Hex Research
NPM · @LEVNIKOLAEVICH/HEX-RESEARCH-MCP · SCANNED AUG 4
Research graph MCP for hypotheses, goals, runs, source quality, audits, and generated maps.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security83
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- Only part of the dependency tree could be resolved (142 of 146), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to levnikolaevich/claude-code-skills). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 87 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability70
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 1141 tokens (~71/item across 16 items; 16 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · @levnikolaevich/hex-research-mcp
claude mcp add levnikolaevich-hex-research-mcp -- npx -y @levnikolaevich/hex-research-mcp
codex mcp add levnikolaevich-hex-research-mcp -- npx -y @levnikolaevich/hex-research-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"levnikolaevich-hex-research-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"@levnikolaevich/hex-research-mcp"
],
"enabled": true
}
}
} openclaw mcp add levnikolaevich-hex-research-mcp --command npx --arg -y --arg @levnikolaevich/hex-research-mcp
mcp_servers:
levnikolaevich-hex-research-mcp:
command: "npx"
args: ["-y", "@levnikolaevich/hex-research-mcp"] {
"mcpServers": {
"levnikolaevich-hex-research-mcp": {
"command": "npx",
"args": [
"-y",
"@levnikolaevich/hex-research-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 4 Aug 26 −1
- CVE-2026-69207 affects this package: medium ▼ security
- Known CVEs: partial → fail ▼ security
- 2 Aug 26 +52
- Known CVEs: unverified → partial ▲ security
- Install scripts: unverified → pass ▲ security
- Provenance: unverified → pass ▲ security
- Malware scan: unverified → pass ▲ security
- The attested source repository moved: levnikolaevich/claude-code-skills security
- Stability: unverified → 0.20 ▲ functional
- License: unverified → pass ▲ functional
- Maintenance: unverified → pass ▲ functional
- Schema quality: unverified → good ▲ functional
- Dependency health: unverified → partial ▲ functional
- Licence: MIT functional
- 31 Jul 26 −20
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 46
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Aug 2026 · Analysed npm/@levnikolaevich/[email protected]
Provenance verified
Ecosystem: npm · Outcome: verified
Reason: verified
- Source repo:
- levnikolaevich/claude-code-skills
- Certificate issuer:
- https://token.actions.githubusercontent.com
- Certificate SAN:
- https://github.com/levnikolaevich/claude-code-skills/.github/workflows/publish-hex-research.yml@refs/tags/hex-research-v0.2.1
- Rekor log index:
- 1477781831
- Predicate type:
- https://slsa.dev/provenance/v1
- Subject digest:
- sha512:1621aded1d86b70285a3ca6f875ddeecb271d166efe45904b139471ec188626567886b7aadf966446469128fd4d9f00330782698ce3aa6c3fcfbed868
- Discovery method:
- attestation_endpoint
Vulnerabilities 1 finding
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-8j4g-w8fx-2239 | CVE-2026-69207 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
Dependencies 142 packages
142 packages in the resolved dependency tree · 142 deprecated · 57 stale.
The dependency tree was only partially resolved, so these counts may be incomplete.
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
analyze_progress Analyze Progress ~59
Use git diff to identify changed research graph files and field-level frontmatter deltas that should be verified or reindexed.
| Name | Type | Req | Description |
|---|---|---|---|
| compare_against | string | — | Git ref to compare against, default "HEAD" |
| path | string | — | Project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
analyze_proposed Analyze Proposed Hypothesis ~61
Check one indexed hypothesis for readiness gaps before promotion or implementation.
| Name | Type | Req | Description |
|---|---|---|---|
| claim_substring | string | — | Fallback selector by claim substring |
| id | string | — | Canonical H## or G## id |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
analyze_topology Analyze Topology ~47
Summarize graph node/edge counts and high-degree hubs without dumping the full graph.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | — | — | Maximum hub rows to return |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
audit_goal_alignment Audit Goal Alignment ~51
Audit hypothesis-goal links, active goals without live hypotheses, goals missing explicit comprehensive-run metrics, and coverage candidates.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | — | — | Maximum issues to return |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
audit_orphans Audit Orphans ~52
Audit orphaned, stale, missing-evidence, missing-source, dead-branch, task, and goal-run gaps.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | — | — | Maximum issues to return |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
export_canvas Export JSON Canvas ~90
Export a bounded JSON Canvas map of goals, hypotheses, runs, and their relationships.
| Name | Type | Req | Description |
|---|---|---|---|
| dry_run | boolean | — | Preview canvas JSON without writing the file |
| mode | string | — | merge preserves existing node positions; overwrite creates a fresh layout |
| output_path | string | — | Canvas path relative to project root, default "docs/research-map.canvas" |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
export_research_map Export Research Map Markdown ~106
Generate docs/research-map.md from canonical split researchgraph files. Dry-run by default; refuses unmarked legacy overwrite unless force is true.
| Name | Type | Req | Description |
|---|---|---|---|
| dry_run | boolean | — | Preview generated markdown without writing; default true |
| force | boolean | — | Allow replacing an unmarked legacy research-map.md after dry-run review |
| output_path | string | — | Markdown path relative to project root, default "docs/research-map.md" |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
find_evidence Find Evidence ~67
Find evidence entries and cited sources, optionally scoped to one hypothesis and source/evidence type.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | — | Hypothesis id |
| limit | — | — | Maximum rows to return |
| path | string | — | Indexed project root |
| type | string | — | Evidence or source type |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
find_hypotheses Find Hypotheses ~141
Search indexed hypotheses by status, goal, task state, source type/year, priority tier, or claim text.
| Name | Type | Req | Description |
|---|---|---|---|
| cited_source_type | string | — | Cited source type filter |
| cited_source_year_min | — | — | Minimum cited source year |
| claim_substring | string | — | Case-insensitive claim substring |
| goal | string | — | Goal id filter, e.g. G1 |
| limit | — | — | Maximum hypotheses to return |
| path | string | — | Indexed project root |
| priority_tier | — | — | Priority tier filter |
| status | string | — | Hypothesis status filter |
| task_state | string | — | Linked task state filter |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
find_runs Find Runs ~97
Find targeted or explicit comprehensive benchmark runs by run id, hypothesis id, type, and comprehensive flag; goal metrics derive only from explicit comprehensive runs.
| Name | Type | Req | Description |
|---|---|---|---|
| comprehensive | boolean | — | Filter comprehensive runs |
| hypothesis | string | — | Hypothesis id for targeted runs |
| id | string | — | Run id |
| limit | — | — | Maximum rows to return |
| path | string | — | Indexed project root |
| type | string | — | Run type |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
index_hypotheses Index Hypotheses ~58
Rebuild the local SQLite research graph from docs/hypotheses, docs/goals, and benchmark run manifests.
| Name | Type | Req | Description |
|---|---|---|---|
| path | string | — | Project root containing docs/hypotheses, docs/goals, and benchmark/runs |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
inspect_goal Inspect Goal ~77
Return a bounded structured view of one goal, including parent/child goals, linked hypotheses, and derived metrics_current provenance or missing-metrics reason.
| Name | Type | Req | Description |
|---|---|---|---|
| claim_substring | string | — | Fallback selector by claim substring |
| id | string | — | Canonical H## or G## id |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
inspect_hypothesis Inspect Hypothesis ~73
Return a bounded structured view of one hypothesis, including goals, tasks, evidence, runs, sources, and edges.
| Name | Type | Req | Description |
|---|---|---|---|
| claim_substring | string | — | Fallback selector by claim substring |
| id | string | — | Canonical H## or G## id |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
trace_goal_tree Trace Goal Tree ~49
Trace the bounded goal decomposition tree around one goal id.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Starting goal id |
| limit | — | — | Maximum goals to return |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
trace_lineage Trace Lineage ~68
Trace bounded hypothesis lineage and dependency edges around a hypothesis id.
| Name | Type | Req | Description |
|---|---|---|---|
| depth | — | — | Maximum traversal depth |
| direction | string | — | Traversal direction |
| id | string | yes | Starting hypothesis id |
| limit | — | — | Maximum nodes to return |
| path | string | — | Indexed project root |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.
verify_index Verify Research Index Inputs ~45
Validate research frontmatter and run manifests without rebuilding the SQLite index.
| Name | Type | Req | Description |
|---|---|---|---|
| path | string | — | Project root containing docs/hypotheses, docs/goals, and benchmark/runs |
| Name | Type | Req | Description |
|---|---|---|---|
| details | object | — | — |
| follow_ups | array | — | — |
| message | string | — | — |
| next_action | string | — | — |
| provenance | — | — | — |
| quality | object | — | — |
| reason | string | — | — |
| result | — | — | — |
| status | string | yes | — |
| summary | object | — | — |
| warnings | array | — | — |
No examples provided.