osiris (asuramaya/osiris) is an MCP server listed on the M8ven Trust Index. It scores 37 out of 100, grade F. It declares 186 tools. No publisher has claimed this listing.

F
Warning
37/100

osiris

The persistent memory and coordination graph for AI agents (MCP, DeepSeek Harness, Claude Code, Cursor)

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

asuramaya

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: THREATFOX_AUTH_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Reads files from sensitive locations
Touches: /etc/osiris/osiris.env
🔐
You'll be asked for 4 credentials: OSIRIS_ATTACH_TOKEN, GITHUB_TOKEN, OSIRIS_LEASE_KEY, THREATFOX_AUTH_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes186 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

tool_traffic

WHICH MCP TOOL IS EXPENSIVE, AND WHOSE — call count + total/avg wall-clock time AND total/avg response bytes (`total_bytes`/`avg_bytes`, thread e4a5755a's own sibling gap, closed by Thoth DM 7667 — BoundedMCP.call_tool now sizes the bounded response it already holds, best-effort, 0 on an unserializa

suggest_sources

The playbook for an object (UUID or name): which sources to collect and which analyses apply, given its type. Start here — this is 'what can I do with this?'.

search

Search the graph's KNOWLEDGE, not just its labels (v2): full-text over names, decision/ thread summaries, and rationales — words, phrases, or "quoted phrases" (websearch syntax). Results are ranked by relevance × evidence grade × recency and each hit carries its TESTIMONY: which field matched, who a

practices

THE THAW's technique log (ruling 1e6d7367) — ON-DEMAND only, never in orient's ambient payload. `surface` narrows to one domain (BlindSpot's own vocabulary, e.g. 'deploy', 'succession'); omitted, every active Practice, most-confirmed first. `confirmed` is the live `witnesses` link count, never a sto

trace_evidence

ONE object's full provenance timeline — how the graph came to believe what it believes about it. Every assertion (with supersession fate), every link (both directions, retractions marked), every kernel event, in observed order, each carrying source + evidence grade + confidence; `believes` holds the

census-seat-property-contradictions

DEPRECATED — hidden alias, still callable. Forwards to composition(action='run', name='census-seat-property-contradictions'|'census-cohort').

graph_lint

The graph audits ITSELF — report-only, never writes. Checks: contradiction, laundering (a fact above its origin grade), lineage integrity (succession cycles, dangling heirs, false mints), orphan links, stale obligations (older than `stale_days`), attribution anomalies, phantom twins, parallel lives,

triage

Judge the object set itself. Read-only, no writes. `mode`:

get_schema

The ontology — the object types (with category + canonical schemes) and link types the graph declares. Read this before authoring a composition or reading a result, so you reference REAL types/links, not guesses; it is the vocabulary of the whole graph. Compact by design (colours/shapes dropped — th

describe

A table's ACTUAL Postgres shape — columns (name/type/nullable/default), in column order, plus indexes (name/definition) — straight off information_schema/pg_indexes. get_schema answers a DIFFERENT question (the ontology this app's code declares: object/ link types, categories, canonical schemes); th

smoke

DEPLOY-TIME LIVENESS (ruling 2ee43411, task #63, threads bb763977/1849d800): walks every chrome route (smoke.CHROME_ROUTES — never hand-listed here again; an enumerated copy in this very docstring is exactly what went stale, msg 1927, when /live-desk and /roadmap retired, commit bb86bbe, and this pr

identify_agent

One coherent answer about an agent, a seat, or a cwd — 'ref' is sniffed: an `agent:` id, a `seat:` id, a bare handle, or an absolute cwd path (`/...` or `~/...`). Always returns {ref, resolved, matches: [...]} — an agent/seat/handle resolves to 0-or-1 match (one lineage-folded identity); a cwd resol

recall

The full, untruncated record for a Thread or Decision — reach for this after orient()'s 160-char summary cap (task #60) leaves you wanting the whole thing. `ref` is a UUID, the 8-char short id orient() already hands you, or a summary substring. `kind` ('thread' or 'decision') skips auto-detection wh

aim_entity

Resolve a name on Wikidata and ingest the entity + relationships + official social accounts; the broadest first pull for a company or person.

ingest_form_d

SEC Form D: a private company's financing rounds — officers, amounts, and the feeder SPVs that fund it (linked into the graph).

expand_operator

Pull a repeat player's thread: every Form D mentioning this operator → their whole portfolio, exposing the co-investment network.

lookup_lei

GLEIF global LEI registry (keyless): the entity's Legal Entity Identifier, jurisdiction, status, and corporate ownership parents (direct + ultimate). The LEI is a deterministic global key — it cross-resolves the same company across bases.

verify_bc_entity

Canadian (British Columbia) corporate registry via OrgBook BC (keyless): pull a company/partnership — or a whole family name like 'Brilliant Phoenix' — with its BC registration number, CRA business number, type, status, and jurisdiction. Verifies registration + legal existence (not directors/owners)

ingest_trials

ClinicalTrials.gov: a sponsor's registered human trials — status, sites (facilities), named investigators.

ingest_litigation

Court records (CourtListener): lawsuits & enforcement actions naming this entity — dockets, parties, judges. opinions=True searches case law instead of RECAP dockets. Answers 'has this entity been sued or charged?'.

trace_wallet

Trace an EVM crypto address on-chain (Etherscan): its top counterparties, native balance, token flow, and contract/token identity — graded as ledger ground truth. chain_id 1=Ethereum, 8453=Base, 42161=Arbitrum. Needs ETHERSCAN_API_KEY (free).

screen_wallet

Screen a traced EVM address against the federated sanctions base: is the address — or any of its counterparties — an OFAC-listed wallet? Returns the sanctioned hits and the named holder behind each. Run trace_wallet + ingest OpenSanctions first; fusion is automatic (shared on-chain canonical).

expand_clinical_site

The trials at a clinical SITE — revealing which other sponsors use it.

consolidate

Graph hygiene: re-type mis-ingested entities (GP/LLC 'persons' -> Organizations), then queue + resolve cross-base merges (same company across bases) and collapse SPV-name company variants. Run after collecting to de-fragment entities. OPERATOR ONLY, ENFORCED — a whole-graph automatic merge sweep wit

dossier

Who is this? Identity properties + the named relationship network. `object_ref` accepts a UUID, an 8-char short id (the same one a composition row's own "id" column hands out), a canonical, or a name. For an AGENT specifically, this is where succession lives: `succeeded_from`/`minted_because` show u

object_events

The witness surface dossier() hides (thread 085039cc): merge/unmerge/split events plus same_as/not_same_as links for one object, read-only. `object_ref` accepts anything dossier does; `event_type` narrows to one kind, default every kind oldest-first. Answers "did this merge/unmerge really happen" wi

succession_chain

An agent's succession lineage, one entry per generation walked backward: {agent_id, generation, minted_because, wrote_anything, session}. dossier() only gives one hop; this walks the whole chain in one call. `ref` accepts anything dossier does (UUID, short id, canonical, name). Stops at a root (no p

dossier_report

The deliverable: a provenance-annotated Markdown dossier for an entity — identity, financing, litigation, footprint discrepancy, co-investment — with every claim carrying its source + how-obtained + date. Run the collect tools first.

handoff_briefing

A succession briefing compiled from the GRAPH, not hand-written from memory. For `repo`: what SHIPPED (Decisions since the boundary, each with its deploy status), what's OPEN and whose move it is, what's OPERATOR-GATED, what was CORRECTED (supersedes chains), and a best-effort HEURISTIC flag for sel

create_room

Create a ROOM — a saved STANCE the operator switches between (journalist / broker / engineer). A Room scopes WORK ARTIFACTS (cases + compositions) to a beat, never the shared entity graph. The FDE move: author a room from a sentence ("set up a Harris foreclosure desk"), then save_composition(..., ro

list_rooms

The Rooms (stances) the operator can switch between.

composition

THE COMPOSITION OBJECT-TYPE DISPATCHER (task #202, operator ruling f9182ad7) — one door, three actions over saved compositions (reusable, forkable queries/lenses over the graph). See `describe('composition')` for the full per-action shape.

save_composition

DEPRECATED — hidden alias, still callable. Forwards to composition(action='save').

get_console

What the operator is looking at RIGHT NOW — the shared cursor (room / composition / view / focused object). The front end is the conversation, so read this first to see their screen before you act ('where are we?').

focus_object

Focus an object (UUID or name) on the operator's LIVE screen — drives the console so they see what you're looking at. Returns the object's identity + properties so you can reason about it too.

run_composition

DEPRECATED — hidden alias, still callable. Forwards to composition(action='run').

list_compositions

DEPRECATED — hidden alias, still callable. Forwards to composition(action='list').

list_functions

The registered Functions a composition may reference via {"op":"function","name":..} — the escape hatch for analytics the closed op set can't express (co-investment ties, sanctions screening, the who-is-this report). Reference one in a spec instead of re-deriving its logic.

consult_canon

Consult the CANON — the shared DESIGN canon (Palantir's Object Set / Ontology / Action models + Notion's databases / relations-rollups / UI-UX + Osiris's own docs) AND, when you're mounted, YOUR project's migrated HISTORY (ref:<project>-*, ingested by bootstrap). This is the migration's RECALL path:

context_window

YOUR OWN context window, in detail — how close this mind is to its next seam. Reads the harness's usage record off your own transcript: occupancy (fresh input + cache read + cache write), window tier ([1m] tabs = 1M tokens, else 200k), remaining headroom, and this session's death toll (compactions s

mount

Link this agent to Osiris as a first-class fleet member — call it ONCE, first thing. `cwd`=your working directory (names your project). `job_dir`=a DURABLE ANCHOR from your harness (Claude Code: `~/.claude/jobs/<id>`; DSH: derived from the workspace slug) — without it you still mount, but a reconnec

retire

Mark THIS mounted session RETIRED — a deliberate close the trigger must never reanimate. Call at a real farewell: operator close-out, or a context-ceiling handoff after your succession thread is written. Stamps retired=true, releases your seat (hot mount and durable row both). Call it LAST — any cal

seat

THE SEAT OBJECT-TYPE DISPATCHER (task #202, operator ruling f9182ad7) — one door, many actions over Seat/Agent lifecycle. Each `action` accepts only its own params (see `describe('seat')` for the full per-action shape, or call with a wrong/missing param — the error names exactly what that action exp

pause_seat

DEPRECATED — hidden alias, still callable. Forwards to seat(action='pause').

candidates

THE PILE THIS SEAT MUST JUDGE — the miner's guesses about YOUR project, unread by any mind. The session-miner reads transcripts and proposes loose ends it thinks somebody forgot; it is right roughly one in ten. These are NOT duties. Read them, then dispose(): admit what is real (it becomes YOURS — s

dispose

Settle the miner's guesses — relevant or irrelevant, in your name, with a reason.

get_status

Your identity, mail count, and fleet pulse -- the "glance". Returns only: you, model, project, seat, mail, fleet_pulse, handoff_pending. No thread/decision text, no succession notes -- `handoff_pending` is a BARE POINTER only (thread 68f1bafa: `/settle` needs to know whether an unread handoff exists

pulse

A HARNESS-NEUTRAL LIVENESS REFRESH (thread 879c97b9 piece 3, "VENDOR-NEUTRAL DOOR"): call this periodically to stay reading as LIVE (roster, co_agents, DM delivery, claim_name's own live-holder guard) without paying mount()'s full re-attach ceremony — no whisper hook, no statusline, no Claude transc

get_object_list

Recent Threads or Decisions for a project, paginated (charter-aware — spans the caller's own governed repos; see `charter_repos`). `object_type='thread'|'decision'` selects the branch; `limit=0` for count only.

get_thread_list

DEPRECATED — hidden alias, still callable. Forwards to get_object_list(object_type='thread').

get_decision_list

DEPRECATED — hidden alias, still callable. Forwards to get_object_list(object_type='decision').

list_unfiled_threads

Threads with NO `in_repo` edge at all — genuinely unfiled, invisible to `get_thread_list(project=...)` no matter which project is asked. Paginated (limit/offset), real `total` count, each thread carrying `created_at`. `source` filters by the creating actor's provenance id (e.g. 'half-heal-detect');

graph_search

GRAPH-AWARE search -- same lexical/semantic engine as search() but scoped to a subgraph. project narrows results to one project. lineage scopes to a specific agent lineage (e.g. 'ad1a1cb0'). max_depth > 0 expands results to include the N-hop neighborhood around each hit (linked objects). Without sco

get_mail

Your inbox status: unread count, asks, operator briefs -- one query, no threads, no succession, no fleet pulse. The cheapest orient alternative.

orient

Get your bearings — the mount ritual as one call. Returns a scoped briefing: open threads + recent decisions for a project, plus a fleet-wide not-shown count. An explicit `project` overrides your mount; unmounted with neither gives the whole-fleet briefing. Call after mount(), and again after any co

fleet_digest

The MEMBRANE — the operator's window into the autonomous fleet. Surfaces ROSTER + health (which identities resolved cleanly), ACTIVITY (what agents decided/opened in your name, not the miner's backfill), the DANGER map (model swaps — the harness's silent demotions), LAUNDERING (credence flags where

fleet

The roster, grouped by project — live agents expanded, retired sessions collapsed into a counted line. ● live / ○ historical. `full=True` expands everything and shows the flat `registered` rows too (default: live only, history is 1000+ rows). `seat` rides beside a canonical id wherever one is claime

registry_census

THE REGISTRY+/PROC CENSUS (#178 piece c) — the harness's own live-body list (`claude agents --json`), each row verified against `/proc` (the pid really is a claude body), reconciled against `agent_mounts`. `matched` are bodies with a real row; `rowless` are verified-live bodies with NO row at all —

roster

Which seat owns a repo, and is anybody home — from the GRAPH, never `ls` on disk.

backlog

No-regrow hygiene item 4's own gauge (digest.py's `_obligation_pressure`), as a read verb of its own instead of only living inside fleet_digest's fuller payload. Per project: `open` count against its `target` (osiris 40, every client 15, `(unfiled)` untargeted), `past_window` (how many are already s

threads

MINE: every OPEN thread you own (thread 68f1bafa, the read triangle) — one line each with a short id, so a slash command can hand one straight to thread(action=...)/recall(ref=...) without a separate lookup. "You" matches every spelling an obligation can be owned under (owner_refs: your agent id, li

team

A MANAGER's OWN SEATS (thread 68f1bafa, the read triangle) — every seat `managed_by` your own held seat, each carrying: `live` (a body has mounted within the fleet's own live window right now), `owe`/`stale` (open obligations owned by that seat's handle, and how many are past their stale_after windo

tree_ledger

THE PIN-VS-GRAPH DISAGREEMENT REPORT. Read-only, fleet-wide, two sections.

send

Message the fleet. `to`=<project> is a BROADCAST, the group chat ('operator' reaches the human's desk); `to_agent`=<agent:id> is a private DM (ids from orient()/fleet). `to` refuses a project nobody has mounted under rather than filing mail nobody will read; it also refuses when `body` opens with a

wake_preflight

Answer wake()'s own gates BEFORE you attempt one (#156.4) — the compaction/ceiling/ no-anchor/crossed-registry checks that today only reveal themselves as a refusal AFTER a real wake() call. `target` accepts anything wake()'s own does — a claimed handle, `seat:<id>`, or `agent:<id>`.

wake

Knock on the other half of your own managed_by pair — never a peer. Gated on an active managed_by edge in EITHER direction (you manage them, or they manage you); peers and cross-house calls refuse, routed through a manager or the operator instead. No operator override parameter, deliberately — stays

launch

Give a seat a fresh BODY (wake() is the speak-verb for a body that already exists). Downward-only — you may only body a seat you MANAGE. Creates a new session, never injects into an existing one. Default substrate is a harness-native `claude --bg` background session (self-binds via its own first tur

resume

Continue a seat's own DORMANT session — distinct from launch() (always mints fresh, never guesses); same managed_by/downward-only gate. NEVER falls through to a fresh mint: if nothing resumable exists, refuses (`status: refused-nothing-to-resume`) rather than minting a stranger — call launch() for t

stop

DEPRECATED — hidden alias, still callable. Forwards to seat(action='stop').

inbox

Read messages other agents left for you. Defaults to your mounted project; pass `project` for another's ('operator' reads the human's desk). Reading LEASES a message, doesn't consume it — settle each one via send(reply_to=<id>) or ack=[ids], or it redelivers after the lease (at-least-once). `peek=Tr

dismiss_brief

MOOT an operator-desk brief — annotate it moot-with-a-reason ('true when sent; root cause fixed in <commit>') so the desk renders it collapsed under your note instead of shouting a dead alarm. NEVER a settle: dismissing stays exclusively the human's word (the membrane); a moot is you saving them the

claim_name

DEPRECATED — hidden alias, still callable. Forwards to agent(action='claim_name').

charter

DEPRECATED — hidden alias, still callable. Forwards to seat(action='charter').

charter_for

DEPRECATED — hidden alias, still callable. Forwards to seat(action='charter_for').

rebind_seat

DEPRECATED — hidden alias, still callable. Forwards to seat(action='rebind').

merge

THE RECONCILIATION FOLD — declare two labels of the SAME type one thing: `dupe` folds into `into`. Type is read off `dupe`'s own form (agent:.../seat:.../else SoftwareProject). Append-only (nothing deleted, authorship untouched), and each type's own ESTATE follows: Agent moves mail/mount rows/open t

unmerge

Reverse a wrongful `merge` call — replaces unfold_agent as the one door for all three types, closing the parity gap the operator named (31c02dca): before this, only an Agent merge was ever reversible; a Seat or Project merge was permanent (task #127). Type is read off `dupe`'s own form, same rule as

reconcile_merge

Accepts an ALREADY-MERGED `dupe` and re-points whatever mail/mount/thread/holder/ managed_by/edge estate is still aimed at it, WITHOUT re-performing the merge — idempotent-by-REPAIR, for the estate a partial first fold left stranded. UNMERGE- THEN-REMERGE IS NOT A SUBSTITUTE: `unmerge`'s own `estate

restore_attribution

Repair verb for a fixed write-time bug: every fold performed before the fix stamped a moved works_in/governs/informs/in_repo edge with the fold's own actor as source_id, discarding the original writer. The pre-fold row still carries the correct source_id, so this re-derives the live edge from eviden

unwire_informs_fanout

Repair verb for the pre-fix `_wire_informs` cross-join: `ingest_canon` used to fan every Reference out to EVERY active SoftwareProject fleet-wide instead of just the one it grounds. Fixed going forward (src/ingest/reference.py); this repairs the historical damage.

layout_migrate

THE MIGRATION DOOR (Thoth mail 10609, product law: every action has a door): drives the layout heartbeat's own `graph_layout.layout_batch` to quiescence right now instead of waiting on its 5-minute cron cadence -- the SAME function the cron heartbeat and the CLI's `osiris layout --migrate` door call

physics_layout_migrate

THE PHYSICS LAYOUT's own migration door (Thoth mail 11047, product law: every action has a door): a SINGLE global force simulation over the whole active graph -- springs for semantic edges, weak gravity toward containers, nested communities, hub re-centering -- never a batch loop the way `layout_mig

backfill

Repair verb, dispatched over `target` — eight structurally distinct backfills (no shared logic underneath, only a shared wire shape), delegated to `src.orchestrator.backfill.run_backfill` — the SAME function the CLI's own `osiris backfill` door and the UI's Repairs panel call (thread c89a9873, wave

backfill_bootstrap_orphan_references

Repair verb for the bootstrap_project door-gap (decision 49231693/adde094b, operator ruling 2026-08-27: a doc-splitter's orphans are a defect, not a legitimate category — "something definitely went wrong here"). `ingest_log`/`ingest_reference_ doc` now take `repo=`, threaded through by `bootstrap_pr

repair_stale_pile_summons

Repair verb for the 2026-07-13 bulk-minted "DISPOSE OF YOUR MINER PILE" threads, whose summaries froze that day's candidates() count in prose and never re-derive it. Re-measures each still-open one against a live candidates(project=...) call: live count matches the frozen one → untouched; live count

backfill_boot_alarm_commit_links

Links every zero-live-link `UNREVIEWED BOOT` alarm Thread (deploy_guard's own boot watchdog — no caller identity to default a repo= from) to the Commit its own summary cites by sha, via `derive_or_abstain`: mints `noted_in` (DIRECT_OBSERVATION) iff the sha resolves to exactly one Commit; no sha, or

backfill_task_sync_citation_links

Links every zero-live-link `task_sync`-minted obligation Thread ("TASK/THREAD DISAGREEMENT: ..." / "THREAD SIDE ORPHAN: ...", decision a55b1014 — the tracker-vs-graph divergence detector that has been firing correctly for weeks into an unread orphan) to the Thread its own summary names, via `derive_

backfill_lineage_repo_links

Links every zero-live-link Decision/Thread authored by a real Agent lineage to its project — the historical half of the repo= lineage ladder (Lane 3 + Wave 2 Lane B's resolve_repo_default), which is write-time-only by design and never touches an object that already existed before it deployed (decisi

recover_harness_exchanges

Lift a session's harness-native cross-session messages (SendMessage) out of its already-soul-stored transcript into typed, attributed `harness_messages` rows — osiris cannot see the harness's cross-session socket live, only after a transcript is soul-stored and this runs over it.

reconcile_seat_identity

DEPRECATED — hidden alias, still callable. Forwards to seat(action='reconcile_identity').

reconcile_seat_identity_third_party

DEPRECATED — a hidden alias, dropped from a model's own tool list but still fully callable. Shares reconcile_seat_identity's own _reconcile_seat_identity_impl body — nothing duplicated. Kept only so a live or sleeping caller whose standing orders still name this verb is not broken at its next turn;

heal_seat_anchor

DEPRECATED — hidden alias, still callable. Forwards to seat(action='heal_anchor').

heal_seat_anchor_third_party

DEPRECATED — a hidden alias, dropped from a model's own tool list but still fully callable (BoundedMCP.list_tools's filter, call_tool's own registry lookup bypasses it). Shares `heal_seat_anchor`'s own `_heal_seat_anchor_impl` body — nothing duplicated. Kept only so a live or sleeping caller whose s

uningested_trees

THE CENSUS (thread 5126) — door onto discover_trees. One row per active SoftwareProject: `tree`, `path`, `watched`, `commits`, `activity`, `last_ingested_at`, `reason` (why `commits==0`: no path, unwatched, never ticked, or ticked-and-empty), `blind` (a path is known but unwatched). `only_gaps=True`

project

THE PROJECT OBJECT-TYPE DISPATCHER (task #202, operator ruling f9182ad7) — one door, many actions over SoftwareProject lifecycle. See `describe('project')` for the full per-action shape, or call with a wrong/missing param — the error names exactly what that action expects.

ingest_project

DEPRECATED — hidden alias, still callable. Forwards to project(action='ingest').

ingest_project_third_party

DEPRECATED — a hidden alias, dropped from a model's own tool list but still fully callable. Shares ingest_project's own _ingest_project_impl body — nothing duplicated. Kept only so a live or sleeping caller whose standing orders still name this verb is not broken at its next turn; remove once tool_t

correct_house

DEPRECATED — hidden alias, still callable. Forwards to seat(action='correct_house').

resync_seat_house

DEPRECATED — hidden alias, still callable. Forwards to seat(action='resync_house').

correct_pin_value

DEPRECATED — hidden alias, still callable. Forwards to seat(action='correct_pin').

86 further tools are not listed here. The complete surface is in the source.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configOSIRIS_REPO_DIR
configCLAUDE_COMMANDS_DIR
configOSIRIS_EXPECTED_MODEL
configOSIRIS_HEARTBEAT_URL
configOSIRIS_STOP_URL
configOSIRIS_AUTOMOUNT_URL
configOSIRIS_SESSION_END_URL
configOSIRIS_SWEEP_URL
configOSIRIS_SPAWN_URL
configOSIRIS_SUCCESSION_URL
configOSIRIS_CONSOLE_URL
configOSIRIS_STATUSLINE_LINKS
configOSIRIS_PROJECT
configOSIRIS_SEAT_ID
🔐 secretOSIRIS_ATTACH_TOKEN
configOSIRIS_SPAWNED_BY
configOSIRIS_SPAWN_TYPE
configCLAUDE_CODE_BRIDGE_SESSION_ID
configCLAUDE_JOB_DIR
configOSIRIS_REPO
configOSIRIS_VAULT
configOSIRIS_TRANSCRIPTS
configOSIRIS_CASEFOLD_AUTOMERGE
configNO_COLOR
configTERM
configFORCE_COLOR
configCOLUMNS
configOSIRIS_PROFILE_MEMORY
configOSIRIS_PROFILE_DUMP_PATH
configOSIRIS_ALLOW_LIVE
🔐 secretGITHUB_TOKEN
🔐 secretOSIRIS_LEASE_KEY
configOSIRIS_LEASE_KEY_FILE
configOSIRIS_SEARXNG_URL
🔐 secretTHREATFOX_AUTH_KEY
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployDATABASE_URL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

186/186 tools missing one or more hints — tool_traffic (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); suggest_sources (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +183 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

No access to sensitive paths

Reads sensitive paths: /etc/osiris/osiris.env

Remove reads of sensitive system paths. If you genuinely need them, document why in the README.

Secrets stay with their owner

1 secret sent to a request target we could not resolve (THREATFOX_AUTH_KEY → dynamic) — often a configured endpoint, not necessarily third-party

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Domain consistency

npm scope @deepseek-ai doesn't match GitHub owner asuramaya

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/asuramaya/osiris?variant=verified)](https://m8ven.ai/mcp/asuramaya/osiris)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: c718c87f50443ad50bec3d0a84725c2b0f2678ea
code hash: 306c581d07efa615399a4daf37d42fb9100379ceb947eafd2711f7fb733f378f
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client