{"name":"io.github.davesheffer/hunch","slug":"davesheffer-hunch","title":null,"description":"Shared records for AI agents: engineering decisions, bug history, rules, and work state through MCP.","url":"https://mcp.market/server/davesheffer-hunch","rating":null,"grade":"C","score":66,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":45,"stars":10,"forks":1,"downloads_week":3154,"last_push_at":"2026-09-19T06:16:48.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/davesheffer/hunch","website":"https://www.hunchmemory.com","version":"1.38.1","remotes":[],"packages":[{"registryType":"npm","registryBaseUrl":"https://registry.npmjs.org","identifier":"@davesheffer/hunch","version":"1.38.1","runtimeHint":"npx","transport":{"type":"stdio"},"packageArguments":[{"description":"Start the Hunch MCP server (stdio) for the current repository.","value":"mcp","type":"positional"}]}],"tools":[],"scan":{"score":66,"grade":"C","scanned_at":"2026-09-19T09:55:11.500Z","report":{"scannerVersion":"0.1.3","scannedAt":"2026-09-19T09:55:11.461Z","components":{"code":{"score":8,"max":25,"notes":["454 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 0 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[{"id":"exec.eval","severity":"medium","component":"code","title":"eval / new Function used","evidence":"dist/cli/index.js: …); } store.close(); }); // ---- eval (retrieval quality; measures the graph-st…"},{"id":"exec.shell-concat","severity":"high","component":"code","title":"Shell command built from a string (injection risk)","evidence":"dist/core/served.js: … continue; try { db.exec(`ALTER TABLE served ADD COLUMN ${name} ${type}`); } catch (error)…"}],"inputs":{"packages":[{"registryType":"npm","identifier":"@davesheffer/hunch","version":"1.38.1","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":11,"publishedAt":"2026-09-16T15:13:17.796Z","repositoryUrl":"git+https://github.com/davesheffer/hunch.git","weeklyDownloads":3154}],"repo":{"found":true,"owner":"davesheffer","repo":"hunch","archived":false,"pushedAt":"2026-09-19T06:16:48Z","stars":10,"forks":1,"openIssues":49,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/26892525?v=4","ownerCreatedAt":"2017-04-04T06:40:12Z","license":"Apache-2.0"},"icon":{"url":"https://www.hunchmemory.com/hunch-mark.svg","source":"site"},"presence":{"stars":10,"forks":1,"downloadsWeek":3154,"license":"Apache-2.0","lastPushAt":"2026-09-19T06:16:48.000Z","score":45}}}},"grade_history":[],"reviews":[]}