0
/ 100
8 days ago
glama

aiquaa-api-quality-mcp-server

Analyzes API requirements and source code, evaluates existing Postman test coverage, and generates or updates test automation with an optional draft pull request on GitHub.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Hardcoded credentials detected
2 live-looking API keys in source: 2 AWS access key
🚨
Known vulnerabilities in dependencies: 1 critical
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
⚠️
Tests do not pass
Either the test suite is broken or the code regressed. Either way the published behaviour can’t be verified by the publisher’s own tests.
🔐
You'll be asked for 2 credentials: AIQUAA_ACCESS_TOKEN, GITHUB_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@3.2.4GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretAIQUAA_ACCESS_TOKENno JWT para AIQUAA en desarrollo (en producción, Authorization: Bearer a /mcp).
configAIQUAA_API_BASE_URLno Backend AIQUAA para requisitos/reglas remotas.
configCODEGRAPH_ALLOWED_ROOTSno Carpetas permitidas para codegraph, separadas por el separador de PATH del SO.
configCODEGRAPH_BINno (default codegraph) Binario de CodeGraph.
configENGRAM_BINno (default engram) Binario de Engram.
configENGRAM_PROJECT_PREFIXno (default aiquaa-) Prefijo de namespace de memoria por proyecto.
configGITHUB_API_URLno Para GitHub Enterprise. Default https://api.github.com.
🔐 secretGITHUB_TOKENsolo para api_pr con dry_run=false Token con permisos contents:write y pull-requests:write.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/stevenayal-aiquaa-api-quality-mcp-server-1p6g5b)](https://m8ven.ai/mcp/stevenayal-aiquaa-api-quality-mcp-server-1p6g5b)
commit: 201bf418228fdc8391f3b6a22c763fef2f6ff163
code hash: d62ab43c45cda673c0e34cc55d8908da7f8cd1c6db3815b4c5c57ff179124c66
verified: 7/23/2026, 9:06:13 AM
view raw JSON →