GrafMCP (SecCodeSmith/GrafMCP) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. No publisher has claimed this listing.
A local MCP server that gives code agents a shared, persistent graph memory backed by Kuzu, plus a live web dashboard for visualizing the graph and activity log.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
SecCodeSmith
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
GRAF_MCP_DBKuzu database locationGRAF_MCP_DEBUGevery raw MCP request method — only when GRAF_MCP_DEBUG=1GRAF_MCP_HOSTGRAF_MCP_LOG_LEVELGRAF_MCP_PORTDaemon port (MCP endpoint + dashboard)GRAF_MCP_WORKSPACEOverrides the automatic per-folder workspace. Set it to a fixed name to pin a project's workspace, or to default to restore the old single shared memory.[](https://m8ven.ai/mcp/seccodesmith/grafmcp)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check