Weavatrix Online runs on your own machine — the client starts it, so there is no endpoint to ping. 92 installs a week from npm. Last commit 24 Aug 2026.
Weavatrix Online extension: guarded sync, advisories, malware review, architecture contracts.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 25 August 2026. No other catalogue keeps this.
We read the source, 7 d ago · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
pattern: /(?:readFileSync|readFile|createReadStream|openSync|Get-Content|\bcat\s)[\s\S]{0,100}?(?:\.ssh\/id_(?:rsa|ed25519|dsa)|\.aws\/credentials|\.git-credentials|\/etc\/shadow|\.docker\/config\.json|\.kube\/config)/i,
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
пакет weavatrix-online ссылается на weavatrix/weavatrix-online
pattern: /(?:readFileSync|readFile|createReadStream|openSync|Get-Content|\bcat\s)[\s\S]{0,100}?(?:\.ssh\/id_(?:rsa|ed25519|dsa)|\.aws\/credentials|\.git-credentials|\/etc\/shadow|\.docker\/config\.json|\.kube\/config)/i,
pattern: /discord(?:app)?\.com\/api\/webhooks|hooks\.slack\.com\/services|api\.telegram\.org\/bot|pastebin\.com\/raw|burpcollaborator|oastify\.com|interact\.sh|webhook\.site|canarytokens\.(?:com|org)|dnslog\.cn/i,
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Weavatrix Online and you get told the day something new turns up.
This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.
claude mcp add weavatrix-online -- npx -y weavatrix-online
{
"mcpServers": {
"weavatrix-online": {
"args": [
"-y",
"weavatrix-online"
],
"command": "npx"
}
}
}
[mcp_servers.weavatrix-online]
command = "npx"
args = ["-y", "weavatrix-online"]
{
"mcpServers": {
"weavatrix-online": {
"args": [
"-y",
"weavatrix-online"
],
"command": "npx"
}
}
}
{
"mcpServers": {
"weavatrix-online": {
"args": [
"-y",
"weavatrix-online"
],
"command": "npx"
}
}
}
This one needs environment variables set before it will start:
WEAVATRIX_SYNC_URL (Cloud or compatible self-hosted sync endpoint), WEAVATRIX_SYNC_TOKEN (Scoped bearer token for the selected endpoint), WEAVATRIX_CAPABILITIES_URL (Optional explicit endpoint capability document URL; defaults to /api/v1/capabilities on the sync origin with legacy /api/health fallback), WEAVATRIX_ARCHITECTURE_URL (Optional explicit architecture-contract URL), WEAVATRIX_PRECISION (Core semantic precision: lsp (default) or off), WEAVATRIX_ADVISORY_STORE (Optional local advisory-cache file override).
The author declared them in the registry entry; get the values from the project itself.
Weavatrix Online extension: guarded sync, advisories, malware review, architecture contracts.
E-signatures for contracts and NDAs. Draft with AI, review, and send for signature.
Architecture-aware MCP context with boundaries, seams, impact scope, and BGI-TWIN guidance.
Structured execution for coding agents: contracts, postconditions, gates, guardrails.
Create, inspect and extract zip archives offline, with traversal, symlink and zip-bomb guards.
Create, inspect and extract zip archives offline, with traversal, symlink and zip-bomb guards.
Analyze any codebase — get architecture, file roles, execution flows, and agent context.
Turn an unfamiliar codebase into validated architecture, contracts, and a reimplementation spec.
Answers built from our own checks of this server.