
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
imi-sight-mcp
Advanced tools
This repository exposes the Sight CLI complexity analysis as an MCP server so LLM clients can request metrics without shell access.
http://npm.imile-inc.com/) so npm install can download @imd/sight-cliThe MCP server bundles @imd/sight-cli as a production dependency. After installation the executable is available at node_modules/.bin/sight; override SIGHT_BINARY only if you need a custom build.
npm installnpm run buildnpm startDuring development you can run npm run dev to execute the TypeScript entry point via tsx.
Configuration is provided via environment variables:
| Variable | Default | Description |
|---|---|---|
SIGHT_BINARY | bundled node_modules/.bin/sight if present, otherwise sight | Absolute path or executable name of the CLI |
SIGHT_WORKDIR | current working directory | Directory passed to the CLI |
SIGHT_DEFAULT_ARGS | --output json | Extra default arguments (space separated or JSON array) |
SIGHT_ALLOWED_FLAGS | (see below) | Comma-separated whitelist for Sight CLI flags to guard against typos |
SIGHT_TIMEOUT_MS | 60000 | Timeout for the CLI invocation |
sight-complexitytarget (string, required): analysis target passed to sight complexityargs (string[], optional): additional Sight CLI flags that must be present in the allow listincludeRawReport (boolean): include raw JSON in the text responsetimeoutMs (number): override configured timeoutnpm test
Unit tests mock the Sight CLI process to cover success, validation failures, missing binary, non-zero exit codes, and timeouts.
-o, --output, --output-file, -i, --include, -e, --exclude, -j, --concurrency, -t, --threshold, --min-complexity, --filter, --min-file, --top-files, --top-functions, -c, --config, --no-config, --jsx-analysis, --jsx-props-in-cognitive, --fast-mode, --memory-limit, --timeout, --max-file-size, --skip-minified-js, --no-color, --include-details, --pretty, --respect-gitignore, --use-global-gitignore, --algorithms, --progress, --tui, --json-view, --view-output-file, --events, --events-file. Update SIGHT_ALLOWED_FLAGS to permit additional switches if the CLI evolves.FAQs
Model Context Protocol server exposing Sight CLI complexity analysis
We found that imi-sight-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.