weavatrix-online
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@weavatrix-onlineRefresh advisories for the current repository"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Weavatrix Online
Take repository intelligence across a network without handing the network your repository.
The explicit network boundary of the Weavatrix ecosystem. Core and Refactor remain separate installs.
Weavatrix Online is the MIT-licensed MCP connector for Weavatrix Cloud and compatible customer-controlled endpoints. It keeps analysis local, produces an inspectable source-free payload, and requires an exact short-lived confirmation before that payload can leave the machine.
The public Online profile exposes 7 MCP tools for endpoint discovery,
advisories, malware review, architecture contracts, and controlled
synchronization. The local weavatrix-js graph engine is an implementation
detail: its tools are not re-exported, so installing Core, Refactor, and Online
together does not duplicate their catalogs in an agent's context.
Installing or starting Online does not synchronize anything. preview_sync
makes no network request; sync_graph accepts only the still-valid preview for
the same repository, destination, payload, and graph.
Choose the right Weavatrix package
Product | Install | Boundary |
| npm or Cargo | Native local-first MCP product. Both package managers distribute the same local Weavatrix server and engine. |
| Cargo | Protocol-independent Rust repository-intelligence engine for library and CLI use; it does not own MCP transport. |
| npm or Cargo | Native extension-only transactional refactoring; it uses the Rust graph engine internally. |
| npm | This optional network extension: source-free Cloud/self-hosted workflows over an internal local graph runtime. |
Online currently uses the JavaScript graph/runtime package internally:
weavatrix-online 0.3.4
└─ weavatrix-js 0.3.x (internal; no Core tools re-exported)It does not proxy the native weavatrix executable, import
weavatrix-refactor, or copy either engine. Use weavatrix when the graph must remain entirely local. Use
weavatrix-online when endpoint status, remotely managed architecture
contracts, advisory refresh, or explicit source-free synchronization is part of
the workflow.
Related MCP server: hve-squad MCP server
Install and run
Plugins for Cursor, Codex, Claude, and Grok
The repository now contains one portable plugin bundle at
plugins/weavatrix-online plus native marketplace manifests for all four
clients. The plugin starts the pinned npm release and includes an optional,
compact skill with one lazily loaded card per Online method.
codex plugin marketplace add Weavatrix/weavatrix-online --sparse .agents/plugins plugins/weavatrix-online
codex plugin add weavatrix-online@weavatrix-online
claude plugin marketplace add Weavatrix/weavatrix-online --sparse .claude-plugin plugins
claude plugin install weavatrix-online@weavatrix-online
grok plugin marketplace add Weavatrix/weavatrix-onlineCursor can load the bundle locally from
~/.cursor/plugins/local/weavatrix-online; public marketplace discovery starts
after the listing is reviewed and approved.
Direct MCP launch
Run the pinned release without a global install:
npx -y weavatrix-online@0.3.4 C:\path\to\repositoryThe command starts a stdio MCP server. The first positional argument is the repository to analyze. An existing graph can be supplied explicitly:
npx -y weavatrix-online@0.3.4 C:\graphs\repository\graph.json C:\path\to\repositoryThe npm package is intentionally an executable MCP product; it does not advertise a nonexistent JavaScript library entry point.
Codex
[mcp_servers.weavatrix_online]
command = "npx"
args = ["-y", "weavatrix-online@0.3.4", "C:\\path\\to\\repository"]
[mcp_servers.weavatrix_online.env]
WEAVATRIX_SYNC_URL = "https://app.weavatrix.com/api/v1/graphs/sync"
WEAVATRIX_SYNC_TOKEN = "load-from-runtime-secret-storage"Claude Desktop
{
"mcpServers": {
"weavatrix-online": {
"command": "npx",
"args": [
"-y",
"weavatrix-online@0.3.4",
"C:\\path\\to\\repository"
],
"env": {
"WEAVATRIX_SYNC_URL": "https://app.weavatrix.com/api/v1/graphs/sync",
"WEAVATRIX_SYNC_TOKEN": "load-from-runtime-secret-storage"
}
}
}
}Keep bearer tokens in the MCP client's runtime secret storage. Do not put them
in Git, a committed .env, release logs, or checked-in MCP configuration.
The seven Online tools
Tool | Network | Evidence and effect |
| Yes | Discovers endpoint capabilities, payload versions, limits, and auth mode without repository evidence. |
| Yes | Inventories exact dependency coordinates, queries OSV, validates returned records, and atomically refreshes the local cache. |
| No | Matches the current inventory against that cache. Missing, stale, partial, or mismatched coverage remains |
| No | Performs bounded static review of installed dependency files. Findings require review and are never a compromise verdict. |
| Yes | Fetches the owner-approved target for the active opaque repository ID, validates it, and updates the local graph cache. |
| No | Serializes the exact allowlisted payload, hashes it, and issues a five-minute confirmation token. |
| Yes | Sends only the payload approved by |
Install Weavatrix Core for read-only repository intelligence and Weavatrix Refactor for guarded source changes. Their methods remain in their owning products.
Typical workflows
Check endpoint compatibility before doing any repository work:
{"name":"online_status","arguments":{"timeout_ms":10000}}Refresh advisory evidence, then evaluate it locally:
{"name":"refresh_advisories","arguments":{"timeout_ms":20000}}
{"name":"scan_dependency_vulnerabilities","arguments":{"max_age_days":30}}Review the exact upload without sending it:
{"name":"preview_sync","arguments":{"payload_version":3}}After a human or trusted controller approves the displayed destination, section summary, counts, size, and body hash, use the returned token:
{
"name": "sync_graph",
"arguments": {
"payload_version": 3,
"dry_run": false,
"confirm_token": "token-returned-by-preview_sync",
"timeout_ms": 30000
}
}Changing the graph, repository, destination, payload, or expiry state invalidates that approval. A rejected or unavailable endpoint leaves the graph local.
Network and consent boundary
local repository
│
▼
local graph + derived evidence
│
▼
preview_sync ── inspect destination, sections, counts, size, and SHA-256
│
▼
explicit approval
│
▼
sync_graph ── capability negotiation ── approved endpointThe connector enforces:
HTTPS for every non-loopback destination;
loopback-only HTTP for local development;
no credentials embedded in URLs;
endpoint capability negotiation before upload;
a bounded versioned payload allowlist;
exact preview hashing and a short-lived confirmation token;
honest
NOT_CHECKEDandPARTIALstates when evidence is incomplete.
The sync payload contains bounded graph topology and selected derived evidence. It excludes source bodies, snippets, absolute host paths, environment values, credentials, Git remotes, and fields outside the wire allowlist. “Source-free” does not mean anonymous: review the displayed repository identity, destination, counts, sections, and hash before approval.
Configuration
Variable | Required | Meaning |
| For Online network workflows | Cloud or compatible self-hosted sync endpoint. |
| For Cloud/authenticated endpoints | Scoped bearer token sent only to the approved endpoint. |
| No | Explicit capability document; otherwise |
| No | Explicit owner-approved architecture-contract endpoint. |
| No | Local semantic precision: |
| No | Override local graph/cache storage. |
| No | Override the local advisory-cache file. |
Compatible endpoints must implement the versioned capability and sync contracts. Capability discovery itself sends no repository evidence.
Security evidence without false certainty
Advisory refresh covers pinned npm, PyPI, Go, Maven/Gradle, and crates.io coordinates found in bounded repository manifests. A clean zero is allowed only when the current inventory matches a complete, current Online cache.
Malware review is static and bounded. It can identify evidence such as download-and-execute lifecycle scripts, reverse-shell patterns, decoded execution, miner indicators, credential-file reads, or suspicious exfiltration endpoints. It cannot prove execution, provenance, credential exposure, safety, or compromise.
Architecture contracts are validated locally before becoming active.
Report vulnerabilities privately through GitHub Security Advisories.
Architecture
The connector is a strict modular ports-and-adapters system:
policy
└─ discovery adapters
└─ security cache and evidence services
└─ Online actions
└─ MCP composition and executablepolicy: destination validation, version matching, inventory identities, and malware evidence rules;discovery: bounded manifest and installed-package adapters;security: atomic advisory state, cached matching, scanning, and reporting;online-actions: capability, contract, advisory, preview, and sync use cases;composition: extension registration, launcher, and stdio executable.
The checked-in architecture contract enforces zero runtime cycles, production files at or below 300 physical lines, and functions at or below 100 physical lines, with no exceptions and no violation baseline.
Development and release proof
npm ci --ignore-scripts
npm test
npm run verify:release
npm audit
npm pack --dry-run --jsonThe release gate verifies package identity, dependency ranges, exact installed versions, MCP Registry metadata, checked-in release notes, MIT licensing, the published file allowlist, and tag/version agreement. CI repeats the tests, security audit, and package dry-run on Node.js 24.
License
MIT. Weavatrix Online and its internal weavatrix-js runtime are
independently versioned MIT-licensed packages.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceTurns any web API into a governed, agent-ready MCP server with lockfile-based approval, fail-closed enforcement, and full audit trail.MIT
- AlicenseAqualityAmaintenanceAn outbound MCP server that exposes a squad of 98 advisory agents as five model-invocable tools for research, planning, review, architecture, and async pipeline runs.6MIT
- AlicenseAqualityCmaintenanceEnables any MCP client to drive a multi-agent orchestration engine with planning, specialist tools, critic revision, and human-in-the-loop approval for sensitive actions.3MIT
- FlicenseNot gradedqualityBmaintenanceHosted remote MCP for AI agent browser approval. Provides structured tools for page approval workflows, session management, and audit receipts.
Related MCP Connectors
Remote MCP for A2A failure replay MCP, structured receipts, audit logs, and reviewer-ready evidence.
Remote MCP for Kiro release readiness, evidence binders, signoff, and CI approval receipts.
Workflow diagnostics, capability routing, and x402 settlement for MCP-compatible agents.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Weavatrix/weavatrix-online'
If you have feedback or need assistance with the MCP directory API, please join our Discord server