C
Caution
74/100
9 days ago

ruvnet-brain

RuvNet Brain — a downloadable, source-grounded brain for Claude Code over Reuven Cohen's (rUv's) RuvNet stack: RuVector/RVF, Ruflo, AgentDB, RuLake, SPARC + 21 building blocks. Grounds Claude in real source via one MCP tool (search_ruvnet), so it builds with the stack instead of drifting off it.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

stuinfla

Source: github_topic

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
3 flows detected: GSC_ACCESS_TOKEN, RUVNET_GISTS_API, GITHUB_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 11 credentials: ANTHROPIC_ADMIN_KEY, ANTHROPIC_API_KEY, GEMINI_API_KEY, GH_TOKEN, GITHUB_TOKEN, GOOGLE_API_KEY, GSC_ACCESS_TOKEN, OPENAI_API_KEY, OPENROUTER_API_KEY, RUVNET_SIGNING_KEY, XAI_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configAIE_NTFY_TOPIC
configALLOW_NO_PRIVATE_FENCE
🔐 secretANTHROPIC_ADMIN_KEY
🔐 secretANTHROPIC_API_KEY
configCE_DEBUG
configCE_FORCE_WORKER_FAIL
configCE_MODEL
configCE_PARALLEL_MIN
configCE_WORKERS
configCLAUDE_BIN
configCODEX
configCODEX_BIN
configCODEX_HOME
configCODEX_SANDBOX
configCONSOLE_PORT
configComSpec
configEVAL_CONCURRENCY
🔐 secretGEMINI_API_KEY
configGH_BIN
🔐 secretGH_TOKEN
configGITHUB_ACTIONS
configGITHUB_RUN_ATTEMPT
configGITHUB_RUN_ID
🔐 secretGITHUB_TOKEN
configGITHUB_WORKFLOW
🔐 secretGOOGLE_API_KEY
🔐 secretGSC_ACCESS_TOKEN
configGUARD_INJECTION_LOG
configISSUE_FIX_COOLDOWN_HOURS
configISSUE_FIX_FAILED_RETRY_HOURS
configISSUE_FIX_GRACE_MS
configISSUE_FIX_LOCK
configISSUE_FIX_LOG_DIR
configISSUE_FIX_MAX_FAILED_ATTEMPTS
configISSUE_FIX_MAX_PER_RUN
configISSUE_FIX_MAX_TURNS
configISSUE_FIX_MODEL
configISSUE_FIX_TIMEOUT_MS
configISSUE_FIX_WORKTREE_DIR
configISSUE_WATCH_STATE
configJOB_HEARTBEAT_DIR
configKB_CE_CASCADE_K
configKB_CE_CASCADE_TOKENS
configKB_CE_MAX_PAIRS
configKB_CE_TRACE
configKB_CONCURRENCY
configKB_DEBUG
configKB_DIR
configKB_HYBRID
configKB_MODEL_CACHEexport =/path/to/models-cache
configKB_NAME
configKB_REPOS
configKB_REPO_ROOT
configKB_TRANSCRIPT_STORES
configMEMORY_DB
configMETAHARNESS_RECEIPTS
configMETAHARNESS_SCRIPTS_DIR
configMODEL_ROUTER_CATALOG
configMODEL_ROUTER_DECISIONS
configMODEL_ROUTER_OUTCOMES
configMODEL_ROUTER_PROFILE
configNTFY_TOPIC
🔐 secretOPENAI_API_KEY
🔐 secretOPENROUTER_API_KEY
configRECONCILE_STAMP
configRUVNET_AGGREGATE_ENVELOPE
configRUVNET_BIG_SHARDS
configRUVNET_BRAIN_CALL_TIMEOUT_MS
configRUVNET_BRAIN_CHILD_IDLE_MS
configRUVNET_BRAIN_CHILD_MCP
configRUVNET_BRAIN_COMPLETE_SOURCE
configRUVNET_BRAIN_EVIDENCE
configRUVNET_BRAIN_FETCH_TIMEOUT_MS
configRUVNET_BRAIN_HOME
configRUVNET_BRAIN_IDLE_EXIT_MS
configRUVNET_BRAIN_IMPORT_ONLY
configRUVNET_BRAIN_INIT_TIMEOUT_MS
configRUVNET_BRAIN_KB
configRUVNET_BRAIN_METER
configRUVNET_BRAIN_NO_UPDATE_FALLBACK
configRUVNET_BRAIN_PING_URL
configRUVNET_BRAIN_PROJECT_DIR
configRUVNET_BRAIN_STATE_DIR
configRUVNET_BRAIN_TEST
configRUVNET_BRAIN_TEST_LATEST_TAG
configRUVNET_CANDIDATE_PAYLOAD
configRUVNET_CANDIDATE_PAYLOAD_SIGNATURE
configRUVNET_CANDIDATE_RECEIPT
configRUVNET_CANONICAL_URL
configRUVNET_CAPABILITY_STATE_LOG
configRUVNET_CLAUDE_BIN
configRUVNET_CLAUDE_MARKETPLACE_SOURCE
configRUVNET_CODEX_BIN
configRUVNET_CODEX_HOOK_TRUST_MODE
configRUVNET_CONSOLE_DISABLE_BACKGROUND_REFRESH
configRUVNET_ENV_FILE
configRUVNET_EVIDENCE_FILE
configRUVNET_GISTS_API
configRUVNET_KNOWN_CLONES
configRUVNET_LEARNING_SCOPE
configRUVNET_LESSON_STORE
configRUVNET_MODEL_CATALOG
configRUVNET_NPM_VISIBILITY_ATTEMPTS
configRUVNET_NPM_VISIBILITY_TIMEOUT_MS
configRUVNET_PUBLICATION_RECEIPT
configRUVNET_RELEASE_ASSET_TIMEOUT_MS
configRUVNET_REPO
configRUVNET_RUFLO_BIN
🔐 secretRUVNET_SIGNING_KEY
configRUVNET_SIGNING_KEY_FILE
configRUVNET_STRICT_INSTALL
configRUVNET_UPGRADE_NOTICE_FILE
configRVF_MODULE_PATH
configSPEND_ALERT_USD
configSPEND_BURST_AGENTS
configSPEND_SCAN_ROOTS
configWATCHDOG_REGISTRY
configWATCHDOG_STATE
🔐 secretXAI_API_KEY
configXDG_CACHE_HOME
configXENOVA_PATH
// quality suggestions

Dependencies

7 dependencies, 1 flagged: playwright

Tool annotations

2/4 tools have annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

4/4 tools missing one or more hints — search_ruvnet (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_kb (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); ruvnet_cli_help (missing: openWorldHint), +1 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tests exist

No test files found

Add tests that exercise each declared tool.

Shell command execution

39 child_process/subprocess calls in production code — runs shell commands (plugin/mcp/server.mjs:189, plugin/mcp/managed-cli-interface.mjs:160, bin/api-spend-watchdog.mjs:95)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets stay with their owner

2 secret/sensitive values flow into network calls (GSC_ACCESS_TOKEN → searchconsole.googleapis.com, RUVNET_GISTS_API → dynamic) (1 other flows matched canonical API hosts)

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Secrets not written to files

3 secret values written to files

Avoid persisting secrets to disk. Keep them in memory or your secret manager.

Secrets not logged

5 secret values sent to console.log

Redact or omit secret values from log output.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/stuinfla-ruvnet-brain-gp2fyt?variant=verified)](https://m8ven.ai/mcp/stuinfla-ruvnet-brain-gp2fyt)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: b70fb01fadc7b333b03fea0dae516d10d2b5bc3a
code hash: 4aa8e8ebda6e7b61853e4ff3d781fceaa99216f769013d0eacfa7b81c6f52421
verified: 8/10/2026, 4:10:28 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client