Aletheore
ClaimedEvidence-grounded repository audit CLI - deterministic scanner, MCP server, live dashboard, and a GitHub Action that posts PR diffs.
Set up this server
01 / Choose your client
02 / Before you connect
Authentication is not specified. Check the project instructions before connecting.
Project instructions03 / Add the configuration
claude mcp add --transport stdio 'aletheore' -- 'uvx' 'aletheore'04 / Check it in your client
Open your client’s MCP settings and confirm the server connects and lists its tools. A copied configuration does not confirm a working connection.
More in Developer Tools
Browse the full directoryBadge
Show this listing on your README and website
Get verified and your listing links back to your site with a do-follow link. The badge is optional while first-100 launch spots remain.
Security profile
Exposure: Broad
Reaches into the environment, credential files or other agents' configuration.
What this server can reach, from a static read of the shipped code. Nothing was executed and nothing here is a verdict: a browser tool has to run commands and an API wrapper has to call its API. Decide what fits your setup.
Detected
- Talks to external services
Makes outbound requests. The hosts are listed so you can see where data goes.
api.github.com, api.groq.com, api.indierouter.ai, api.mistral.ai, api.nuget.org, api.openai.com, api.osv.dev, api.paddle.com, api.pushover.net, api.resend.com, api.securityscorecards.dev, api.slack.com, api.x.ai
- Reads environment variables in bulk
Copies or enumerates the whole environment, which can include keys meant for other tools.
- Runs shell commands
Spawns processes on your machine. Expected for command, browser and build tools.
- Accesses credential files
References SSH keys, cloud credential files or token stores.
- Contains instructions aimed at AI agents
Text in code or agent-facing files that steers a model. Worth reading before you trust it.
- Passes model output on without checks
Model output reaches HTML, SQL or a shell without validation.
- Runs unpinned packages at runtime
Executes npx or uvx without a version, so a compromised upstream release would run.
Dependencies with known advisories
None found in the lockfiles and manifests checked against OSV.dev.
Left out of the profile
20 pattern matches in documentation, configuration or CI files were recorded but are not part of the profile, because they do not run when the server does. The owner dashboard lists them.
Tool change history
FAQ
Questions about Aletheore MCP Server
- How do I connect Aletheore MCP Server to Claude?
- Run `claude mcp add aletheore -- uvx aletheore` in Claude Code, or add the same command and arguments under mcpServers in Cursor's mcp.json or Claude Desktop's claude_desktop_config.json, then restart the client. The blocks above are ready to paste.
- Is Aletheore MCP Server free?
- MCPVault has not verified a licence for this server. Check the upstream terms and pricing before use; connected APIs may require a paid account.
- What can Aletheore MCP Server do?
- MCPVault has not yet recorded the tool list for Aletheore MCP Server; it is captured when the server passes a live MCP handshake. The description above is what the project publishes.