74
/ 100
23 hours ago
npm

grasp-mcp-server

48-tool MCP server for codebase analysis — dependency graphs, architecture layers, security scanning, refactor plans, git history, and more. Works with GitHub and GitLab repos (cloud + self-hosted) and local directories.

ashfordeOU/grasp· npm: grasp-mcp-server· listed on npm
Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Tool annotations don’t match behaviour
4 read-only tools perform write/delete/exec — grasp_req_trace (line 3787: tagRe.exec(line)); grasp_mro (line 6948: pyClass.exec(content)); grasp_kg_export (line 8436: fs.writeFileSync(args.out_path, text))
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 15 credentials: BITBUCKET_PASSWORD, GHE_TOKEN, GH_TOKEN, GITEA_TOKEN, GITHUB_APP_TOKEN, GITHUB_CLIENT_SECRET, GITHUB_TOKEN, GITHUB_WEBHOOK_SECRET, GITLAB_OAUTH_CLIENT_SECRET, GITLAB_TOKEN, GRASP_HTTP_API_KEY, GRASP_NVD_API_KEY, JIRA_TOKEN, LINEAR_API_KEY, WEBHOOK_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAZURE_DEVOPS_PAT
🔐 secretBITBUCKET_PASSWORD
configBITBUCKET_USERNAME
🔐 secretGHE_TOKEN
🔐 secretGH_TOKEN
🔐 secretGITEA_TOKEN
🔐 secretGITHUB_APP_TOKEN
configGITHUB_CLIENT_ID
🔐 secretGITHUB_CLIENT_SECRET
🔐 secretGITHUB_TOKENgithub-token: ${{ secrets. }}
🔐 secretGITHUB_WEBHOOK_SECRET
configGITLAB_HOST
configGITLAB_OAUTH_CLIENT_ID
🔐 secretGITLAB_OAUTH_CLIENT_SECRET
configGITLAB_OAUTH_REDIRECT_URI
🔐 secretGITLAB_TOKEN
configGRASP_DB
configGRASP_DB_DIR
configGRASP_DISABLE_EMBEDDINGSgrasp_semantic_search slow on first call Embedding model is downloading (~30 MB) First call takes 30-60s; subsequent calls instant. Or set =1 for fallback
configGRASP_EMBED_INIT_TIMEOUT_MS
configGRASP_HOST
🔐 secretGRASP_HTTP_API_KEY
configGRASP_HTTP_MCPOptional MCP-over-HTTP bridge — set =1 to expose the MCP server over Streamable HTTP (bearer-token auth) so a whole team can share one Grasp instance instead of each running their own stdio server.
configGRASP_HTTP_MCP_PORT
🔐 secretGRASP_NVD_API_KEY
configGRASP_PORT
configGRASP_SEMANTIC_MAX_SIGS
configJIRA_BASE_URL
configJIRA_EMAIL
🔐 secretJIRA_TOKEN
🔐 secretLINEAR_API_KEY
configMCP_DIST_PATH
configPORT
configSTRIPE_PRO_PRICE_ID
🔐 secretWEBHOOK_SECRET
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/grasp-mcp-server-eq1d9a)](https://m8ven.ai/mcp/grasp-mcp-server-eq1d9a)
commit: bf0397b19af8234ca4775d75e8030146a05d925c
code hash: d1e09a432258744b79b14bb383e6047049f5e7b4b75f6e81c2830390ef498cac
verified: 7/30/2026, 8:20:24 PM
view raw JSON →