Luvv MCPServer
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| LOG_LEVEL | No | 日志级别(debug/info/warn/error) | info |
| SEMGREP_CONFIG | No | semgrep 规则集(如 p/security-audit、p/owasp-top-ten 等) | auto |
| SEMGREP_TIMEOUT | No | semgrep 超时时间(秒) | 300 |
| GITLEAKS_TIMEOUT | No | gitleaks 超时时间(秒) | 120 |
| INCLUDE_RAW_OUTPUT | No | 是否返回完整原始输出 | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| run_security_scanA | 对目标目录执行安全扫描,内部自动并行调用 semgrep(SAST 静态分析)和 gitleaks(硬编码密钥检测),返回合并的结构化 JSON 审计报告。若依赖工具未安装,报告中会附带各平台的安装指引。 |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 1 tool
With only one tool, there is no possibility of confusion between tools. The tool's purpose is clearly described.
The single tool name 'run_security_scan' follows a clear verb_noun pattern, which is consistent and descriptive.
Having only one tool feels thin for a general-purpose server, but for a focused security scanning utility it is borderline acceptable. The count is at the low end of reasonable.
The server lacks any other tools beyond the security scan, providing no CRUD or lifecycle operations. It is severely limited for a typical MCP server, with significant gaps in functionality.