world-model-mcp
PyPI
v0.16.2
Published by an unidentified publisher — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
MCP server that builds a world model for codebases to prevent hallucinations, repeated mistakes, and regressions
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 8 = 92. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`adapters/pi/index.ts:22`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: rt { spawn } from "node:child_process"; import { mkdirSync } from "node:fs"; import { homedir } from "node:os"; import {
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server adapters/pi/index.ts
In the server's implementation (`hooks/src/world-model-inject.ts:11`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: import { spawn } from 'child_process'; type EventName = 'PostCompact' | 'UserPromptSubmit' | 'SessionStart'; interfac
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server hooks/src/world-model-inject.ts
In a packaging/dev/install script (shipped, but not the server runtime) (`benchmarks/repeat-mistake/agent_runner.py:184`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: try: proc = subprocess.run( cmd, cwd=str(checkout.repo_dir),
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server benchmarks/repeat-mistake/agent_runner.py
In a packaging/dev/install script (shipped, but not the server runtime) (`benchmarks/repeat-mistake/claude_client.py:86`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: proc = subprocess.run( [self.binary, "-p", "--output-format", "text"],
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server benchmarks/repeat-mistake/claude_client.py
In a packaging/dev/install script (shipped, but not the server runtime) (`benchmarks/repeat-mistake/clone_repo.py:39`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: stderr).""" proc = subprocess.run( cmd, cwd=cwd, capture_output=True, text=True,
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server benchmarks/repeat-mistake/clone_repo.py
In a packaging/dev/install script (shipped, but not the server runtime) (`benchmarks/repeat-mistake/score.py:56`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: join(cmd)}") proc = subprocess.run(cmd, env=os.environ.copy()) return proc.returncode def collect_results(
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server benchmarks/repeat-mistake/score.py
In a packaging/dev/install script (shipped, but not the server runtime) (`examples/managed-agents-self-hosted/deploy_modal.py:54`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: Modal immediately. subprocess.Popen(["python", "-m", "world_model_server.server"])
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server examples/managed-agents-self-hosted/deploy_modal.py
In a packaging/dev/install script (shipped, but not the server runtime) (`scripts/engagement_tracker.py:78`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: d JSON.""" result = subprocess.run( ["gh", "api", path], capture_output=True, text=True, timeout=15,
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server scripts/engagement_tracker.py
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/integration/test_buzz_acp_handshake.py:195`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: oot, }) proc = subprocess.Popen( [buzz_agent], stdin=subprocess.PIPE, stdout=subprocess
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/integration/test_buzz_acp_handshake.py
In a packaging/dev/install script (shipped, but not the server runtime) (`tests/test_etch_verify_subprocess_e2e.py:80`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: nts. """ return subprocess.run( [sys.executable, "-m", "world_model_server.etch_verify", *args],
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server tests/test_etch_verify_subprocess_e2e.py
Each tool and what it can reach — statically extracted from the published source.
export_claude_mdno sensitive capabilityfind_contradictionsno sensitive capabilityget_agents_md_constraintsno sensitive capabilityget_audit_log_headno sensitive capabilityget_co_edit_suggestionsno sensitive capabilityget_compaction_auditno sensitive capabilityget_constraintsno sensitive capabilityget_context_for_actionno sensitive capabilityget_decision_logno sensitive capabilityget_health_reportno sensitive capabilityget_injection_contextno sensitive capabilityget_related_bugsno sensitive capabilityingest_pr_reviewsno sensitive capabilitypin_annotationno sensitive capabilitypredict_regressionno sensitive capabilitypredict_test_failuresno sensitive capabilitypromote_constraintno sensitive capabilityprove_entry_inclusionno sensitive capabilityquery_factno sensitive capabilityrecall_transcript_rangeno sensitive capabilityrecord_compaction_auditno sensitive capabilityrecord_correctionno sensitive capabilityrecord_decisionno sensitive capabilityrecord_eventno sensitive capabilityrecord_test_outcomeno sensitive capabilityresolve_contradictionno sensitive capabilitysearch_globalno sensitive capabilityseed_projectno sensitive capabilitysimulate_changeno sensitive capabilityvalidate_changeno sensitive capabilityverify_retrievalno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.16.2 latest |
A 92/100 | 10 | 1.13.0 | 2026-08-25 |
v0.15.8 |
A 92/100 | 10 | 1.12.1 | 2026-08-03 |
v0.15.7 |
A 92/100 | 10 | 1.12.1 | 2026-07-31 |
v0.15.5 |
A 92/100 | 10 | 1.12.1 | 2026-07-27 |
v0.15.4 |
A 92/100 | 10 | 1.9.0 | 2026-07-24 |
v0.15.1 |
A 92/100 | 10 | 1.9.0 | 2026-07-23 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan world-model-mcp --online --registry pypi
MCP server for 2s.io — 575+ pay-per-call tools for AI agents — ground-truth data, AI gateway, and agent infra (storage, locks, queues, watchers). x402 USDC on Base/Solana, no API keys, upto usage billing, free trials.
ArXiv preprints + Google Scholar papers, with citation counts in one query.
Add MCP servers to your favorite coding agents with a single command.
Help agents automatically write and test stories for your UI components
Model Context Protocol server for AI-Archive platform - enables AI agents to discover, submit, and review research papers
MCP server for Semantic Scholar research workflows with stdio and Streamable HTTP transports.