37
/ 100
15 days ago
glama

Weavatrix

Provides a dependency graph of any local repository with tools for change impact, transitive dependents, health audits, and more, enabling AI coding agents to see structure and refactor safely.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: WEAVATRIX_SYNC_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 1 credential: WEAVATRIX_SYNC_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configGITHUB_REF_NAME
configGITHUB_REF_TYPE
configGOMODCACHE
configGOPATH
configPROGRAMFILES
configWEAVATRIX_OSV_TIMEOUT_MS
configWEAVATRIX_RG_CMD
🔐 secretWEAVATRIX_SYNC_TOKENendpoint is yours, configured via WEAVATRIX_SYNC_URL / . Off by default.
configWEAVATRIX_SYNC_URLendpoint is yours, configured via / WEAVATRIX_SYNC_TOKEN. Off by default.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/sergii-ziborov-weavatrix-i79io7)](https://m8ven.ai/mcp/sergii-ziborov-weavatrix-i79io7)
commit: d0952321d120691a35b6caef1c9629a243065079
code hash: f4434e4fd8f4ed654896a3035d208dec5331276503a8380bb322e0a5d5b47541
verified: 7/16/2026, 8:46:02 AM
view raw JSON →