{"name":"io.github.thecolourfoundation/rune","slug":"thecolourfoundation-rune","title":null,"description":"Evidence-traced codebase understanding and security scanning for AI agents over MCP.","url":"https://mcp.market/server/thecolourfoundation-rune","rating":null,"grade":"A","score":89,"certified":false,"status":"active","category":"security","tags":["security"],"presence":{"score":24,"stars":8,"forks":0,"downloads_week":null,"last_push_at":"2026-09-20T07:22:05.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/thecolourfoundation/rune","website":null,"version":"0.3.0","remotes":[],"packages":[{"registryType":"npm","identifier":"@moosl/rune","version":"0.3.0","transport":{"type":"stdio"},"runtimeArguments":[{"value":"serve","type":"positional"},{"description":"Absolute path to the project directory to scan and serve.","isRequired":true,"type":"positional","valueHint":"project_dir"}]}],"tools":[{"name":"rune_explain","description":"Given a fact or derived-conclusion id (as returned by other rune_ tools), return the full evidence trail: the raw fact(s) it's based on, file, line, and matched source text.","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_get_experience","description":"Get the history of past task attempts recorded for this project: what was tried, whether it succeeded or failed, and why. This is raw history, not verified rules -- use rune_get_memory for trusted, approved conventions.","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_get_file_dependencies","description":"Get the internal (relative-import) dependency list for a given file path, as recorded in the understanding graph.","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_get_memory","description":"Get durable project-specific knowledge Rune has recorded: conventions, required commands, known pitfalls. Each entry has a status (proposed/approved/rejected) and confidence score -- only 'approved' entries should be treated as trusted; 'proposed' entries are unverified and should be treated as a hint, not a fact.","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_get_overview","description":"Get a high-level architecture summary of the software: detected stack, component count, route count. Start here.","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_get_security_findings","description":"Get all security findings Rune has detected in this project: exposed secrets, dangerous shell execution, risky CI/CD workflow permissions, and typosquat-shaped dependencies. Use this before merging a PR or reviewing a codebase for security risk -- this is the single call that answers 'are there security concerns in this repo.' Every finding cites file, line, matched evidence, severity, and confide","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_list_components","description":"List all React components Rune has identified, with file location and detection kind (function/class).","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_list_routes","description":"List all API/page routes Rune has identified across Express and Next.js (pages + app router).","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_rescan","description":"Re-scan the project from disk and refresh Rune's understanding graph. Call this after significant code changes if `rune watch` isn't already running in the background.","write_action":false,"price_micros":0,"input_schema":null},{"name":"rune_search","description":"Search facts and derived understanding by name, file path, or route path substring. Use this to find where something lives before reading files directly.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":89,"grade":"A","scanned_at":"2026-09-21T05:08:40.327Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-21T05:08:40.351Z","components":{"code":{"score":25,"max":25,"notes":["21 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 1 days ago"]},"identity":{"score":6,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[],"inputs":{"packages":[{"registryType":"npm","identifier":"@moosl/rune","version":"0.3.0","found":true,"license":"MIT","hasInstallScripts":false,"dependencyCount":4,"publishedAt":"2026-08-28T10:08:20.658Z"}],"repo":{"found":true,"owner":"thecolourfoundation","repo":"rune","archived":false,"pushedAt":"2026-09-20T07:22:05Z","stars":8,"forks":0,"openIssues":3,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/273975473?v=4","ownerCreatedAt":"2026-04-06T10:14:52Z","license":"MIT"},"icon":{"url":"https://avatars.githubusercontent.com/u/273975473?v=4&s=128","source":"github"},"presence":{"stars":8,"forks":0,"downloadsWeek":null,"license":"MIT","lastPushAt":"2026-09-20T07:22:05.000Z","score":24}}}},"grade_history":[],"reviews":[]}