not analyzable — no source code found to analyze
MCP stdio server that scans a repository once and answers architecture questions from an evidence-backed graph, so agents stop re-reading the source tree to work out what depends on what. Scans PHP, TypeScript/JavaScript, and Python out of process and exposes 25 tools for impact analysis, dependency cycles, boundary policies, and diagram export.
Insufficient evidence to grade. This server's source has not been statically analyzed, so a low grade would only mean "nothing found", not "nothing there". We don't show a reassuring grade we can't stand behind. Attested signals (CVEs, provenance) below still apply.
Once the source is analyzed (see the analysis flag in the header), a graded score appears here. How analysis works: methodology.
graded 5m ago · see ecosystem CVEs →
- A · 8 → A · 5
No known CVEs for this server.
No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of AraneaDev.