@4da/mcp-server
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| FOURDA_DB_PATH | No | Path to 4DA's SQLite database. Default: Auto-detected. | |
| FOURDA_OFFLINE | No | Disable all network calls. Default: false. | false |
| MCP_AUTH_SECRET | No | Shared secret for verifying Bearer tokens on --http (HMAC-SHA256). Falls back to JWT_SECRET. Unset means no token is accepted. Default: Unset. | |
| MCP_ALLOWED_HOSTS | No | Extra comma-separated hostnames accepted in Host/Origin (needed when binding to 0.0.0.0). Default: localhost only. | |
| MCP_AUTH_REQUIRED | No | Require auth on a loopback --http bind. Always required on a non-loopback bind. Default: false. | false |
| FOURDA_EMBED_PROVIDER | No | Embedding provider for semantic recall. Set to "openai" to explicitly configure an OpenAI embedding provider (the decision/memory text you store is sent to OpenAI to be embedded); the default — no embedding provider, or a local Ollama one — keeps everything on your machine, and FOURDA_OFFLINE=true overrides it regardless. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
| prompts | {} |
| resources | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| vulnerability_scanA | Scan this project's lockfiles (npm/pnpm/yarn/bun, Cargo, Python, Go) for known OSV.dev vulnerabilities, transitives included, with fix versions and where each is pinned; |
| dependency_healthA | Dependency version freshness, deprecation and CVE counts across npm/Rust/Python/Go. Call when the user asks whether their dependencies are outdated, stale or need updating. |
| upgrade_plannerA | Prioritized upgrade plan: the 4DA app's work order when computed (per-line targets, manifest vs lockfile fix), else the smallest version that fixes each vulnerability from the lockfiles. Call when the user asks what to upgrade. |
| upgrade_impactA | What changes between the installed version of ONE dependency and a target version: changelog entries per release, breaking changes, deprecations, security fixes, and the files in this project that import it. Call before upgrading or bumping a dependency. |
| dependency_checkA | Verdict (proceed/wait/review/avoid/unknown) with evidence for adding a dependency or bumping one to a version. Call BEFORE you add a package or apply any version bump. |
| what_should_i_knowA | Pre-task briefing scoped to the task: the dependencies it touches, their installed versions, version-confirmed vulnerabilities, releases since, your recorded decisions, and a delegation verdict. Call BEFORE starting a non-trivial task, especially one that changes dependencies. |
| ecosystem_pulseA | Recent Hacker News discussions that name a dependency or framework this project actually uses. Call when the user asks what is new or being discussed in their ecosystem. |
| get_contextA | What 4DA knows about the user: role, tech stack, interests, exclusions, and detected project context. Call FIRST when you need to know what the user works on before answering or recommending. |
| decision_memoryA | Record, list, update, or supersede the developer's architectural and tech decisions. Call when the user makes, changes, or asks about a settled decision or convention. |
| check_decision_alignmentA | Check whether a technology or pattern aligns with the developer's recorded decisions. Call BEFORE suggesting a major tech change, new library, or architecture shift. |
| agent_memoryA | Cross-agent persistent memory: what one agent learns, any agent can recall. Call to store a discovery, decision, or warning, or to recall prior context before starting work. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| deps | Plan dependency upgrades, vet every bump with dependency_check, apply only the safe ones in small tested batches, and report the rest with evidence. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| vulnerability_scan schema | Full JSON Schema for the vulnerability_scan tool |
| dependency_health schema | Full JSON Schema for the dependency_health tool |
| upgrade_planner schema | Full JSON Schema for the upgrade_planner tool |
| upgrade_impact schema | Full JSON Schema for the upgrade_impact tool |
| dependency_check schema | Full JSON Schema for the dependency_check tool |
| what_should_i_know schema | Full JSON Schema for the what_should_i_know tool |
| ecosystem_pulse schema | Full JSON Schema for the ecosystem_pulse tool |
| get_context schema | Full JSON Schema for the get_context tool |
| get_relevant_content schema | Full JSON Schema for the get_relevant_content tool |
| get_actionable_signals schema | Full JSON Schema for the get_actionable_signals tool |
| knowledge_gaps schema | Full JSON Schema for the knowledge_gaps tool |
| record_feedback schema | Full JSON Schema for the record_feedback tool |
| decision_memory schema | Full JSON Schema for the decision_memory tool |
| check_decision_alignment schema | Full JSON Schema for the check_decision_alignment tool |
| agent_memory schema | Full JSON Schema for the agent_memory tool |
| developer_dna schema | Full JSON Schema for the developer_dna tool |
| Skill manifest | Registry of 4DA skills for Claude Code agent dispatch |
| Tool categories | Tool groupings by category with tag metadata |
TDQS
Scored across 11 tools
The dependency tools (vulnerability_scan, dependency_health, upgrade_planner, upgrade_impact, dependency_check) each have distinct triggers and outputs, but they cluster tightly around the same CVE/version domain and could be confused at the edges. The memory tools (decision_memory, agent_memory, check_decision_alignment) overlap more noticeably, since agent_memory explicitly also stores decisions that decision_memory owns.
Most names are snake_case noun phrases (vulnerability_scan, dependency_health, upgrade_planner, decision_memory), but the set mixes noun-phrase and verb_noun styles (get_context, check_decision_alignment) and includes the outlier 'what_should_i_know'. Readable, but no single predictable pattern.
11 tools is well-scoped for a dependency-intelligence and memory assistant, and each tool appears to earn its place with a defined workflow role (pre-task briefing, scanning, planning, impact, memory).
Coverage spans scanning, health, planning, impact, decisions, and cross-agent memory, which is strong for the stated domain. Minor gaps: no tool to enumerate the project's declared dependencies/manifests directly, and no way to record or apply the upgrade outcome after planning.