41
/ 100
1 month ago
github_topic

metaharness

πŸ› οΈ The meta-harness for AI agents β€” scaffold your own focused, branded agent harness with its own npx CLI, MCP server, memory, learning loop, and witness-signed releases. Works with Claude Code, Codex, pi.dev, Hermes, OpenClaw, and RVM (hardware-isolated sandbox).

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry β€” install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
πŸ”
You'll be asked for 3 credentials: INFRACOST_API_KEY, OPENROUTER_API_KEY, WITNESS_SIGNING_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 critical

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@2.0.0GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

criticalvitest@2.0.0GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

Depend on this server? Get alerted when its CVEs change.Watch this server free β†’
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configBENCH_HOST_ITERS
configBENCH_HOST_OUT
configBENCH_ITEMS
configBENCH_OUT
configBENCH_QUERIES
configCHECKOV_BIN
configDRACO_CONCURRENCY
πŸ” secretINFRACOST_API_KEY
configINFRACOST_BIN
configMACHINE
πŸ” secretOPENROUTER_API_KEY
configPINATA_JWT
configPROJECT
configTERRAFORM_BIN
configTF_PLUGIN_CACHE_DIR
configVITE_BASE
πŸ” secretWITNESS_SIGNING_KEY
configZONE
configDARWIN_BASE_URL
configDARWIN_COST_SIDECAR
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance β€” verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/ruvnet-metaharness-15agwf)](https://m8ven.ai/mcp/ruvnet-metaharness-15agwf)
commit: 7c5b3be0c7f71bfcd17b103d2189620a7bcb3375
code hash: 3a994eb901a497dd7e5d9ceb8acbd048f49d38472734819dc575f2ff4edaab43
verified: 6/30/2026, 9:53:44 AM
view raw JSON β†’