Atlas / MCP servers / dadbodgeoff / Drift

DriftBLOCK

mcp/dadbodgeoff/drift

Codebase intelligence for AI. Detects patterns & conventions + remembers decisions across sessions. MCP server for any IDE. Offline CLI.

Verdict
BLOCK
Grade
F
Trust score
44 /100
Exposed tools
13 11r · 2w · 0d
Transport
—
License
MIT
Stars
789
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Drift stops an AI agent from writing code that violates conventions your repo already follows. It runs entirely on your machine.

Beta install: build from source. Nothing is published to npm yet — npm install -g @drift/cli does not work, and the driftdetect package on npm is the unrelated v1 from January. Building needs a Rust toolchain (rustup) because the scan engine is Rust.
git clone https://github.com/dadbodgeoff/drift.git && cd drift
pnpm install --frozen-lockfile
pnpm build && pnpm build:engine

# There is no `drift` binary yet; the entry point is the built CLI.
alias drift="node $PWD/packages/cli/dist/main.js"
drift doctor --repo-root .          # fails loudly if the toolchain is missing

Then, in the repository you want to protect:

cd your-repo
drift start --repo-root . --accept-defaults

start prints whether the convention it accepted will actually block, and the command to make it a gate if it will not. Now have an agent add a route that queries the database directly, the way a hundred other routes in your repo do not, and check the change:

drift check --diff HEAD~1...HEAD --scope changed-hunks

It names the file, the line, and the convention that was broken. In block mode it exits 2.

--diff main...HEAD only works once your branch has commits that main does not. On a freshly cloned repo you are on main, so that range is empty and Drift refuses rather than reporting a pass it cannot support — exit 3. That refusal is correct; give it a range with changes in it.

Scope — read this before adopting

Drift enforces one convention family well, and says so rather than implying more:

**It doe

Read from source at commit 51722e380a67OBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add utils --env API_KEY=${API_KEY} --env BLOCKED_KEY=${BLOCKED_KEY} --env DOC_KEY=${DOC_KEY} --env KEY=${KEY} -- npx -y @acme/utils
claude-desktop
{
  "mcpServers": {
    "utils": {
      "command": "npx",
      "args": [
        "-y",
        "@acme/utils"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "BLOCKED_KEY": "${BLOCKED_KEY}",
        "DOC_KEY": "${DOC_KEY}",
        "KEY": "${KEY}"
      }
    }
  }
}
03

Exposed tools (13)

11 read · 2 write · 0 destructive.

ToolRiskDescription
drift-beta-wavewriteExecute beta live-validation charters, escalate only what failed, assemble results
get_allowed_contextreadCheck whether a path can be exposed through an agent-facing surface.
get_audit_statusreadReturn read-only audit hash-chain verification status for a repo.
get_capabilitiesreadReturn Drift V1 CLI and MCP capability metadata without reading repo source.
get_conventionsreadReturn accepted conventions for a repo.
get_findingsreadReturn stored Drift findings for a repo, with optional review filters.
get_repo_contractreadReturn the approved repo contract, policy, and conventions.
get_repo_mapwriteReturn the latest indexed file-role/import/export/call map and parser-gap quality without source snippets.
get_required_check_executionsreadReturn stored required-check execution proof for a repo without running commands.
get_runtime_inforeadReturn Drift runtime, schema, support-scope, and read-only governance metadata.
get_scan_statusreadReturn the latest Drift scan status for a repo, including parser-gap quality.
get_security_contextreadReturn accepted security contract context and middleware coverage summaries without source snippets.
get_task_preflightreadReturn policy-filtered conventions, findings, and parser-gap quality relevant to a task.
04

Trust audit

BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (2 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
packages/cli/src/engine/engine-payload-limits.ts
engine-payload-limits.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
packages/query/src/repo-map-payload.ts
repo-map-payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
scripts/payload-invariants-baseline.json
payload-invariants-baseline.json
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/cli/src/domain/contract-materialization.ts:270
denied_globs: ["**/.env", "**/.env.*", "**/*.pem", "**/*.key", "**/*.crt", "**/*.p12", "**/id_rsa", "**/id_ed25519"],
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/cli/src/domain/convention-candidates.ts:255
denied_globs: ["**/.env", "**/.env.*", "**/*.pem", "**/*.key", "**/*.crt", "**/*.p12", "**/id_rsa", "**/id_ed25519"],
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/cli/src/domain/repo-paths.ts:50
denied_globs: ["**/.env", "**/.env.*", "**/*.pem", "**/*.key", "**/*.crt", "**/*.p12", "**/id_rsa", "**/id_ed25519"],
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/cli/src/domain/repo-identity.ts
repo-identity.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/cli/src/engine/rust-engine.ts
rust-engine.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
crates/drift-engine/tests/security_facts.rs:259
const user = { email: "SECRET_VALUE_SHOULD_NOT_LEAK", password: "sk_live_should_not_leak" };
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
crates/drift-engine/tests/security_facts.rs:1252
const config = { password: "SECRET_VALUE_SHOULD_NOT_LEAK" };
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/test/claim-coverage.test.ts:25
token: "grouped_next_api_route_gets_api_route_role"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/test/claim-coverage.test.ts:46
token: "refuses_reuse_from_a_different_engine_version"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/core/test/claim-coverage.test.ts:54
token: "a_utility_from_the_familys_own_module_does_not_join"
LOWInventory / provenance · inv.binary · CWE-1104
docs/beta-live-validation/harness/__pycache__/_probelib.cpython-314.pyc
_probelib.cpython-314.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/beta-live-validation/harness/__pycache__/_stats.cpython-314.pyc
_stats.cpython-314.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/beta-live-validation/results/05-scan-and-incremental-reuse.md
05-scan-and-incremental-reuse.md
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/cli/test/engine-payload-gate.test.ts
engine-payload-gate.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/cli/test/fixtures/stub-payload-engine.mjs
stub-payload-engine.mjs
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.symlink · CWE-1104
docs/internal/sprint-1/PROTOCOL.md
docs/internal/sprint-1/PROTOCOL.md
Why it matters. link not followed
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
docs/beta-live-validation/workflow/check-wave.mjs:11
const meta = new Function(`return ${metaSrc}`)()
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
docs/beta-live-validation/workflow/check-wave.mjs:38
const fn = new Function(...Object.keys(g), `return (async () => { ${body} })()`)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
docs/beta-live-validation/workflow/check-wave.mjs:73
const waves = new Function(`return ${src.match(/const WAVES = (\{[\s\S]*?\n\})/)[1].replace(/\/\/.*$/gm, '')}`)()
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
docs/beta-live-validation/workflow/check-wave.mjs:74
const excl = new Function(`return ${src.match(/const EXCLUSIVE = new Set\((\[[^\]]*\])\)/)[1]}`)()
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/e2e/check-refusal-legibility.test.ts:97
exec(["start", "--repo-root", ".", "--accept-defaults"]);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
packages/core/test/context-egress.test.ts:34
"**/id_rsa",
Why it matters. touches a credential store

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha 51722e380a67full audit observations/trust-audit/mcp-server/dadbodgeoff__drift.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2751722e380a67BLOCKF44first audit
06

Questions

What is the Drift MCP server?

Codebase intelligence for AI. Detects patterns & conventions + remembers decisions across sessions. MCP server for any IDE. Offline CLI.

What tools does Drift expose?

13 in total: 11 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Drift safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (44/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Drift need?

It reads API_KEY, BLOCKED_KEY, DOC_KEY, KEY, SHADOW_KEY and STRIPE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (51722e380a67), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement