39
/ 100
2 days ago
glama

ProvarDX MCP Server

Connects AI assistants to Provar projects for automated test generation, validation, and quality scoring using 170+ rules via Quality Hub API or local validation.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 5 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 4 credentials: GH_TOKEN, GITHUB_TOKEN, PROVAR_API_KEY, PROVAR_OAUTH_CLIENT_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical5 high1 medium4 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalfast-xml-parser@4.3.6GHSA-m7jm-9gc2-mpf2

fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

high@modelcontextprotocol/sdk@1.8.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.8.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highfast-xml-parser@4.3.6GHSA-8gc5-j5rx-235r

fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)

highfast-xml-parser@4.3.6GHSA-jmr7-xgp7-cmfj

fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretGH_TOKEN
🔐 secretGITHUB_TOKEN
configNVM_DIR
🔐 secretPROVAR_API_KEY~/.provar/credentials.json, and store it as the environment variable
configPROVAR_AUTO_DEFECTS
configPROVAR_COGNITO_CLIENT_ID
configPROVAR_COGNITO_DOMAIN
configPROVAR_DEV_WHITELIST_KEYS
configPROVAR_HOME
configPROVAR_MCP_EMIT_TOKEN_META
configPROVAR_MCP_MAX_TOOL_DEPTH
configPROVAR_MCP_QUALITY_THRESHOLD
configPROVAR_MCP_SCHEMA_MODE
configPROVAR_MCP_TOOLS
configPROVAR_MCP_VALIDATION_DIR
configPROVAR_NO_UPDATE_CHECK
configPROVAR_OAUTH_CLIENT_ID
🔐 secretPROVAR_OAUTH_CLIENT_SECRET
configPROVAR_QUALITY_HUB_URL
configSMOKE_INCLUDE_SETUP
configSMOKE_OVERALL_TIMEOUT_MS
configSMOKE_REQUEST_TIMEOUT_MS
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/provartesting-provardx-cli-8410rp)](https://m8ven.ai/mcp/provartesting-provardx-cli-8410rp)
commit: 2a64edf2ac3aa764fc320088d8e165899f08fe78
code hash: 3bb08916158b0996bd87e28549978faf5aab332cc3e42dcf06387dd1f7d6d8b6
verified: 7/29/2026, 9:14:47 AM
view raw JSON →