56
/ 100
1 month ago
glama

Deep SAST MCP Server

Provides deterministic, 100%-file-coverage security findings by running Semgrep, gitleaks, and osv-scanner on code repositories, enabling thorough security assessment of every file.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: MCP_AUTH_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOWED_GIT_HOSTS
configMAX_REPO_MBRepositories are shallow-cloned from allowed hosts only and size-capped by .
configCLONE_DEPTH
configSCAN_TIMEOUT_S
configCOMMAND_VERSION_TIMEOUT_S
🔐 secretMCP_AUTH_TOKENSet to require Authorization: Bearer <token> on MCP requests.
configPUBLIC_REPORTSwhen generated; set =false to require the same bearer token for reports.
configREPORTS_ROOT
configPUBLIC_BASE_URL
configSPACE_HOST
configSPACE_ID
configSPACE_AUTHOR_NAME
configSPACE_REPO_NAME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/piyushptiwari-github-code-assessment-mcp-n0we80)](https://m8ven.ai/mcp/piyushptiwari-github-code-assessment-mcp-n0we80)
commit: b3e879bcfd0a9d3a7ea4ce53794e29ce2781f4f4
code hash: 243f87b31cb7fc3aeb63a557be93a078880a5a54aa1a973dd1280781af7a9439
verified: 6/22/2026, 12:14:27 PM
view raw JSON →