healthcare-agent-orchestrator (Azure-Samples/healthcare-agent-orchestrator) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 1 tool. No publisher has claimed this listing.

B
Emerging
89/100
7 days ago

healthcare-agent-orchestrator

Facilitates creating modular specialized agents that coordinate across diverse data types and tools like M365 and Teams to assist multi-disciplinary healthcare workflows—such as cancer care.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Azure-Samples

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: GRAPH_RAG_SUBSCRIPTION_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configAZURE_CLIENT_ID
configWEBSITE_SITE_NAME
configSCENARIO
configAPP_BLOB_STORAGE_ENDPOINT
configAZURE_OPENAI_DEPLOYMENT_NAME_REASONING_MODEL
configAZURE_OPENAI_REASONING_MODEL_ENDPOINT
🔐 secretGRAPH_RAG_SUBSCRIPTION_KEY
configOTEL_EXPERIMENTAL_RESOURCE_DETECTORS
configEXCLUDED_AGENTS
configBOT_IDS
configHLS_MODEL_ENDPOINTS
configMicrosoftAppPassword
configMicrosoftAppType
configMicrosoftAppTenantId
configAZURE_OPENAI_DEPLOYMENT_NAME
configAZURE_OPENAI_ENDPOINT
configCLINICAL_NOTES_SOURCEDefaults to blob
configFHIR_SERVICE_ENDPOINT
configFABRIC_USER_DATA_FUNCTION_ENDPOINT
configKEYVAULT_ENDPOINT
configHEALTHCARE_AGENT_DIRECTLINE_URL
configHEALTHCARE_AGENT_DEFAULT_USER_ID
configHEALTHCARE_AGENT_MAX_RETRIES
configHEALTHCARE_AGENT_RETRY_DELAY
configHEALTHCARE_AGENT_TIMEOUT
configHEALTHCARE_AGENT_MAX_RECONNECT_ATTEMPTS
configHEALTHCARE_AGENT_WS_PING_INTERVAL
configHEALTHCARE_AGENT_WS_PING_TIMEOUT
configHEALTHCARE_AGENT_WS_CLOSE_TIMEOUT
configHEALTHCARE_AGENT_RESPONSE_POLL_INTERVAL
configBACKEND_APP_HOSTNAME
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployAPPLICATIONINSIGHTS_CONNECTION_STRING
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

1/1 tools missing one or more hints — reset_conversation (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/azure-samples/healthcare-agent-orchestrator)](https://m8ven.ai/mcp/azure-samples/healthcare-agent-orchestrator)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: f9abf14177c0c7c6817a990f45ffa19b3a4cd51b
code hash: b229ccfda8b1f43be81b91710b4388c6d69e4a4958c9aa16af4cc2690e31e5b2
verified: 9/3/2026, 7:07:51 PM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client