Atlas / MCP servers / enola-labs / Enola

EnolaCAUTION

mcp/enola-labs/enola-1

Understand, analyze, and govern software systems across repositories, languages, and technologies.

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
2 2r · 0w · 0d
Transport
streamable-http
License
Apache-2.0
Stars
257
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

enola

enola - One graph of your whole software system, built from the code, on your machine

Website · Docs · CLI reference · Benchmarks · Releases · Report a gap

enola reads your source code and writes down what is in it: the modules, the functions, the API routes, the database tables it touches, the message topics it publishes. Then it records how each of those pieces connects to the others, inside one repository and across several. That record is a graph: a list of things, and a list of links between them. You can ask the graph questions, hand it to your coding agent, or build your own tools on it.

Runs locally as one binary. No AI model, no language server, no account, no upload. The graph comes from parsing your code. The same code always produces the same graph.

Read from source at commit 250554a33411OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add ts-sample -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "ts-sample": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
list_datasets_jsonreadpass
list_users_toolreadTool handler — dispatched by the MCP server, no in-code caller.
04

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
cmd/enola/main.go:357
fmt.Fprintf(os.Stderr, "Shared URL: http://127.0.0.1:%d (whichever server holds it lists all the others)\n", opts.StablePort)
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cmd/enola/consumer_contract_test.go:30
const consumerFixtures = "../../internal/engine/testdata/repos"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/cross-repo/run.sh:14
echo "then re-run with:  ENOLA=../../enola ./run.sh" >&2
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/custom-client/run.sh:14
echo "then re-run with:  ENOLA=../../enola ./run.sh" >&2
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/layers-gate/run.sh:14
echo "then re-run with:  ENOLA=../../enola ./run.sh" >&2
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/engine/custom_client_example_test.go:21
const customClientExample = "../../examples/custom-client"
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
internal/extractors/tsextractor/ts_io_test.go:20
export function beacon(d) { return navigator.sendBeacon('/b', d); }
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
internal/extractors/tsextractor/ts_io_test.go:25
for _, name := range []string{"src.getFeed", "src.getUser", "src.readCfg", "src.beacon", "src.openSocket"} {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CLI.md:838
59903  api, web, mobile            57m 12s      42  http://127.0.0.1:56730 (shared)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CLI.md:839
60122  auth-service                12m 04s       8  http://127.0.0.1:56744
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CLI.md:906
**One bookmarkable URL.** Besides its own port, every server competes for a fixed **shared URL**, `http://127.0.0.1:7171` by default. The first to start wins it; when that one exits another takes over
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/DASHBOARD.md:163
`http://127.0.0.1:7171`. The first process owns it; another can take over after that
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
internal/metrics/delta_test.go:45
t.Errorf("moved ΔD = %v, want -0.267", r.DeltaD())
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
internal/metrics/delta_test.go:79
t.Fatalf("zone change must rank before a larger ΔD without one: %+v", rows)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
internal/engine/testdata/repos/graphql_multirepo/client/package.json
graphql-tag
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
internal/engine/testdata/repos/py_grpc_multirepo/client/requirements.txt
grpcio
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
internal/engine/testdata/repos/py_grpc_multirepo/server/requirements.txt
grpcio, grpcio-tools
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
internal/engine/testdata/repos/python_flask_sample/requirements.txt
Flask, Flask-AppBuilder
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
internal/engine/testdata/repos/ts_ember_sample/package.json
ember-source, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
ARCHITECTURE.md:222
Agent tooling starts one MCP server per session, so several run concurrently — different repos, sometimes the same repo, both binaries — and they all share `~/.enola`. Two mechanisms keep that from tu
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
ARCHITECTURE.md:743
**Pi is the exception that still gets a local file,** because Pi has no MCP client: an instruction naming enola's tools would name tools Pi cannot call. [`pkg/install/pi_extension.js`](pkg/install/pi_
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
ARCHITECTURE.md:755
The first two rules were in place from the start; the third was learned from [#288](https://github.com/enola-labs/enola/issues/288), where a comment in `hook.go` asserted that `additionalContext` hand
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
ARCHITECTURE.md:775
**Sessions share a repository's `.enola`.** Each run writes `run.json` beside the artifacts (rotated into `previous/` with them) and each pin writes `baseline/pin.json`: the agent session behind it an
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 250554a33411full audit observations/trust-audit/mcp-server/enola-labs__enola-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07250554a33411CAUTIONB82first audit
06

Questions

What is the Enola MCP server?

Understand, analyze, and govern software systems across repositories, languages, and technologies.

What tools does Enola expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Enola safe to connect to an agent?

With care. The audit graded it B (82/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Enola need?

No credential environment variables were found in its source, so it appears to need none.

How does Enola run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as ts-sample at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (250554a33411), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement