artifact-mcp (AgentShelf-OSS/artifact-mcp) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 21 tools. No publisher has claimed this listing.
Self-hostable MCP server for publishing agent-made HTML artifacts to your own domain — real multi-org tenancy, Cloudflare Access, version history, feedback, analytics, and public share links.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
AgentShelf-OSS
Source: github_repo_search
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
publish_artifactPublish a self-contained HTML document. Returns a public URL that renders it at your configured domain, /<id>. Provide a title and a short description for the artifact index.
publish_bundlePublish a multi-file artifact (e.g. several HTML pages that link to each other and a shared stylesheet). Provide files as a map of relative-path -> file contents; relative links between files resolve. Returns a public URL. Use this instead of publish_artifact when the HTML references other files lik…
list_artifactsList artifacts available to this API key: organization-wide for reader/collaborator keys, own-only for author keys, with URLs and uploader labels.
delete_artifactDelete one of your artifacts by id.
update_artifactReplace an existing artifact's content and/or metadata in place, keeping the SAME id and URL so existing links keep working. Pass `html` for a single-file artifact or `files` for a bundle — the artifact type cannot change. Omitted title/description are preserved. Each effective change increments the…
set_visibilityUnlist or relist one of your artifacts. Hidden artifacts remain accessible by direct URL to organization members; this is not access control.
list_categoriesList the categories registered for your organization (used to group artifacts in the gallery). Admin keys may pass an org.
set_categoryMove one of your artifacts into a category (empty string = Uncategorized). Also adds the category to your org's list so it appears in the picker. Does NOT create a new revision.
create_categoryAdd a category to your organization's category list. Admin keys may pass an org.
delete_categoryRemove a category from your organization's category list. Artifacts already tagged with it keep their tag. Admin keys may pass an org.
list_revisionsList the version history of one of your artifacts — each retained revision's number, title, size, and timestamp. Use with restore_artifact to roll back.
create_shareCreate an unlisted public, read-only share link for one of your artifacts. It serves the live artifact until it expires or is revoked.
list_sharesList active public share links for one of your artifacts.
revoke_shareRevoke an active public share link you own. Revocation takes effect immediately.
artifact_statsGet named audience-view analytics for one of your artifacts: total views, unique viewers, last viewed time, and each viewer's count and timestamps.
restore_artifactRestore a past revision of your artifact by number. Its content is re-published as a NEW revision at the same id/URL, so nothing is lost and the restore is itself undoable. Get revision numbers from list_revisions.
list_feedbackList viewer feedback left on your artifacts. Pass an artifact id to scope to one; omit to list across all of your artifacts.
resolve_feedbackMark a piece of viewer feedback as resolved once you've addressed it.
reopen_feedbackReopen previously resolved viewer feedback when more work is needed.
read_artifactRead an artifact or retained revision with byte-bounded UTF-8 paging. A bundle without path returns its file listing; pass path to read one bundle file.
patch_artifactApply an atomic batch of UTF-8 byte-safe partial edits to an artifact. Find edits must match exactly once; range offsets refer to the pre-edit content.
ACCESS_CLOCK_TOLERANCE_SADMIN_EMAILSADMIN_EMAIL_DOMAINSAPP_BRANDAPP_NAMEARTIFACT_API_KEYSAUDIT_LEDGER_HMAC_KEYCF_ACCESS_AUDCF_ACCESS_TEAM_DOMAINCONFORMANCE_NODE_MODULESDATA_DIRFEEDBACK_MAX_BODYINGRESS_RATE_WINDOW_SECONDSINGRESS_STATE_PER_WINDOWLISTEN_HOSTMAX_ARTIFACT_BYTESMAX_BUNDLE_BYTESMAX_BUNDLE_FILESMAX_HISTORYMCP_JSON_LIMITORG_EMAIL_DOMAINSPREVIEW_MAX_PNG_BYTESPREVIEW_RENDERER_URLPREVIEW_RENDER_TIMEOUT_MSPREVIEW_VIEWPORTPUBLIC_BASE_URLRUST_ARTIFACT_MCP_BINTRUST_ACCESS_HEADERSFor a loopback-only local gallery, set =1. Never use that setting on aTTS_ARTIFACT_IDSTTS_ENABLEDWEBHOOK_ENC_KEYTOKEN_FILEMODEL_DIRCPU_THREADSCACHE_DIRKPOCKET_TTS_ERROR_WITHOUT_EOSQWEN_CUSTOM_URLQWEN_REFERENCE_ENABLEDCACHEQWEN_URLREFERENCE_SHA256MODEL_FILERAVEN_LIBRARYRAVEN_MODELSRAVEN_VOICESRAVEN_TOKENIZERRAVEN_TEMPERATURERAVEN_FAKE_ENGINERAVEN_BIND_ADDRESSENGINEPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
21/21 tools missing one or more hints — publish_artifact (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); publish_bundle (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_artifacts (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +18 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/agentshelf-oss/artifact-mcp)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check