heuristic-mcp (softerist/heuristic-mcp) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. No publisher has claimed this listing.

C
Caution
74/100

heuristic-mcp

Enhanced MCP server for semantic code search with call-graph proximity, recency ranking, and find-similar-code. Built for AI coding assistants.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

softerist

Source: github_topic · also listed on Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 1 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
// known CVEs in dependencies1 critical1 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@4.0.18GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

high@modelcontextprotocol/sdk@1.25.3GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configEMBEDDING_PROCESS_PERSISTENT
configHEURISTIC_MCP_PID
configHEURISTIC_MCP_PROCESS_LIFECYCLE
configSMART_CODING_ANN_CANDIDATE_MULTIPLIER
configSMART_CODING_ANN_EF_CONSTRUCTION
configSMART_CODING_ANN_EF_SEARCH
configSMART_CODING_ANN_ENABLED
configSMART_CODING_ANN_INDEX_CACHE
configSMART_CODING_ANN_M
configSMART_CODING_ANN_MAX_CANDIDATES
configSMART_CODING_ANN_METRIC
configSMART_CODING_ANN_MIN_CANDIDATES
configSMART_CODING_ANN_MIN_CHUNKS
configSMART_CODING_AUTO_STOP_OTHER_SERVERS_ON_STARTUP
configSMART_CODING_BATCH_SIZE
configSMART_CODING_CHUNK_SIZE
configSMART_CODING_CLEAR_CACHE_AFTER_INDEX
configSMART_CODING_CONTENT_CACHE_ENTRIES
configSMART_CODING_EMBEDDING_BATCH_SIZE
configSMART_CODING_EMBEDDING_DIMENSION
configSMART_CODING_EMBEDDING_FAIL_FAST_BREAKER
configSMART_CODING_EMBEDDING_MODEL
configSMART_CODING_EMBEDDING_PROCESS_GC_MAX_REQUESTS
configSMART_CODING_EMBEDDING_PROCESS_GC_MAX_REQUESTS_WITHOUT_COLLECTION
configSMART_CODING_EMBEDDING_PROCESS_GC_MIN_INTERVAL_MS
configSMART_CODING_EMBEDDING_PROCESS_GC_RSS_THRESHOLD_MB
configSMART_CODING_EMBEDDING_THREADS
configSMART_CODING_EXACT_MATCH_BOOST
configSMART_CODING_EXPLICIT_GC
configSMART_CODING_INCREMENTAL_GC_THRESHOLD_MB
configSMART_CODING_INCREMENTAL_MEMORY_PROFILE
configSMART_CODING_INDEX_CHECKPOINT_INTERVAL_MS
configSMART_CODING_LOGS
configSMART_CODING_MAX_FILE_SIZE
configSMART_CODING_MAX_RESULTS
configSMART_CODING_MEMORY_LOG_INTERVAL_MS
configSMART_CODING_PRELOAD_EMBEDDING_MODEL
configSMART_CODING_RECENCY_BOOST
configSMART_CODING_RECENCY_DECAY_DAYS
configSMART_CODING_RECYCLE_SERVER_COOLDOWN_MS
configSMART_CODING_RECYCLE_SERVER_DELAY_MS
configSMART_CODING_RECYCLE_SERVER_ON_HIGH_RSS_AFTER_INCREMENTAL
configSMART_CODING_RECYCLE_SERVER_RSS_THRESHOLD_MB
configSMART_CODING_REQUIRE_TRUSTED_WORKSPACE_SIGNAL_FOR_TOOLS
configSMART_CODING_SEMANTIC_WEIGHT
configSMART_CODING_SHUTDOWN_INDEX_WAIT_MS
configSMART_CODING_SHUTDOWN_QUERY_POOL_AFTER_INDEX
configSMART_CODING_SMART_INDEXING
configSMART_CODING_UNLOAD_MODEL_AFTER_INDEX
configSMART_CODING_UNLOAD_MODEL_AFTER_SEARCH
configSMART_CODING_VECTOR_CACHE_ENTRIES
configSMART_CODING_VECTOR_STORE_CONTENT_MODE
configSMART_CODING_VECTOR_STORE_FORMAT
configSMART_CODING_VECTOR_STORE_LOAD_MODE
configSMART_CODING_VERBOSE
configSMART_CODING_WATCH_FILES
configSMART_CODING_WORKER_DISABLE_HEAVY_MODEL_ON_WINDOWS
configSMART_CODING_WORKER_DISABLE_HEAVY_MODEL_WINDOWS
configSMART_CODING_WORKER_THREADS
configVITEST
configXDG_CACHE_HOME
// quality suggestions

No eval / new Function

1 eval() or new Function() call — dynamic code execution

Replace eval / Function with explicit parsing or safer alternatives.

No arbitrary install scripts

Has postinstall/preinstall script — runs arbitrary code on npm install

Remove postinstall/preinstall hooks unless they’re essential.

Production dependencies are patched

0 critical, 1 high severity in production deps — @modelcontextprotocol/sdk@1.25.3 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Dev dependencies

1 critical/high in dev-only deps (does not ship to users)

Upgrade dev dependencies when convenient.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/softerist/heuristic-mcp?variant=verified)](https://m8ven.ai/mcp/softerist/heuristic-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: b28d6bbbf90a202ee26cda8f2f9b7e569fcb322b
code hash: c9a8ae6a82a733ffc25594c9f0998ebfd88f5bfcb1c5991fe3f921b5bff34f20
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client