Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

Hex Research

NPM · @LEVNIKOLAEVICH/HEX-RESEARCH-MCP · SCANNED AUG 4

Research graph MCP for hypotheses, goals, runs, source quality, audits, and generated maps.

+31 this week 77 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security83
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available. View diagnostics → Fail
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (142 of 146), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to levnikolaevich/claude-code-skills). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 87 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability70
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 1141 tokens (~71/item across 16 items; 16 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @levnikolaevich/hex-research-mcp

# add to Claude Code
claude mcp add levnikolaevich-hex-research-mcp -- npx -y @levnikolaevich/hex-research-mcp
# add to Codex CLI
codex mcp add levnikolaevich-hex-research-mcp -- npx -y @levnikolaevich/hex-research-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "levnikolaevich-hex-research-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@levnikolaevich/hex-research-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add levnikolaevich-hex-research-mcp --command npx --arg -y --arg @levnikolaevich/hex-research-mcp
# ~/.hermes/config.yaml
mcp_servers:
  levnikolaevich-hex-research-mcp:
    command: "npx"
    args: ["-y", "@levnikolaevich/hex-research-mcp"]
// mcp.json
{
  "mcpServers": {
    "levnikolaevich-hex-research-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@levnikolaevich/hex-research-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Aug 26 −1
    • CVE-2026-69207 affects this package: medium security
    • Known CVEs: partial → fail security
  • 2 Aug 26 +52
    • Known CVEs: unverified → partial security
    • Install scripts: unverified → pass security
    • Provenance: unverified → pass security
    • Malware scan: unverified → pass security
    • The attested source repository moved: levnikolaevich/claude-code-skills security
    • Stability: unverified → 0.20 functional
    • License: unverified → pass functional
    • Maintenance: unverified → pass functional
    • Schema quality: unverified → good functional
    • Dependency health: unverified → partial functional
    • Licence: MIT functional
  • 31 Jul 26 −20
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Jul 26 46

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Aug 2026 · Analysed npm/@levnikolaevich/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
levnikolaevich/claude-code-skills
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/levnikolaevich/claude-code-skills/.github/workflows/publish-hex-research.yml@refs/tags/hex-research-v0.2.1
Rekor log index:
1477781831
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:1621aded1d86b70285a3ca6f875ddeecb271d166efe45904b139471ec188626567886b7aadf966446469128fd4d9f00330782698ce3aa6c3fcfbed868
Discovery method:
attestation_endpoint
Vulnerabilities 1 finding
ID CVE Severity Vector Fix available
GHSA-8j4g-w8fx-2239 CVE-2026-69207 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
Dependencies 142 packages

142 packages in the resolved dependency tree · 142 deprecated · 57 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 16 exposed · ~1,141 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
analyze_progress ~59

Use git diff to identify changed research graph files and field-level frontmatter deltas that should be verified or reindexed.

NameTypeReqDescription
compare_againststringGit ref to compare against, default "HEAD"
pathstringProject root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

analyze_proposed ~61

Check one indexed hypothesis for readiness gaps before promotion or implementation.

NameTypeReqDescription
claim_substringstringFallback selector by claim substring
idstringCanonical H## or G## id
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

analyze_topology ~47

Summarize graph node/edge counts and high-degree hubs without dumping the full graph.

NameTypeReqDescription
limitMaximum hub rows to return
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

audit_goal_alignment ~51

Audit hypothesis-goal links, active goals without live hypotheses, goals missing explicit comprehensive-run metrics, and coverage candidates.

NameTypeReqDescription
limitMaximum issues to return
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

audit_orphans ~52

Audit orphaned, stale, missing-evidence, missing-source, dead-branch, task, and goal-run gaps.

NameTypeReqDescription
limitMaximum issues to return
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

export_canvas ~90

Export a bounded JSON Canvas map of goals, hypotheses, runs, and their relationships.

NameTypeReqDescription
dry_runbooleanPreview canvas JSON without writing the file
modestringmerge preserves existing node positions; overwrite creates a fresh layout
output_pathstringCanvas path relative to project root, default "docs/research-map.canvas"
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

export_research_map ~106

Generate docs/research-map.md from canonical split researchgraph files. Dry-run by default; refuses unmarked legacy overwrite unless force is true.

NameTypeReqDescription
dry_runbooleanPreview generated markdown without writing; default true
forcebooleanAllow replacing an unmarked legacy research-map.md after dry-run review
output_pathstringMarkdown path relative to project root, default "docs/research-map.md"
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

find_evidence ~67

Find evidence entries and cited sources, optionally scoped to one hypothesis and source/evidence type.

NameTypeReqDescription
idstringHypothesis id
limitMaximum rows to return
pathstringIndexed project root
typestringEvidence or source type
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

find_hypotheses ~141

Search indexed hypotheses by status, goal, task state, source type/year, priority tier, or claim text.

NameTypeReqDescription
cited_source_typestringCited source type filter
cited_source_year_minMinimum cited source year
claim_substringstringCase-insensitive claim substring
goalstringGoal id filter, e.g. G1
limitMaximum hypotheses to return
pathstringIndexed project root
priority_tierPriority tier filter
statusstringHypothesis status filter
task_statestringLinked task state filter
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

find_runs ~97

Find targeted or explicit comprehensive benchmark runs by run id, hypothesis id, type, and comprehensive flag; goal metrics derive only from explicit comprehensive runs.

NameTypeReqDescription
comprehensivebooleanFilter comprehensive runs
hypothesisstringHypothesis id for targeted runs
idstringRun id
limitMaximum rows to return
pathstringIndexed project root
typestringRun type
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

index_hypotheses ~58

Rebuild the local SQLite research graph from docs/hypotheses, docs/goals, and benchmark run manifests.

NameTypeReqDescription
pathstringProject root containing docs/hypotheses, docs/goals, and benchmark/runs
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

inspect_goal ~77

Return a bounded structured view of one goal, including parent/child goals, linked hypotheses, and derived metrics_current provenance or missing-metrics reason.

NameTypeReqDescription
claim_substringstringFallback selector by claim substring
idstringCanonical H## or G## id
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

inspect_hypothesis ~73

Return a bounded structured view of one hypothesis, including goals, tasks, evidence, runs, sources, and edges.

NameTypeReqDescription
claim_substringstringFallback selector by claim substring
idstringCanonical H## or G## id
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

trace_goal_tree ~49

Trace the bounded goal decomposition tree around one goal id.

NameTypeReqDescription
idstringyesStarting goal id
limitMaximum goals to return
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

trace_lineage ~68

Trace bounded hypothesis lineage and dependency edges around a hypothesis id.

NameTypeReqDescription
depthMaximum traversal depth
directionstringTraversal direction
idstringyesStarting hypothesis id
limitMaximum nodes to return
pathstringIndexed project root
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.

verify_index ~45

Validate research frontmatter and run manifests without rebuilding the SQLite index.

NameTypeReqDescription
pathstringProject root containing docs/hypotheses, docs/goals, and benchmark/runs
NameTypeReqDescription
detailsobject
follow_upsarray
messagestring
next_actionstring
provenance
qualityobject
reasonstring
result
statusstringyes
summaryobject
warningsarray

No examples provided.