Server data from the Official MCP Registry
Dev intelligence layer: 7 MCP tools for graph-powered codebase reasoning.
Dev intelligence layer: 7 MCP tools for graph-powered codebase reasoning.
GraQle is a sophisticated code analysis and governance platform with extensive functionality and generally sound security practices (no telemetry, secret scanning, Sigstore signatures). However, the MCP server implementation exhibits moderate concerns: unvalidated subprocess execution via gh CLI without input sanitization, broad shell command allowlists, overly permissive error handling with potential information disclosure, and insufficient validation of safety-critical LLM outputs. These issues are partially mitigated by governance gates and fallback mechanisms, but the combination creates exploitable attack surface for code injection and data exfiltration. Supply chain analysis found 6 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.
3 files analyzed · 17 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-quantamixsol-graqle": {
"args": [
"graqle"
],
"command": "uvx"
}
}
}Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.