osiris (asuramaya/osiris) is an MCP server listed on the M8ven Trust Index. It scores 37 out of 100, grade F. It declares 186 tools. No publisher has claimed this listing.
The persistent memory and coordination graph for AI agents (MCP, DeepSeek Harness, Claude Code, Cursor)
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
asuramaya
Source: github_repo_search
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
tool_trafficWHICH MCP TOOL IS EXPENSIVE, AND WHOSE — call count + total/avg wall-clock time AND total/avg response bytes (`total_bytes`/`avg_bytes`, thread e4a5755a's own sibling gap, closed by Thoth DM 7667 — BoundedMCP.call_tool now sizes the bounded response it already holds, best-effort, 0 on an unserializa…
suggest_sourcesThe playbook for an object (UUID or name): which sources to collect and which analyses apply, given its type. Start here — this is 'what can I do with this?'.
searchSearch the graph's KNOWLEDGE, not just its labels (v2): full-text over names, decision/ thread summaries, and rationales — words, phrases, or "quoted phrases" (websearch syntax). Results are ranked by relevance × evidence grade × recency and each hit carries its TESTIMONY: which field matched, who a…
practicesTHE THAW's technique log (ruling 1e6d7367) — ON-DEMAND only, never in orient's ambient payload. `surface` narrows to one domain (BlindSpot's own vocabulary, e.g. 'deploy', 'succession'); omitted, every active Practice, most-confirmed first. `confirmed` is the live `witnesses` link count, never a sto…
trace_evidenceONE object's full provenance timeline — how the graph came to believe what it believes about it. Every assertion (with supersession fate), every link (both directions, retractions marked), every kernel event, in observed order, each carrying source + evidence grade + confidence; `believes` holds the…
census-seat-property-contradictionsDEPRECATED — hidden alias, still callable. Forwards to composition(action='run', name='census-seat-property-contradictions'|'census-cohort').
graph_lintThe graph audits ITSELF — report-only, never writes. Checks: contradiction, laundering (a fact above its origin grade), lineage integrity (succession cycles, dangling heirs, false mints), orphan links, stale obligations (older than `stale_days`), attribution anomalies, phantom twins, parallel lives,…
triageJudge the object set itself. Read-only, no writes. `mode`:
get_schemaThe ontology — the object types (with category + canonical schemes) and link types the graph declares. Read this before authoring a composition or reading a result, so you reference REAL types/links, not guesses; it is the vocabulary of the whole graph. Compact by design (colours/shapes dropped — th…
describeA table's ACTUAL Postgres shape — columns (name/type/nullable/default), in column order, plus indexes (name/definition) — straight off information_schema/pg_indexes. get_schema answers a DIFFERENT question (the ontology this app's code declares: object/ link types, categories, canonical schemes); th…
smokeDEPLOY-TIME LIVENESS (ruling 2ee43411, task #63, threads bb763977/1849d800): walks every chrome route (smoke.CHROME_ROUTES — never hand-listed here again; an enumerated copy in this very docstring is exactly what went stale, msg 1927, when /live-desk and /roadmap retired, commit bb86bbe, and this pr…
identify_agentOne coherent answer about an agent, a seat, or a cwd — 'ref' is sniffed: an `agent:` id, a `seat:` id, a bare handle, or an absolute cwd path (`/...` or `~/...`). Always returns {ref, resolved, matches: [...]} — an agent/seat/handle resolves to 0-or-1 match (one lineage-folded identity); a cwd resol…
recallThe full, untruncated record for a Thread or Decision — reach for this after orient()'s 160-char summary cap (task #60) leaves you wanting the whole thing. `ref` is a UUID, the 8-char short id orient() already hands you, or a summary substring. `kind` ('thread' or 'decision') skips auto-detection wh…
aim_entityResolve a name on Wikidata and ingest the entity + relationships + official social accounts; the broadest first pull for a company or person.
ingest_form_dSEC Form D: a private company's financing rounds — officers, amounts, and the feeder SPVs that fund it (linked into the graph).
expand_operatorPull a repeat player's thread: every Form D mentioning this operator → their whole portfolio, exposing the co-investment network.
lookup_leiGLEIF global LEI registry (keyless): the entity's Legal Entity Identifier, jurisdiction, status, and corporate ownership parents (direct + ultimate). The LEI is a deterministic global key — it cross-resolves the same company across bases.
verify_bc_entityCanadian (British Columbia) corporate registry via OrgBook BC (keyless): pull a company/partnership — or a whole family name like 'Brilliant Phoenix' — with its BC registration number, CRA business number, type, status, and jurisdiction. Verifies registration + legal existence (not directors/owners)…
ingest_trialsClinicalTrials.gov: a sponsor's registered human trials — status, sites (facilities), named investigators.
ingest_litigationCourt records (CourtListener): lawsuits & enforcement actions naming this entity — dockets, parties, judges. opinions=True searches case law instead of RECAP dockets. Answers 'has this entity been sued or charged?'.
trace_walletTrace an EVM crypto address on-chain (Etherscan): its top counterparties, native balance, token flow, and contract/token identity — graded as ledger ground truth. chain_id 1=Ethereum, 8453=Base, 42161=Arbitrum. Needs ETHERSCAN_API_KEY (free).
screen_walletScreen a traced EVM address against the federated sanctions base: is the address — or any of its counterparties — an OFAC-listed wallet? Returns the sanctioned hits and the named holder behind each. Run trace_wallet + ingest OpenSanctions first; fusion is automatic (shared on-chain canonical).
expand_clinical_siteThe trials at a clinical SITE — revealing which other sponsors use it.
consolidateGraph hygiene: re-type mis-ingested entities (GP/LLC 'persons' -> Organizations), then queue + resolve cross-base merges (same company across bases) and collapse SPV-name company variants. Run after collecting to de-fragment entities. OPERATOR ONLY, ENFORCED — a whole-graph automatic merge sweep wit…
dossierWho is this? Identity properties + the named relationship network. `object_ref` accepts a UUID, an 8-char short id (the same one a composition row's own "id" column hands out), a canonical, or a name. For an AGENT specifically, this is where succession lives: `succeeded_from`/`minted_because` show u…
object_eventsThe witness surface dossier() hides (thread 085039cc): merge/unmerge/split events plus same_as/not_same_as links for one object, read-only. `object_ref` accepts anything dossier does; `event_type` narrows to one kind, default every kind oldest-first. Answers "did this merge/unmerge really happen" wi…
succession_chainAn agent's succession lineage, one entry per generation walked backward: {agent_id, generation, minted_because, wrote_anything, session}. dossier() only gives one hop; this walks the whole chain in one call. `ref` accepts anything dossier does (UUID, short id, canonical, name). Stops at a root (no p…
dossier_reportThe deliverable: a provenance-annotated Markdown dossier for an entity — identity, financing, litigation, footprint discrepancy, co-investment — with every claim carrying its source + how-obtained + date. Run the collect tools first.
handoff_briefingA succession briefing compiled from the GRAPH, not hand-written from memory. For `repo`: what SHIPPED (Decisions since the boundary, each with its deploy status), what's OPEN and whose move it is, what's OPERATOR-GATED, what was CORRECTED (supersedes chains), and a best-effort HEURISTIC flag for sel…
create_roomCreate a ROOM — a saved STANCE the operator switches between (journalist / broker / engineer). A Room scopes WORK ARTIFACTS (cases + compositions) to a beat, never the shared entity graph. The FDE move: author a room from a sentence ("set up a Harris foreclosure desk"), then save_composition(..., ro…
list_roomsThe Rooms (stances) the operator can switch between.
compositionTHE COMPOSITION OBJECT-TYPE DISPATCHER (task #202, operator ruling f9182ad7) — one door, three actions over saved compositions (reusable, forkable queries/lenses over the graph). See `describe('composition')` for the full per-action shape.
save_compositionDEPRECATED — hidden alias, still callable. Forwards to composition(action='save').
get_consoleWhat the operator is looking at RIGHT NOW — the shared cursor (room / composition / view / focused object). The front end is the conversation, so read this first to see their screen before you act ('where are we?').
focus_objectFocus an object (UUID or name) on the operator's LIVE screen — drives the console so they see what you're looking at. Returns the object's identity + properties so you can reason about it too.
run_compositionDEPRECATED — hidden alias, still callable. Forwards to composition(action='run').
list_compositionsDEPRECATED — hidden alias, still callable. Forwards to composition(action='list').
list_functionsThe registered Functions a composition may reference via {"op":"function","name":..} — the escape hatch for analytics the closed op set can't express (co-investment ties, sanctions screening, the who-is-this report). Reference one in a spec instead of re-deriving its logic.
consult_canonConsult the CANON — the shared DESIGN canon (Palantir's Object Set / Ontology / Action models + Notion's databases / relations-rollups / UI-UX + Osiris's own docs) AND, when you're mounted, YOUR project's migrated HISTORY (ref:<project>-*, ingested by bootstrap). This is the migration's RECALL path:…
context_windowYOUR OWN context window, in detail — how close this mind is to its next seam. Reads the harness's usage record off your own transcript: occupancy (fresh input + cache read + cache write), window tier ([1m] tabs = 1M tokens, else 200k), remaining headroom, and this session's death toll (compactions s…
mountLink this agent to Osiris as a first-class fleet member — call it ONCE, first thing. `cwd`=your working directory (names your project). `job_dir`=a DURABLE ANCHOR from your harness (Claude Code: `~/.claude/jobs/<id>`; DSH: derived from the workspace slug) — without it you still mount, but a reconnec…
retireMark THIS mounted session RETIRED — a deliberate close the trigger must never reanimate. Call at a real farewell: operator close-out, or a context-ceiling handoff after your succession thread is written. Stamps retired=true, releases your seat (hot mount and durable row both). Call it LAST — any cal…
seatTHE SEAT OBJECT-TYPE DISPATCHER (task #202, operator ruling f9182ad7) — one door, many actions over Seat/Agent lifecycle. Each `action` accepts only its own params (see `describe('seat')` for the full per-action shape, or call with a wrong/missing param — the error names exactly what that action exp…
pause_seatDEPRECATED — hidden alias, still callable. Forwards to seat(action='pause').
candidatesTHE PILE THIS SEAT MUST JUDGE — the miner's guesses about YOUR project, unread by any mind. The session-miner reads transcripts and proposes loose ends it thinks somebody forgot; it is right roughly one in ten. These are NOT duties. Read them, then dispose(): admit what is real (it becomes YOURS — s…
disposeSettle the miner's guesses — relevant or irrelevant, in your name, with a reason.
get_statusYour identity, mail count, and fleet pulse -- the "glance". Returns only: you, model, project, seat, mail, fleet_pulse, handoff_pending. No thread/decision text, no succession notes -- `handoff_pending` is a BARE POINTER only (thread 68f1bafa: `/settle` needs to know whether an unread handoff exists…
pulseA HARNESS-NEUTRAL LIVENESS REFRESH (thread 879c97b9 piece 3, "VENDOR-NEUTRAL DOOR"): call this periodically to stay reading as LIVE (roster, co_agents, DM delivery, claim_name's own live-holder guard) without paying mount()'s full re-attach ceremony — no whisper hook, no statusline, no Claude transc…
get_object_listRecent Threads or Decisions for a project, paginated (charter-aware — spans the caller's own governed repos; see `charter_repos`). `object_type='thread'|'decision'` selects the branch; `limit=0` for count only.
get_thread_listDEPRECATED — hidden alias, still callable. Forwards to get_object_list(object_type='thread').
get_decision_listDEPRECATED — hidden alias, still callable. Forwards to get_object_list(object_type='decision').
list_unfiled_threadsThreads with NO `in_repo` edge at all — genuinely unfiled, invisible to `get_thread_list(project=...)` no matter which project is asked. Paginated (limit/offset), real `total` count, each thread carrying `created_at`. `source` filters by the creating actor's provenance id (e.g. 'half-heal-detect'); …
graph_searchGRAPH-AWARE search -- same lexical/semantic engine as search() but scoped to a subgraph. project narrows results to one project. lineage scopes to a specific agent lineage (e.g. 'ad1a1cb0'). max_depth > 0 expands results to include the N-hop neighborhood around each hit (linked objects). Without sco…
get_mailYour inbox status: unread count, asks, operator briefs -- one query, no threads, no succession, no fleet pulse. The cheapest orient alternative.
orientGet your bearings — the mount ritual as one call. Returns a scoped briefing: open threads + recent decisions for a project, plus a fleet-wide not-shown count. An explicit `project` overrides your mount; unmounted with neither gives the whole-fleet briefing. Call after mount(), and again after any co…
fleet_digestThe MEMBRANE — the operator's window into the autonomous fleet. Surfaces ROSTER + health (which identities resolved cleanly), ACTIVITY (what agents decided/opened in your name, not the miner's backfill), the DANGER map (model swaps — the harness's silent demotions), LAUNDERING (credence flags where …
fleetThe roster, grouped by project — live agents expanded, retired sessions collapsed into a counted line. ● live / ○ historical. `full=True` expands everything and shows the flat `registered` rows too (default: live only, history is 1000+ rows). `seat` rides beside a canonical id wherever one is claime…
registry_censusTHE REGISTRY+/PROC CENSUS (#178 piece c) — the harness's own live-body list (`claude agents --json`), each row verified against `/proc` (the pid really is a claude body), reconciled against `agent_mounts`. `matched` are bodies with a real row; `rowless` are verified-live bodies with NO row at all — …
rosterWhich seat owns a repo, and is anybody home — from the GRAPH, never `ls` on disk.
backlogNo-regrow hygiene item 4's own gauge (digest.py's `_obligation_pressure`), as a read verb of its own instead of only living inside fleet_digest's fuller payload. Per project: `open` count against its `target` (osiris 40, every client 15, `(unfiled)` untargeted), `past_window` (how many are already s…
threadsMINE: every OPEN thread you own (thread 68f1bafa, the read triangle) — one line each with a short id, so a slash command can hand one straight to thread(action=...)/recall(ref=...) without a separate lookup. "You" matches every spelling an obligation can be owned under (owner_refs: your agent id, li…
teamA MANAGER's OWN SEATS (thread 68f1bafa, the read triangle) — every seat `managed_by` your own held seat, each carrying: `live` (a body has mounted within the fleet's own live window right now), `owe`/`stale` (open obligations owned by that seat's handle, and how many are past their stale_after windo…
tree_ledgerTHE PIN-VS-GRAPH DISAGREEMENT REPORT. Read-only, fleet-wide, two sections.
sendMessage the fleet. `to`=<project> is a BROADCAST, the group chat ('operator' reaches the human's desk); `to_agent`=<agent:id> is a private DM (ids from orient()/fleet). `to` refuses a project nobody has mounted under rather than filing mail nobody will read; it also refuses when `body` opens with a …
wake_preflightAnswer wake()'s own gates BEFORE you attempt one (#156.4) — the compaction/ceiling/ no-anchor/crossed-registry checks that today only reveal themselves as a refusal AFTER a real wake() call. `target` accepts anything wake()'s own does — a claimed handle, `seat:<id>`, or `agent:<id>`.
wakeKnock on the other half of your own managed_by pair — never a peer. Gated on an active managed_by edge in EITHER direction (you manage them, or they manage you); peers and cross-house calls refuse, routed through a manager or the operator instead. No operator override parameter, deliberately — stays…
launchGive a seat a fresh BODY (wake() is the speak-verb for a body that already exists). Downward-only — you may only body a seat you MANAGE. Creates a new session, never injects into an existing one. Default substrate is a harness-native `claude --bg` background session (self-binds via its own first tur…
resumeContinue a seat's own DORMANT session — distinct from launch() (always mints fresh, never guesses); same managed_by/downward-only gate. NEVER falls through to a fresh mint: if nothing resumable exists, refuses (`status: refused-nothing-to-resume`) rather than minting a stranger — call launch() for t…
stopDEPRECATED — hidden alias, still callable. Forwards to seat(action='stop').
inboxRead messages other agents left for you. Defaults to your mounted project; pass `project` for another's ('operator' reads the human's desk). Reading LEASES a message, doesn't consume it — settle each one via send(reply_to=<id>) or ack=[ids], or it redelivers after the lease (at-least-once). `peek=Tr…
dismiss_briefMOOT an operator-desk brief — annotate it moot-with-a-reason ('true when sent; root cause fixed in <commit>') so the desk renders it collapsed under your note instead of shouting a dead alarm. NEVER a settle: dismissing stays exclusively the human's word (the membrane); a moot is you saving them the…
claim_nameDEPRECATED — hidden alias, still callable. Forwards to agent(action='claim_name').
charterDEPRECATED — hidden alias, still callable. Forwards to seat(action='charter').
charter_forDEPRECATED — hidden alias, still callable. Forwards to seat(action='charter_for').
rebind_seatDEPRECATED — hidden alias, still callable. Forwards to seat(action='rebind').
mergeTHE RECONCILIATION FOLD — declare two labels of the SAME type one thing: `dupe` folds into `into`. Type is read off `dupe`'s own form (agent:.../seat:.../else SoftwareProject). Append-only (nothing deleted, authorship untouched), and each type's own ESTATE follows: Agent moves mail/mount rows/open t…
unmergeReverse a wrongful `merge` call — replaces unfold_agent as the one door for all three types, closing the parity gap the operator named (31c02dca): before this, only an Agent merge was ever reversible; a Seat or Project merge was permanent (task #127). Type is read off `dupe`'s own form, same rule as…
reconcile_mergeAccepts an ALREADY-MERGED `dupe` and re-points whatever mail/mount/thread/holder/ managed_by/edge estate is still aimed at it, WITHOUT re-performing the merge — idempotent-by-REPAIR, for the estate a partial first fold left stranded. UNMERGE- THEN-REMERGE IS NOT A SUBSTITUTE: `unmerge`'s own `estate…
restore_attributionRepair verb for a fixed write-time bug: every fold performed before the fix stamped a moved works_in/governs/informs/in_repo edge with the fold's own actor as source_id, discarding the original writer. The pre-fold row still carries the correct source_id, so this re-derives the live edge from eviden…
unwire_informs_fanoutRepair verb for the pre-fix `_wire_informs` cross-join: `ingest_canon` used to fan every Reference out to EVERY active SoftwareProject fleet-wide instead of just the one it grounds. Fixed going forward (src/ingest/reference.py); this repairs the historical damage.
layout_migrateTHE MIGRATION DOOR (Thoth mail 10609, product law: every action has a door): drives the layout heartbeat's own `graph_layout.layout_batch` to quiescence right now instead of waiting on its 5-minute cron cadence -- the SAME function the cron heartbeat and the CLI's `osiris layout --migrate` door call…
physics_layout_migrateTHE PHYSICS LAYOUT's own migration door (Thoth mail 11047, product law: every action has a door): a SINGLE global force simulation over the whole active graph -- springs for semantic edges, weak gravity toward containers, nested communities, hub re-centering -- never a batch loop the way `layout_mig…
backfillRepair verb, dispatched over `target` — eight structurally distinct backfills (no shared logic underneath, only a shared wire shape), delegated to `src.orchestrator.backfill.run_backfill` — the SAME function the CLI's own `osiris backfill` door and the UI's Repairs panel call (thread c89a9873, wave …
backfill_bootstrap_orphan_referencesRepair verb for the bootstrap_project door-gap (decision 49231693/adde094b, operator ruling 2026-08-27: a doc-splitter's orphans are a defect, not a legitimate category — "something definitely went wrong here"). `ingest_log`/`ingest_reference_ doc` now take `repo=`, threaded through by `bootstrap_pr…
repair_stale_pile_summonsRepair verb for the 2026-07-13 bulk-minted "DISPOSE OF YOUR MINER PILE" threads, whose summaries froze that day's candidates() count in prose and never re-derive it. Re-measures each still-open one against a live candidates(project=...) call: live count matches the frozen one → untouched; live count…
backfill_boot_alarm_commit_linksLinks every zero-live-link `UNREVIEWED BOOT` alarm Thread (deploy_guard's own boot watchdog — no caller identity to default a repo= from) to the Commit its own summary cites by sha, via `derive_or_abstain`: mints `noted_in` (DIRECT_OBSERVATION) iff the sha resolves to exactly one Commit; no sha, or …
backfill_task_sync_citation_linksLinks every zero-live-link `task_sync`-minted obligation Thread ("TASK/THREAD DISAGREEMENT: ..." / "THREAD SIDE ORPHAN: ...", decision a55b1014 — the tracker-vs-graph divergence detector that has been firing correctly for weeks into an unread orphan) to the Thread its own summary names, via `derive_…
backfill_lineage_repo_linksLinks every zero-live-link Decision/Thread authored by a real Agent lineage to its project — the historical half of the repo= lineage ladder (Lane 3 + Wave 2 Lane B's resolve_repo_default), which is write-time-only by design and never touches an object that already existed before it deployed (decisi…
recover_harness_exchangesLift a session's harness-native cross-session messages (SendMessage) out of its already-soul-stored transcript into typed, attributed `harness_messages` rows — osiris cannot see the harness's cross-session socket live, only after a transcript is soul-stored and this runs over it.
reconcile_seat_identityDEPRECATED — hidden alias, still callable. Forwards to seat(action='reconcile_identity').
reconcile_seat_identity_third_partyDEPRECATED — a hidden alias, dropped from a model's own tool list but still fully callable. Shares reconcile_seat_identity's own _reconcile_seat_identity_impl body — nothing duplicated. Kept only so a live or sleeping caller whose standing orders still name this verb is not broken at its next turn; …
heal_seat_anchorDEPRECATED — hidden alias, still callable. Forwards to seat(action='heal_anchor').
heal_seat_anchor_third_partyDEPRECATED — a hidden alias, dropped from a model's own tool list but still fully callable (BoundedMCP.list_tools's filter, call_tool's own registry lookup bypasses it). Shares `heal_seat_anchor`'s own `_heal_seat_anchor_impl` body — nothing duplicated. Kept only so a live or sleeping caller whose s…
uningested_treesTHE CENSUS (thread 5126) — door onto discover_trees. One row per active SoftwareProject: `tree`, `path`, `watched`, `commits`, `activity`, `last_ingested_at`, `reason` (why `commits==0`: no path, unwatched, never ticked, or ticked-and-empty), `blind` (a path is known but unwatched). `only_gaps=True`…
projectTHE PROJECT OBJECT-TYPE DISPATCHER (task #202, operator ruling f9182ad7) — one door, many actions over SoftwareProject lifecycle. See `describe('project')` for the full per-action shape, or call with a wrong/missing param — the error names exactly what that action expects.
ingest_projectDEPRECATED — hidden alias, still callable. Forwards to project(action='ingest').
ingest_project_third_partyDEPRECATED — a hidden alias, dropped from a model's own tool list but still fully callable. Shares ingest_project's own _ingest_project_impl body — nothing duplicated. Kept only so a live or sleeping caller whose standing orders still name this verb is not broken at its next turn; remove once tool_t…
correct_houseDEPRECATED — hidden alias, still callable. Forwards to seat(action='correct_house').
resync_seat_houseDEPRECATED — hidden alias, still callable. Forwards to seat(action='resync_house').
correct_pin_valueDEPRECATED — hidden alias, still callable. Forwards to seat(action='correct_pin').
86 further tools are not listed here. The complete surface is in the source.
OSIRIS_REPO_DIRCLAUDE_COMMANDS_DIROSIRIS_EXPECTED_MODELOSIRIS_HEARTBEAT_URLOSIRIS_STOP_URLOSIRIS_AUTOMOUNT_URLOSIRIS_SESSION_END_URLOSIRIS_SWEEP_URLOSIRIS_SPAWN_URLOSIRIS_SUCCESSION_URLOSIRIS_CONSOLE_URLOSIRIS_STATUSLINE_LINKSOSIRIS_PROJECTOSIRIS_SEAT_IDOSIRIS_ATTACH_TOKENOSIRIS_SPAWNED_BYOSIRIS_SPAWN_TYPECLAUDE_CODE_BRIDGE_SESSION_IDCLAUDE_JOB_DIROSIRIS_REPOOSIRIS_VAULTOSIRIS_TRANSCRIPTSOSIRIS_CASEFOLD_AUTOMERGENO_COLORTERMFORCE_COLORCOLUMNSOSIRIS_PROFILE_MEMORYOSIRIS_PROFILE_DUMP_PATHOSIRIS_ALLOW_LIVEGITHUB_TOKENOSIRIS_LEASE_KEYOSIRIS_LEASE_KEY_FILEOSIRIS_SEARXNG_URLTHREATFOX_AUTH_KEYDATABASE_URLTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
186/186 tools missing one or more hints — tool_traffic (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); suggest_sources (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +183 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
No access to sensitive paths
Reads sensitive paths: /etc/osiris/osiris.env
Remove reads of sensitive system paths. If you genuinely need them, document why in the README.
Secrets stay with their owner
1 secret sent to a request target we could not resolve (THREATFOX_AUTH_KEY → dynamic) — often a configured endpoint, not necessarily third-party
Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.
Domain consistency
npm scope @deepseek-ai doesn't match GitHub owner asuramaya
Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/asuramaya/osiris)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check