67
/ 100
8 days ago
glama

RepoRescue MCP

Clones and inspects public GitHub repositories to extract evidence like manifests, dependencies, and version hints, and can run allow-listed repos in isolated Docker containers for reproducible verification.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configREPO_RESCUE_ALLOWED_REPOS$env:="pallets/click"
configREPO_RESCUE_MAX_REPO_MB
configREPO_RESCUE_PYTHON_IMAGE
configSYSTEMROOT
configREPO_RESCUE_INSTALL_TIMEOUT_SECONDS
configREPO_RESCUE_RUN_TIMEOUT_SECONDS
configREPO_RESCUE_EXECUTION_BACKEND
configREPO_RESCUE_HOST
configREPO_RESCUE_PORT
configREPO_RESCUE_TRANSPORTThe Streamable HTTP endpoint defaults to http://localhost:8000/mcp. Set =stdio for a command-based host.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/wenjieding327-repo-rescue-mcp-a6apsw)](https://m8ven.ai/mcp/wenjieding327-repo-rescue-mcp-a6apsw)
commit: 89423aae19eb46a7037dd319b6d2758c20a6a3b4
code hash: b33d8b54b4370512d0bf5c87f70e38c158fa5042e69676b24791245012efe9af
verified: 7/23/2026, 9:14:54 AM
view raw JSON →