIMITIncrease the coordinator/conductor limits (these gate task routing in-process): set / CONDUCTOR_MEMORY_LIMIT and COORDINATOR_MAX_MEMORY_MB / CONDUCTOR_MAX_MEMORY_MB, or edit config/default.yaml.COORDINATOR_PRIORITYCOORDINATOR_TASK_QUEUE_LIMITDATABASE_CACHE_SIZEDATABASE_MMAP_SIZEDATABASE_MODEDATABASE_PATHDATABASE_SYNCHRONOUSDATABASE_TEMP_STOREDEV_AGENT_MAX_CONCURRENCYDEV_AGENT_MEMORY_LIMITDEV_AGENT_PRIORITYDIST_JSDORA_AGENT_MAX_CONCURRENCYDORA_AGENT_MEMORY_LIMITDORA_AGENT_PRIORITYDRAIN_AFTER_ALL_MSEMBEDDING_DEBUGINDEXER_AGENT_BATCH_SIZEINDEXER_AGENT_CACHE_SIZEINDEXER_AGENT_CACHE_TTLINDEXER_AGENT_MAX_CONCURRENCYINDEXER_AGENT_MEMORY_LIMITINDEXER_AGENT_PRIORITYJEST_DETECT_OPEN_HANDLESJEST_FORCE_EXITJEST_PER_FILE_CONCURRENCYJEST_WORKER_IDKOTLIN_ANALYZER_VERBOSELOG_DIRLOG_ENABLE_CONSOLELOG_FILELOG_FORMATLOG_LEVELLOG_MAX_FILESLOG_MAX_FILE_SIZEMCP_AGENT_TIMEOUTMCP_DEBUG_DISABLE_SEMANTICThe command logs progress to logs_llm/mcp-server-YYYY-MM-DD.log. Set =0 if you want embeddings enabled during the run.MCP_DEBUG_MODEMCP_DEV_INDEX_BATCHMCP_EMBEDDING_API_KEYMCP_EMBEDDING_ENABLEDMCP_EMBEDDING_FALLBACKMCP_EMBEDDING_MODELe =gemini-embedding-001 \MCP_EMBEDDING_PROVIDERe =openai \MCP_MAX_CONCURRENT_AGENTSMCP_SEMANTIC_WARMUP_LIMITexport =25MCP_SEMANTIC_WARMUP_TOPICMCP_SERVER_HOSTMCP_SERVER_PORTMCP_SERVER_TIMEOUTMCP_STDIO_ALLOW_STDOUT_LOGSIf you must see logs on stdout for local debugging, set =1 (not recommended for strict clients).MCP_USE_PARSERMEMORY_EMBED_DIMOLLAMA_AUTO_PULLOLLAMA_BASE_URLOLLAMA_CHECK_SERVEROLLAMA_CONCURRENCYOLLAMA_PULL_TIMEOUT_MSOLLAMA_TIMEOUT_MSOLLAMA_WARMUP_TEXTOPENAI_API_KEYe =YOUR_KEY \OPENAI_BASE_URLe =https://generativelanguage.googleapis.com/v1beta/openai \OPENAI_CONCURRENCYOPENAI_MAX_BATCH_SIZEOPENAI_TIMEOUT_MSPARSER_AGENT_BATCH_SIZEPARSER_AGENT_CACHE_SIZEPARSER_AGENT_MAX_CONCURRENCYPARSER_AGENT_MEMORY_LIMITPARSER_AGENT_PRIORITYPARSER_AGENT_WORKER_POOL_SIZEPARSER_BUFFER_SIZEPARSER_CACHE_SIZEPARSER_CACHE_TTLPARSER_DISABLE_CACHEPARSER_INCREMENTAL_ENABLEDPARSER_LANGUAGESPARSER_MAX_FILE_SIZEPARSER_TIMEOUTPARSER_TREE_SITTER_ENABLEDPROJECT_DIRQUERY_AGENT_CACHE_WARMUPQUERY_AGENT_COMPLEX_TIMEOUTQUERY_AGENT_MAX_CONCURRENCYQUERY_AGENT_MEMORY_LIMITQUERY_AGENT_PRIORITYQUERY_AGENT_SIMPLE_TIMEOUTSEMANTIC_AGENT_BATCH_SIZESEMANTIC_AGENT_DEBUGSEMANTIC_AGENT_MAX_CONCURRENCYSEMANTIC_AGENT_MEMORY_LIMITSEMANTIC_AGENT_MODEL_PATHSEMANTIC_AGENT_PRIORITYSEND_AFTER_INDEX_MSTARGET_DIRTOTAL_TIMEOUTTRANSFORMERS_LOCAL_PATHTRANSFORMERS_QUANTIZEDVECTOR_STORE_DEBUGShell command execution
42 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 2 high severity in production deps — @modelcontextprotocol/sdk@1.5.0 (high), @modelcontextprotocol/sdk@1.5.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Your fixes are re-checked automatically. Claim the listing and we tell you when the grade moves, and reach you directly if we find anything urgent.
[](https://m8ven.ai/mcp/er77-code-graph-rag-mcp-1iabtu)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check