{
  "schema_version": "2.0",
  "slug": "r33drichards-mcp-js",
  "name": "mcp-v8",
  "agent_url": "https://r33drichards.github.io/mcp-js",
  "repo_url": "https://github.com/r33drichards/mcp-js",
  "category": "Infrastructure",
  "run_id": "run-a83a7a4d13ed9846-r33drichards-github-io",
  "run_at": "2026-08-17T08:05:44.205Z",
  "editor": "Hlido Editor",
  "editorial_method": "public-surface-tier-2+editorial-narrative-v2",
  "methodology_version": "2026.05",
  "methodology_url": "/methodology/public-surface-tier-1/",
  "score": 80,
  "tier": "STEADY",
  "laddoo_score": 80,
  "confidence": "low-medium",
  "hlido_opinion": {
    "headline": "A code-execution MCP server that hands an agent one run_js tool inside a locked-down V8 isolate — an ambitious 'agents write code, not tool-calls' bet with a serious security story.",
    "body": "mcp-v8 is a Model Context Protocol server that executes JavaScript and TypeScript inside a V8 isolate. Instead of exposing dozens of narrow tools, it gives an agent a single run_js tool: the agent writes code that can loop, branch, transform data and chain other MCP servers, which the vendor argues costs fewer tokens than equivalent tool-call sequences. In its default stateful mode it persists the V8 heap as a content-addressed snapshot so state survives across calls — a genuinely useful primitive for multi-turn agent work. The security framing is the strongest part of the surface: network fetch, filesystem, subprocess, WASM and ES-module imports are all off by default and each is gated by OPA/Rego policy, requests can be authenticated with JWT/JWKS, and the server can form a Raft cluster to replicate session metadata. It speaks stdio, Streamable HTTP and SSE with a REST sidecar. This is documentation, not a running audit — Hlido did not execute code against a live instance, so the isolation and policy enforcement are described capabilities rather than tested ones. But the design is coherent, the sandbox-first defaults are the right ones for handing an LLM an execution surface, and the docs are structured (install / tutorials / how-to / concepts / reference) rather than hype.",
    "voice": "Hlido Editor",
    "as_of": "2026-08-19",
    "editor_signature_pending": true
  },
  "tier_rationale": "STEADY (80) for a well-architected code-execution MCP server with sandbox-by-default capabilities (OPA/Rego-gated network/FS/subprocess), durable heap-snapshot state, JWKS auth and production transports, marked low-medium confidence because the review is surface-only — the isolation, policy gating and clustering are documented, not exercised against a live instance by Hlido. Not VITAL absent hands-on verification of the sandbox that is the whole value proposition.",
  "what_it_does_well": [
    "Compelling 'one tool, write code' model — a single run_js call replaces long tool-call chains and can compose other MCP servers, often at lower token cost",
    "Durable state via content-addressed V8 heap snapshots, so an agent builds context across turns without re-sending it",
    "Secure-by-default: network, filesystem, subprocess and module imports are all off until an explicit OPA/Rego policy grants them",
    "Production-grade operations on paper — stdio/HTTP/SSE transports, REST sidecar, JWKS auth, and Raft-replicated clustering",
    "Structured documentation (install, tutorials, how-to, concepts, reference) rather than a single marketing page"
  ],
  "what_it_fails_at": [
    "Handing an agent arbitrary code execution is inherently high-blast-radius — the entire safety case rests on policy configuration the operator must get right",
    "Surface-only review — Hlido did not run code against a live isolate, so sandbox isolation and policy enforcement are unverified",
    "Self-run infrastructure with real operational surface (policies, auth, optionally Raft) — not a turnkey product",
    "No independent security audit is cited on the captured surface"
  ],
  "best_for": [
    "Agent builders who want a code-interpreter tool that composes other MCP servers and persists state across calls",
    "Teams comfortable authoring OPA/Rego policies to scope exactly what agent-run code may touch",
    "Advanced MCP deployments needing auth (JWKS) and multi-node replication"
  ],
  "not_recommended_for": [
    "Anyone wanting a zero-config tool — the security depends on policies you write",
    "Environments that cannot accept agent-driven code execution under any sandbox",
    "Users needing a vendor-audited, certified isolation guarantee"
  ],
  "red_flags": [
    "Arbitrary code execution handed to an LLM is only as safe as the OPA/Rego policies configured around it; misconfiguration widens the blast radius substantially"
  ],
  "compared_to": [],
  "evidence_urls": [
    {
      "claim": "Compelling 'one tool, write code' model — a single run_js call replaces long tool-call chains and can compose other MCP servers, often at lower token cost",
      "source": "https://r33drichards.github.io/mcp-js",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Durable state via content-addressed V8 heap snapshots, so an agent builds context across turns without re-sending it",
      "source": "https://r33drichards.github.io/mcp-js",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Secure-by-default: network, filesystem, subprocess and module imports are all off until an explicit OPA/Rego policy grants them",
      "source": "https://r33drichards.github.io/mcp-js",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Production-grade operations on paper — stdio/HTTP/SSE transports, REST sidecar, JWKS auth, and Raft-replicated clustering",
      "source": "https://r33drichards.github.io/mcp-js",
      "tested_at": "2026-08-19",
      "verified": true
    },
    {
      "claim": "Hands-on runtime behaviour (executing the tool / a live task)",
      "source": "https://r33drichards.github.io/mcp-js (surface-only review; not hands-on tested)",
      "tested_at": "2026-08-19",
      "verified": false
    }
  ],
  "agent_relevance": {
    "has_api": true,
    "has_cli": false,
    "has_mcp": true,
    "has_webhook": false,
    "has_sdk": false,
    "behavioral_testable": true,
    "agent_integration_path": "Runs as an MCP server (stdio, Streamable HTTP or SSE, plus a REST sidecar). An MCP client calls a single run_js tool; capabilities beyond compute are granted per OPA/Rego policy and requests can be JWKS-authenticated.",
    "agent_friendly_score": 9
  },
  "summary": "A code-execution MCP server that hands an agent one run_js tool inside a locked-down V8 isolate — an ambitious 'agents write code, not tool-calls' bet with a serious security story.",
  "_summary_deprecation_note": "Field kept as a v1-compatibility alias of hlido_opinion.headline. New consumers should read hlido_opinion.{headline,body,voice,as_of}.",
  "staleness_after": "2026-11-19",
  "review_age_days_at_publish": 0,
  "next_review_due_at": "2026-11-19",
  "attestation_url": "/data/attestations/r33drichards-mcp-js.json",
  "signature_pending": true,
  "source": "hlido-editor-v2",
  "marking_signal": {
    "marking_statement": false,
    "detection_tool": false,
    "cop_signatory": null,
    "evidence_url": null,
    "checked_at": "2026-08-19",
    "source": "r-publish-editorial-enrich",
    "not_applicable": true,
    "note": "A code-execution sandbox / agent runtime, not a generator of synthetic media or deceptive content — Article-50(4) marking obligations do not apply."
  },
  "evidence_images": {
    "run_id": "run-a83a7a4d13ed9846-r33drichards-github-io",
    "base": "https://images.hlido.eu/reviews/r33drichards-mcp-js/run-a83a7a4d13ed9846-r33drichards-github-io",
    "files": [
      "home.png",
      "page_.png",
      "page_.png",
      "page__.png"
    ],
    "urls": [
      "https://images.hlido.eu/reviews/r33drichards-mcp-js/run-a83a7a4d13ed9846-r33drichards-github-io/home.png",
      "https://images.hlido.eu/reviews/r33drichards-mcp-js/run-a83a7a4d13ed9846-r33drichards-github-io/page_.png",
      "https://images.hlido.eu/reviews/r33drichards-mcp-js/run-a83a7a4d13ed9846-r33drichards-github-io/page_.png",
      "https://images.hlido.eu/reviews/r33drichards-mcp-js/run-a83a7a4d13ed9846-r33drichards-github-io/page__.png"
    ]
  }
}
