voyager-repo
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@voyager-repoScout this repo and tell me the risks before I start"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
voyager-repo
Voyager's repo-penetration organ — the eyes an AI agent sends ahead before it touches an unknown repository.
Voyager penetrates the web (@dir-ai/voyager),
the repo (this), and — next — networks. Repotector is the repo's guardian
that receives and controls; Voyager Repo is the agent's counterpart that reaches
outward and reports back, safely.
npx @dir-ai/voyager-repo scout . # orient in the repo you're standing in
npx @dir-ai/voyager-repo scout . --check-deps 10 # + vet 10 deps via VoyagerWhat it does
Like how Claude or Codex orient themselves in a new codebase — but as a safe,
repeatable tool. scout produces an orientation brief:
purpose — inferred from the manifest/README, framed as untrusted (owner text is injection-stripped before it reaches your model)
structure — languages, key dirs (with role guesses), entrypoints
build — the install/build/test/run commands (detected, never run)
health — git signals: commit count, bus factor (top-author share), recency, churn hotspots
dependencies — composes with Voyager to give each dependency a real OSV-gated verdict (
--check-deps N)risks — install hooks (RCE on
npm install), committed secrets, missing lockfile, large opaque binariesapproach plan — see below
Related MCP server: gitl
The approach protocol (the point)
A careful newcomer, not a bulldozer:
Handshake with Repotector if the repo carries one (
.repotector/) — read its active zones/leases and respect them before editing.Fail-closed permissions. Everything is read-only by default. Installing dependencies, executing code, or cloning a remote is withheld until you consent (
--allow-install/--allow-exec/--allow-clone) — and execution, when allowed, belongs in a sandbox.An orderly tour — the brief ends with the ordered next steps a well-behaved agent should take, so it explores on purpose instead of poking at random.
Guarantees
Nothing in the target is executed on the host.
scoutreads files and git; it never runs the repo's code. (Execution, when consented, runs in Voyager's hardened container.)Every owner-controlled byte is untrusted — README, description, commit messages, the Repotector ledger — injection-stripped and framed before your model sees it.
Exit codes:
0oriented ·1oriented + HIGH-risk finding(s) ·2tool error.
MCP
voyager-repo mcpTool: scout_repo — same orientation, safe-by-default (invasive flags off).
Library
import { scout } from '@dir-ai/voyager-repo'
const brief = await scout('/path/to/repo', { checkDeps: 10 })
if (brief.risks.some((r) => r.level === 'high')) { /* caution */ }Status
0.x — Phase 1 (repo orientation) of the Voyager "senses" line. Roadmap:
capability analysis of a package's tarball, PyPI/cargo/go dependency vetting,
and the net organ (cloud/infra introspection).
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceRemote MCP server enabling AI clients to securely inspect repositories over SSH with read-only tools.MIT
- AlicenseNot gradedqualityAmaintenanceAI code reviews and git activity digests with machine-readable risk scoring, available as an MCP server for use within an agent session.1MIT

repo-doctorofficial
AlicenseNot gradedqualityCmaintenanceMCP server that produces scored, evidence-cited audits of public GitHub repos via tools for fetching metadata, reading files, scanning git history, and checking hygiene.MIT- AlicenseNot gradedqualityCmaintenanceMCP server that scans PyPI packages and GitHub repos for security vulnerabilities, dangerous patterns, and prompt injection vectors, providing trust scores (0-10) and side-by-side comparisons.MIT