43
/ 100
1 month ago
mcp_so

Reftrixmcp

MCP server with 20 tools for web design analysis — layout extraction, motion detection, quality scoring, and semantic search via Playwright, pgvector, and Ollama.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 3 credentials: BULLMQ_UI_PASSWORD, MCP_API_KEY, REFTRIX_WORKER_SUPERVISOR_BOOT_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

lowjs-yaml@4.1.1GHSA-h67p-54hq-rp68

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configBACKFILL_RECONCILIATION_BATCH_LIMIT
configBACKFILL_RECONCILIATION_INTERVAL_MS
configBACKFILL_RECONCILIATION_RUN_ON_START
configBACKFILL_RECONCILIATION_STALE_THRESHOLD_MS
configBACKFILL_RECOVERY_BATCH_LIMIT
configBACKFILL_RECOVERY_INTERVAL_MS
configBACKFILL_RECOVERY_RUN_ON_START
configBULLMQ_UI_ENABLED
🔐 secretBULLMQ_UI_PASSWORD
configBULLMQ_UI_USER
configCSS_ANALYSIS_CACHE_DIR
configCSS_ANALYSIS_CACHE_MAX_SIZE
configCSS_ANALYSIS_CACHE_TTL_MS
configDEFAULT_PROJECT_ID
configDINOV2_MODEL_PATHcustom DINOv2 ViT-B/14 ONNX model path.
configEMBEDDING_BACKFILL_CONCURRENCY
configEMBEDDING_BACKFILL_MEMORY_PRESSURE_DELAY_MS
configEMBEDDING_CACHE_ENABLED(default true) -- enable/disable the Layout Embedding disk cache (additive opt-out flag; set "false" to write no cache files).
configENABLE_SECTION_MERGE_POSTPROCESSOR
configENABLE_SECTION_SPLIT_POSTPROCESSOR
configLD_LIBRARY_PATH
🔐 secretMCP_API_KEY
configMCP_API_KEYS
configMCP_AUTH_ENABLED
configOLLAMA_VISION_MODEL
configONNX_EXECUTION_PROVIDER
configPAGE_WORKER_CONCURRENCY
configPHASE0_CLEANUP_INTERVAL_MS
configPHASE0_CLEANUP_MAX_BATCH_SIZE
configPHASE0_CLEANUP_OLDER_THAN_MS
configPHASE0_CLEANUP_RUN_ON_START
configPHASE5_MAX_SECTIONS_INPUT
configPHASE5_PARENT_RSS_MAX_MB
configRATE_LIMIT_ENABLED
configRATE_LIMIT_RPM
configREDIS_HOST
configREDIS_MAX_RETRIES_PER_REQUEST
configREDIS_PORT
configREDIS_URLcp .env.example .env.local # edit DATABASE_URL / as needed
configREFTRIX_ALLOW_MANUAL_WORKERpage.analyze workers are auto-forked by WorkerSupervisor when the MCP server starts (v0.4.0 PR7d-2+); manual start is developer-only (=true required when MCP server is running)
configREFTRIX_CRASH_DUMP_ROOT
configREFTRIX_EMBEDDING_CACHE_ROOT
configREFTRIX_EMBEDDING_CACHE_ROOT_ALLOW_FALLBACK
configREFTRIX_REPO_ROOT
configREFTRIX_WORKER_CHILD_TYPE
configREFTRIX_WORKER_IS_CHILD
configREFTRIX_WORKER_STDERR_REDIRECT_ENABLED
🔐 secretREFTRIX_WORKER_SUPERVISOR_BOOT_TOKEN
configREFTRIX_WORKER_SUPERVISOR_BOOT_TOKEN_BACKFILL
configSCREENSHOT_CLEANUP_INTERVAL_MS
configSCREENSHOT_CLEANUP_MAX_BATCH_SIZE
configSCREENSHOT_CLEANUP_OLDER_THAN_MS
configSCREENSHOT_CLEANUP_RUN_ON_START
configT1A_COMMIT_SHA
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/tkmd-reftrixmcp-ogvxxs)](https://m8ven.ai/mcp/tkmd-reftrixmcp-ogvxxs)
commit: 89b828222357fdf2c695903ba98af3dac92495a8
code hash: 4083164ef9368df295a2f7c962c51f86ba031a0621b0674ac883bb743c5489f2
verified: 6/17/2026, 11:52:16 AM
view raw JSON →