Atlas / MCP servers / hive-academy / Anubis

AnubisCAUTION

mcp/hive-academy/anubis
Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
16 11r · 5w · 0d
Transport
streamable-http
License
MIT
Stars
125
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Transform your AI agent from chaotic coder to intelligent workflow orchestrator with three powerful capabilities:

Three Pillars of Intelligent Workflow Management

Intelligent Guidance | Seamless Transitions | Repository Pattern Architecture

[](https://github.com/hive-academy/anubis) [](https://github.com/hive-academy/anubis) [](https://github.com/hive-academy/anubis)

[](https://hub.docker.com/r/hiveacademy/anubis)

[NPM Package](https://www.npmjs.com/package/@hive-academy/anubis) • [Docker Hub](https://hub.docker.com/r/hiveacademy/anubis) • [Website](https://hive-academy.github.io/Anubis-MCP/)

QUICK START

Option 1: NPX (Recommended)

Add to your MCP client config
{
"mcpServers": {
"anubis": {
"command": "npx",
"args": ["-y", "@hive-academy/anubis"],
"env": {
"PROJECT_ROOT": "C:\\path\\to\\projects"
}
}
}
}

Option 2: Docker (MCP Configuration)

For Unix/Linux/macOS (mcp.json):

{
"mcpServe
Read from source at commit 2990f578d1e0OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add anubis -- npx -y @hive-academy/[email protected]
claude-desktop
{
  "mcpServers": {
    "anubis": {
      "command": "npx",
      "args": [
        "-y",
        "@hive-academy/[email protected]"
      ]
    }
  }
}
03

Exposed tools (16)

11 read · 5 write · 0 destructive.

ToolRiskDescription
architectreadArchitect role
bootstrap_workflowreadInitializes a new workflow execution with product-manager role, starting from git setup through task creation and delegation.
execute_research_operationwriteExecute research operations including create, update, get, and list operations for research reports
execute_review_operationwriteExecute review operations including create, update, get for code reviews and completion reports
execute_transitionwriteExecutes role transition and returns execution status with essential details for next steps.
get_role_transitionsreadGets available role transitions with recommendations, scores, and basic requirements for workflow progression.
get_step_guidancereadProvides focused guidance for executing the current workflow step, including commands and validation checklist.
get_step_progressreadGet concise step progress focused on essential status information for workflow continuation.
get_workflow_guidancereadProvides minimal role identity and basic capabilities for workflow execution.
individual_subtask_operationswriteExecute individual subtask operations including creation, updates, dependency tracking, and batch management with evidence collection
init_rulesreadInitialize Anubis workflow rules to specified AI agent (cursor or copilot)
product-managerreadTest role
report_step_completionreadReport step completion results with structured data and get next step guidance.
task_operationswriteExecute task lifecycle operations (create, update, get, list) with comprehensive task management capabilities.
validate_transitionreadValidates role transition requirements and provides pass/fail status with actionable feedback.
workflow_execution_operationsreadManages workflow execution state through strongly-typed operations for creating, querying, updating, and completing workflow executions. Handles execution context and progress tracking with validated parameters.
04

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (2 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (12)

MEDIUMInventory / provenance · inv.binary · CWE-1104
prisma/.anubis/workflow.db
workflow.db
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/files/DOCKER_PUBLISH_GUIDE.md:220
- DATABASE_URL=postgresql://workflow:secure_password@postgres:5432/workflow_db
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.hidden_file · CWE-1104
.kilocodemodes
.kilocodemodes
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.lintstagedrc.json
.lintstagedrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.roomodes
.roomodes
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domains/task-management/repositories/implementations/code-review.repository.ts:2
import { CodeReview, Prisma } from '../../../../../generated/prisma';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domains/task-management/repositories/implementations/code-review.repository.ts:3
import { PrismaService } from '../../../../prisma/prisma.service';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domains/task-management/repositories/implementations/completion-report.repository.ts:2
import { CompletionReport, Prisma } from '../../../../../generated/prisma';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domains/task-management/repositories/implementations/completion-report.repository.ts:3
import { PrismaService } from '../../../../prisma/prisma.service';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/domains/task-management/repositories/implementations/delegation-record.repository.ts:2
import { DelegationRecord, Prisma } from '../../../../../generated/prisma';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @nestjs/common, @nestjs/config, @nestjs/core, @nestjs/platform-express, @prisma/adapter-better-sqlite3, @prisma/client, @rekog/mcp-nest
Why it matters. 54 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 2990f578d1e0full audit observations/trust-audit/mcp-server/hive-academy__anubis.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-072990f578d1e0CAUTIONB82first audit
06

Questions

What tools does Anubis expose?

16 in total: 11 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Anubis safe to connect to an agent?

With care. The audit graded it B (82/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Anubis need?

No credential environment variables were found in its source, so it appears to need none.

How does Anubis run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @hive-academy/anubis at 1.2.26.

How current is this page?

The grade is for one exact copy of the source (2990f578d1e0), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement