48-tool MCP server for codebase analysis — dependency graphs, architecture layers, security scanning, refactor plans, git history, and more. Works with GitHub and GitLab repos (cloud + self-hosted) and local directories.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.AZURE_DEVOPS_PATBITBUCKET_PASSWORDBITBUCKET_USERNAMEGHE_TOKENGH_TOKENGITEA_TOKENGITHUB_APP_TOKENGITHUB_CLIENT_IDGITHUB_CLIENT_SECRETGITHUB_TOKEN— github-token: ${{ secrets. }}GITHUB_WEBHOOK_SECRETGITLAB_HOSTGITLAB_OAUTH_CLIENT_IDGITLAB_OAUTH_CLIENT_SECRETGITLAB_OAUTH_REDIRECT_URIGITLAB_TOKENGRASP_DBGRASP_DB_DIRGRASP_DISABLE_EMBEDDINGS— grasp_semantic_search slow on first call Embedding model is downloading (~30 MB) First call takes 30-60s; subsequent calls instant. Or set =1 for fallbackGRASP_EMBED_INIT_TIMEOUT_MSGRASP_HOSTGRASP_HTTP_API_KEYGRASP_HTTP_MCP— Optional MCP-over-HTTP bridge — set =1 to expose the MCP server over Streamable HTTP (bearer-token auth) so a whole team can share one Grasp instance instead of each running their own stdio server.GRASP_HTTP_MCP_PORTGRASP_NVD_API_KEYGRASP_PORTGRASP_SEMANTIC_MAX_SIGSJIRA_BASE_URLJIRA_EMAILJIRA_TOKENLINEAR_API_KEYMCP_DIST_PATHPORTSTRIPE_PRO_PRICE_IDWEBHOOK_SECRET[](https://m8ven.ai/mcp/grasp-mcp-server-eq1d9a)