46
/ 100
1 month ago
glama

code-guard-ai

The only Multi-LLM Compliance Engine (GPT-4o + Claude + DeepSeek). Auto-fix GDPR/LGPD risks and more 15 frameworks. code.guard.eu

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: CODEGUARD_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Known vulnerabilities in dependencies: 1 critical, 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 13 credentials: CODEGUARD_API_KEY, CODEGUARD_API_SECRET, CODEGUARD_LICENSE_KEY, CODEGUARD_WEBHOOK_SECRET, KIMI_API_KEY, MINIMAX_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, SILICONFLOW_API_KEY, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, SUPABASE_ANON_KEY, SUPABASE_SERVICE_ROLE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical2 high1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalsimple-git@3.30.0GHSA-r275-fr43-pm7q

simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

highsimple-git@3.30.0GHSA-hffm-xvc3-vprc

simple-git is vulnerable to Remote Code Execution

highsimple-git@3.30.0GHSA-jcxm-m3jx-f287

simple-git Affected by Command Execution via Option-Parsing Bypass

lowjoi@18.1.2GHSA-q7cg-457f-vx79

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretCODEGUARD_API_KEY
configCODEGUARD_API_KEYSexport ="your-api-key-1,your-api-key-2"
🔐 secretCODEGUARD_API_SECRET
🔐 secretCODEGUARD_LICENSE_KEY
configCODEGUARD_MEMORY_PERSIST
configCODEGUARD_SAFE_ROOT
🔐 secretCODEGUARD_WEBHOOK_SECRET
configCOMPANY_NAME
🔐 secretKIMI_API_KEY
🔐 secretMINIMAX_API_KEY
🔐 secretOPENAI_API_KEY(Optional)
🔐 secretOPENROUTER_API_KEY
configPORT
🔐 secretSILICONFLOW_API_KEY
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
configSTRIPE_WEBHOOK_TOLERANCE_SEC
🔐 secretSUPABASE_ANON_KEY
🔐 secretSUPABASE_SERVICE_ROLE_KEY
configSUPABASE_URL
configTRANSPORT_MODEexport =sse
configVSCODE_PID
configWEBHOOK_URL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/negraodenio-code-guard-ai-a8gnwm)](https://m8ven.ai/mcp/negraodenio-code-guard-ai-a8gnwm)
commit: 132a65e8546271e854b71f0add31f37528c53948
code hash: 7bc8828b298b67e0edaed3b8edcdedbd5d21a9520954b323296a5c18e732d94d
verified: 6/14/2026, 11:17:22 AM
view raw JSON →