Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

Hex Line

NPM · @LEVNIKOLAEVICH/HEX-LINE-MCP · SCANNED AUG 4

Hash-verified file editing MCP server with token efficiency hook for AI coding agents.

−10 this week 72 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security87
  • No malware found by supply-chain analysis.Pass
  • Only part of the dependency tree could be resolved (145 of 149), so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (145 of 149), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to levnikolaevich/claude-code-skills). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 67 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability36
  • AI-judged instruction clarity (fair).Partial
  • Context-footprint check failed: tool/resource definitions use about 1759 tokens (~195/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @levnikolaevich/hex-line-mcp

# add to Claude Code
claude mcp add levnikolaevich-hex-line-mcp -- npx -y @levnikolaevich/hex-line-mcp
# add to Codex CLI
codex mcp add levnikolaevich-hex-line-mcp -- npx -y @levnikolaevich/hex-line-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "levnikolaevich-hex-line-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@levnikolaevich/hex-line-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add levnikolaevich-hex-line-mcp --command npx --arg -y --arg @levnikolaevich/hex-line-mcp
# ~/.hermes/config.yaml
mcp_servers:
  levnikolaevich-hex-line-mcp:
    command: "npx"
    args: ["-y", "@levnikolaevich/hex-line-mcp"]
// mcp.json
{
  "mcpServers": {
    "levnikolaevich-hex-line-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@levnikolaevich/hex-line-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 3 Aug 26 +26
    • Known CVEs: unverified → partial security
    • Provenance: unverified → pass security
    • Install scripts: unverified → pass security
    • The attested source repository moved: levnikolaevich/claude-code-skills security
    • Maintenance: unverified → pass functional
    • Dependency health: unverified → partial functional
    • License: unverified → pass functional
    • Licence: MIT functional
  • 2 Aug 26 +18
    • Malware scan: unverified → pass security
    • Stability: unverified → 0.20 functional
  • 1 Aug 26 +22
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • MCP protocol: unverified → pass functional
    • Tool coverage: unverified → 100 functional
  • 31 Jul 26 −25
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −52
    • Provenance: pass → unverified security
    • Known CVEs: partial → unverified security
    • Malware scan: pass → unverified security
    • Install scripts: pass → unverified security
    • The attested source repository moved: levnikolaevich/claude-code-skills security
    • Dependency health: partial → unverified functional
    • License: pass → unverified functional
    • Maintenance: pass → unverified functional
    • Licence: MIT functional
  • 27 Jul 26 +57
    • Install scripts: unverified → pass security
    • Known CVEs: unverified → partial security
    • Provenance: unverified → pass security
    • The attested source repository moved: levnikolaevich/claude-code-skills security
    • Maintenance: unverified → pass functional
    • License: unverified → pass functional
    • Tool coverage: unverified → 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: fair functional
    • First check of Schema quality: fail functional
    • Licence: MIT functional
  • 26 Jul 26 25

    First indexed and scored.

    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Aug 2026 · Analysed npm/@levnikolaevich/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
levnikolaevich/claude-code-skills
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/levnikolaevich/claude-code-skills/.github/workflows/publish-hex-line.yml@refs/tags/hex-line-v1.31.0
Rekor log index:
1668585986
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:c4c751555ea5e68dfaa8069c88506e1d32f3e01bd8b9fd19d5591f1da231b2cf41bdeacc225047bc3dd0b6a26a21a4a80b0efd74b64db3c4e82190bf2
Discovery method:
attestation_endpoint
Dependencies 145 packages

145 packages in the resolved dependency tree · 144 deprecated · 49 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 9 exposed · ~1,759 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
bulk_replace ~184

Search-and-replace text across multiple files inside an explicit root path. Use for renames and refactors when the project scope is known.

NameTypeReqDescription
allow_externalbooleanAllow a replacement root outside the current project root. Use only when you intentionally target a temp or external directory.
dry_runbooleanPreview without writing (default: false)
formatstring"compact" (default) = summary only, "full" = include capped diffs
globstringFile glob (default: "**/*.{md,mjs,json,yml,ts,js}")
max_filesnumberMax files to process (default: 100)
pathstringyesRoot directory for the replacement scope
replacementsyesJSON array of {old, new} pairs: [{"old":"foo","new":"bar"}]
NameTypeReqDescription
codestring
contentstring
errorobject
failure_classstring
next_actionstring
pathstring
reasonstring
recoverystring
statusstringyes
summarystring

No examples provided.

changes ~67

Semantic diff against git ref (default: HEAD). Returns canonical status, summary, next_action, changed symbols, and graph-backed risk hints when available.

NameTypeReqDescription
compare_againststringGit ref to compare against (default: "HEAD")
pathstringyesFile or directory path
NameTypeReqDescription
codestring
contentstring
errorobject
failure_classstring
next_actionstring
pathstring
recoverystring
statusstringyes
summarystring

No examples provided.

edit_file ~479

Apply hash-verified partial edits to one file. Batch ALL hunks for the same file into ONE call via the `edits` array -- separate sequential edit_file calls on one file go stale and conflict (the most common edit failure). Carry base_revision only for a genuinely later follow-up after the file changed. Anchors accept tag.N, a bare line number, or unique line content (auto-resolved); range_checksum accepts "auto" to compute it for the current range. Preserves existing line endings and trailing-newline shape; conservative conflicts return retry helpers. boundary_mode=inclusive deletes the anchor lines themselves; new_text must close any delimiter whose opening falls inside the replaced range.

NameTypeReqDescription
allow_externalbooleanAllow editing a path outside the current project root. Use only when you intentionally target a temp or external file.
base_revisionstringPrior revision from read_file/edit_file. Enables conservative auto-rebase for same-file follow-up edits.
conflict_policystringConflict handling (default: "conservative"). "conservative" returns structured CONFLICT output with recovery_ranges, retry_edit/retry_edits, suggested_read_call, and retry_plan when available.
dry_runbooleanPreview changes without writing
editsyesJSON array of canonical edits. [{"set_line":{"anchor":"ab.12","new_text":"x"}}] [{"replace_lines":{"start_anchor":"ab.10","end_anchor":"cd.15","new_text":"x","range_checksum":"10-15:a1b2"}}] [{"inser…
file_pathstringyesFile to edit
restore_indentbooleanAuto-fix indentation to match anchor (default: false)
NameTypeReqDescription
codestring
contentstring
errorobject
failure_classstring
file_pathstring
next_actionstring
reasonstring
recoverystring
statusstringyes
summarystring
warningsarray

No examples provided.

grep_search ~364

Search file contents with ripgrep. Default: summary-first discovery output; use `content` with `edit_ready=true` when you need verified edit hunks.

NameTypeReqDescription
allow_large_outputbooleanBypass the default content-mode block/char caps when you intentionally need a larger payload.
case_insensitivebooleanIgnore case (-i)
contextnumberSymmetric context lines around matches (-C)
context_afternumberContext lines AFTER match (-A)
context_beforenumberContext lines BEFORE match (-B)
edit_readybooleanPreserve hash/checksum search hunks in `content` mode. Default: false.
globstringGlob filter (e.g. "*.ts")
head_limitnumberTotal match events across all files; multiline matches count as 1 (default: 50 for summary discovery, 200 for content, 1000 for files_with_matches/count, 0 = unlimited)
limitnumberMax matches per file (default: 20 for summary discovery, 100 for content)
literalbooleanLiteral string search, no regex (-F)
multilinebooleanPattern can span multiple lines (-U)
output_modestringOutput format (default: summary)
pathstringSearch dir/file (default: cwd)
patternstringyesSearch pattern (regex by default, literal if literal:true)
plainbooleanOmit hash tags, return file:line:content
smart_casebooleanCI when pattern is all lowercase, CS if uppercase (-S)
typestringFile type (e.g. "js", "py")
NameTypeReqDescription
codestring
contentstring
errorobject
failure_classstring
next_actionstring
patternstring
recoverystring
statusstringyes
summarystring

No examples provided.

inspect_path ~223

Inspect a file or directory path. Files return compact metadata; directories return a gitignore-aware tree or pattern matches.

NameTypeReqDescription
formatstring"compact" = shorter path view, "full" = include sizes/metadata where available
gitignorebooleanRespect root .gitignore patterns (default: true). Nested .gitignore not supported
max_depthnumberMax recursion depth (default: 2 for discovery, or 20 in pattern mode)
max_entriesnumberMax entries to show in pattern mode before truncation metadata is returned (default: 60, 0 = unlimited)
pathstringyesFile or directory path
patternstringGlob filter on names (e.g. "*-mcp", "*.mjs"). Returns flat match list instead of tree
typestring"file", "dir", or "all" (default). Like find -type f/d
verbositystringResponse budget. `minimal` returns the shortest tree summary.
NameTypeReqDescription
codestring
contentstring
errorobject
failure_classstring
next_actionstring
pathstring
reasonstring
recoverystring
statusstringyes
summarystring

No examples provided.

outline ~58

AST-based structural outline with hash anchors for direct edit_file usage. Supports JavaScript/TypeScript, Python, C#, and PHP code files plus markdown headings (.md/.mdx, fence-aware).

NameTypeReqDescription
file_pathstringyesSource file path
NameTypeReqDescription
codestring
contentstring
errorobject
failure_classstring
file_pathstring
next_actionstring
reasonstring
recoverystring
statusstringyes
summarystring

No examples provided.

read_file ~200

Read file with progressive disclosure. Default: minimal plain partial read for discovery; enable edit-ready metadata explicitly when preparing a verified edit.

NameTypeReqDescription
edit_readybooleanInclude hash/checksum edit protocol blocks explicitly. Default: false for discovery reads.
file_pathstringFile path
file_pathsarrayArray of file paths to read (batch mode)
limitnumberMax lines (default: 200 for discovery, 2000 for edit-ready, 0 = all)
offsetnumberStart line (1-indexed, default: 1)
plainbooleanOmit hashes (lineNum|content)
rangesLine ranges, e.g. ["10-25", {"start":40,"end":55}]
verbositystringResponse budget. `minimal` is discovery-first, `compact` adds revision context, `full` preserves the richest payload.
NameTypeReqDescription
codestring
contentstring
edit_readyboolean
errorobject
failure_classstring
file_pathstring
file_pathsarray
next_actionstring
recoverystring
statusstringyes
summarystring

No examples provided.

verify ~103

Check if held checksums are still valid without rereading. Use before delayed or mixed-tool follow-up edits; returns canonical status, next_action, and reread guidance.

NameTypeReqDescription
base_revisionstringOptional prior revision to compare against latest state.
checksumsarrayyesChecksum strings, e.g. ["1-50:f7e2a1b0", "51-100:abcd1234"]
file_pathstringyesFile path
NameTypeReqDescription
codestring
contentstring
errorobject
failure_classstring
file_pathstring
next_actionstring
reasonstring
recoverystring
statusstringyes
summarystring

No examples provided.

write_file ~81

Create a new file or overwrite existing. Creates parent dirs. For existing files prefer edit_file (shows diff, verifies hashes).

NameTypeReqDescription
allow_externalbooleanAllow writing a path outside the current project root. Use only when you intentionally target a temp or external file.
contentstringyesFile content
file_pathstringyesFile path
NameTypeReqDescription
codestring
errorobject
failure_classstring
file_pathstring
linesnumber
next_actionstring
recoverystring
statusstringyes
summarystring

No examples provided.