DriftBLOCK
Codebase intelligence for AI. Detects patterns & conventions + remembers decisions across sessions. MCP server for any IDE. Offline CLI.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Drift stops an AI agent from writing code that violates conventions your repo already follows. It runs entirely on your machine.
Beta install: build from source. Nothing is published to npm yet —npm install -g @drift/clidoes not work, and thedriftdetectpackage on npm is the unrelated v1 from January. Building needs a Rust toolchain (rustup) because the scan engine is Rust.
git clone https://github.com/dadbodgeoff/drift.git && cd drift pnpm install --frozen-lockfile pnpm build && pnpm build:engine # There is no `drift` binary yet; the entry point is the built CLI. alias drift="node $PWD/packages/cli/dist/main.js" drift doctor --repo-root . # fails loudly if the toolchain is missing
Then, in the repository you want to protect:
cd your-repo drift start --repo-root . --accept-defaults
start prints whether the convention it accepted will actually block, and the command to make it a gate if it will not. Now have an agent add a route that queries the database directly, the way a hundred other routes in your repo do not, and check the change:
drift check --diff HEAD~1...HEAD --scope changed-hunks
It names the file, the line, and the convention that was broken. In block mode it exits 2.
--diff main...HEADonly works once your branch has commits thatmaindoes not. On a freshly cloned repo you are onmain, so that range is empty and Drift refuses rather than reporting a pass it cannot support — exit3. That refusal is correct; give it a range with changes in it.
Scope — read this before adopting
Drift enforces one convention family well, and says so rather than implying more:
**It doe
51722e380a67OBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add utils --env API_KEY=${API_KEY} --env BLOCKED_KEY=${BLOCKED_KEY} --env DOC_KEY=${DOC_KEY} --env KEY=${KEY} -- npx -y @acme/utils{
"mcpServers": {
"utils": {
"command": "npx",
"args": [
"-y",
"@acme/utils"
],
"env": {
"API_KEY": "${API_KEY}",
"BLOCKED_KEY": "${BLOCKED_KEY}",
"DOC_KEY": "${DOC_KEY}",
"KEY": "${KEY}"
}
}
}
}Exposed tools (13)
11 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
drift-beta-wave | write | Execute beta live-validation charters, escalate only what failed, assemble results |
get_allowed_context | read | Check whether a path can be exposed through an agent-facing surface. |
get_audit_status | read | Return read-only audit hash-chain verification status for a repo. |
get_capabilities | read | Return Drift V1 CLI and MCP capability metadata without reading repo source. |
get_conventions | read | Return accepted conventions for a repo. |
get_findings | read | Return stored Drift findings for a repo, with optional review filters. |
get_repo_contract | read | Return the approved repo contract, policy, and conventions. |
get_repo_map | write | Return the latest indexed file-role/import/export/call map and parser-gap quality without source snippets. |
get_required_check_executions | read | Return stored required-check execution proof for a repo without running commands. |
get_runtime_info | read | Return Drift runtime, schema, support-scope, and read-only governance metadata. |
get_scan_status | read | Return the latest Drift scan status for a repo, including parser-gap quality. |
get_security_context | read | Return accepted security contract context and middleware coverage summaries without source snippets. |
get_task_preflight | read | Return policy-filtered conventions, findings, and parser-gap quality relevant to a task. |
Trust audit
BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
engine-payload-limits.ts
repo-map-payload.ts
payload-invariants-baseline.json
denied_globs: ["**/.env", "**/.env.*", "**/*.pem", "**/*.key", "**/*.crt", "**/*.p12", "**/id_rsa", "**/id_ed25519"],
denied_globs: ["**/.env", "**/.env.*", "**/*.pem", "**/*.key", "**/*.crt", "**/*.p12", "**/id_rsa", "**/id_ed25519"],
denied_globs: ["**/.env", "**/.env.*", "**/*.pem", "**/*.key", "**/*.crt", "**/*.p12", "**/id_rsa", "**/id_ed25519"],
repo-identity.ts
rust-engine.ts
const user = { email: "SECRET_VALUE_SHOULD_NOT_LEAK", password: "sk_live_should_not_leak" };const config = { password: "SECRET_VALUE_SHOULD_NOT_LEAK" };token: "grouped_next_api_route_gets_api_route_role"
token: "refuses_reuse_from_a_different_engine_version"
token: "a_utility_from_the_familys_own_module_does_not_join"
_probelib.cpython-314.pyc
_stats.cpython-314.pyc
05-scan-and-incremental-reuse.md
engine-payload-gate.test.ts
stub-payload-engine.mjs
docs/internal/sprint-1/PROTOCOL.md
const meta = new Function(`return ${metaSrc}`)()const fn = new Function(...Object.keys(g), `return (async () => { ${body} })()`)const waves = new Function(`return ${src.match(/const WAVES = (\{[\s\S]*?\n\})/)[1].replace(/\/\/.*$/gm, '')}`)()const excl = new Function(`return ${src.match(/const EXCLUSIVE = new Set\((\[[^\]]*\])\)/)[1]}`)()exec(["start", "--repo-root", ".", "--accept-defaults"]);
"**/id_rsa",
Gates applied: no_behavioural_pass.
51722e380a67full audit observations/trust-audit/mcp-server/dadbodgeoff__drift.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | 51722e380a67 | BLOCK | F | 44 | first audit |
Questions
What is the Drift MCP server?
Codebase intelligence for AI. Detects patterns & conventions + remembers decisions across sessions. MCP server for any IDE. Offline CLI.
What tools does Drift expose?
13 in total: 11 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Drift safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (44/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Drift need?
It reads API_KEY, BLOCKED_KEY, DOC_KEY, KEY, SHADOW_KEY and STRIPE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (51722e380a67), read on 2026-09-27. The repository is watched and re-audited when it changes.