F
Warning
22/100
1 day ago

source

BlackRoad Source — canonical source tree with 198 directories organizing every component, service, agent, and product

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

BlackRoad-OS-Inc

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
12 flows detected: PRISM_TOKEN, GITHUB_TOKEN, SESSION_SECRET. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 32 credentials: AIRTABLE_API_KEY, GH_TOKEN, GH_WEBHOOK_SECRET, GITHUB_TOKEN, GITHUB_WEBHOOK_SECRET, GITLAB_SSH_PRIVATE_KEY, GUMROAD_TOKEN, INTERNAL_TOKEN, LINEAR_API_KEY, SERVICE_TOKEN, SESSION_SECRET, SHEETS_CONNECTOR_TOKEN, STRIPE_PUBLIC_KEY, STRIPE_SECRET, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, SANDBOX_API_KEY, ANTHROPIC_API_KEY, SECRET_KEY, PI_OPS_MQTT_PASSWORD, OPENAI_API_KEY, ATLASSIAN_API_TOKEN, CODEX_SSH_KEY, GIT_TOKEN, SALESFORCE_ACCESS_TOKEN, HUBSPOT_API_KEY, PRISM_EMAIL_SMTP_PASSWORD, SAP_PASSWORD, NETSUITE_CONSUMER_KEY, NETSUITE_CONSUMER_SECRET, NETSUITE_TOKEN_SECRET, HOLO_MQTT_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretAIRTABLE_API_KEY
configAIRTABLE_BASE_ID_MAIN
configAIRTABLE_TABLE_BACKLOG
configALLOW_ORIGINS
configALLOW_SHELL
configASANA_PROJECT_ID_MAIN
configASANA_PROJECT_ID_OPS
configAUTH_SERVICE_URL
configAUTOPAL_GLOBAL_ENABLED
configBASE_URL
configBILLING_DISABLE
configBLACKROAD_API_URL
configBLACKROAD_GATEWAY_CONFIG
configBRAINSTORM_DIR
configBRAINSTORM_HOST
configBRAINSTORM_OWNER_PID
configBRAINSTORM_PORT
configBRAINSTORM_URL_HOST
configBRANCH_MAIN
configBRANCH_STAGING
configBRC_DISABLE_NATIVE_DB
configBR_TEST_DISABLE_DB
configBYPASS_LOGIN
configCHANNEL_DEV_CI
configCHANNEL_DEV_PRS
configCHANNEL_RELEASES
configCHANNEL_SECURITY
configCORS_ORIGIN
configDB_PATH
configDEFAULT_LLM_MODEL
configDEPLOY_BASE_DIR
configDISCORD_INVITE
configDOTENV_PATH
configELECTRON_DISABLE_LOGGING
configENABLE_OPERATOR
configENABLE_RPA
configFLAGS_MAX_AGE_MS
configFLAGS_PARAM
🔐 secretGH_TOKEN
🔐 secretGH_WEBHOOK_SECRET
configGITHUB_ORG
🔐 secretGITHUB_TOKEN
🔐 secretGITHUB_WEBHOOK_SECRET
configGITLAB_GROUP
configGITLAB_REPO_SSH
🔐 secretGITLAB_SSH_PRIVATE_KEY
configGIT_REPO_PATH
configGOOGLE_CALENDAR_CREDENTIALS
configGSHEETS_SA_JSON
🔐 secretGUMROAD_TOKEN
configICS_URL
🔐 secretINTERNAL_TOKEN
configJEST_WORKER_ID
🔐 secretLINEAR_API_KEY
configLLM_BRIDGE_URL
configLLM_URL
configLOG_LEVEL
configMAIL_PROVIDER
configMATH_ENGINE_URL
configMODELS_TTL_MS
configN8N_PREVIEW_MODE
configOLLAMA_URL
configORIGIN_KEY_PATH
configPI_CORE_HOST
configREGISTRY_API
configRITUAL_WORKFLOW_FILE
configRITUAL_WORKFLOW_REF
configRPA_ALLOW_HOSTS
🔐 secretSERVICE_TOKEN
🔐 secretSESSION_SECRET
configSF_USERNAME
🔐 secretSHEETS_CONNECTOR_TOKEN
configSLACK_WEBHOOK_URL
🔐 secretSTRIPE_PUBLIC_KEY
🔐 secretSTRIPE_SECRET
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
configSUBSCRIBE_MODE
configTARGET_HOST
configTARGET_IP
configTOOLS_PORT
configWEB_ROOT
configMODEL_NAME
configMODEL_PATH
configWORKERS
configGPU_MEMORY_UTILIZATION
configMAX_MODEL_LEN
configBLACKROAD_IDENTITY_VALIDATION
configBLACKROAD_AUDIT_LOGGING
configBLACKROAD_BREATH_SYNC
configTENSOR_PARALLEL_SIZE
configCORS_ORIGINS
configSANDBOX_DOMAIN
🔐 secretSANDBOX_API_KEY
configKIMI_BASE_URL
configKIMI_MODEL_NAME
🔐 secretANTHROPIC_API_KEY
🔐 secretSECRET_KEY
configPI_OPS_MQTT_USERNAME
🔐 secretPI_OPS_MQTT_PASSWORD
configEXPERIMENT_DB
configPIPELINE_DB
configNOTEBOOK_DB
configOLLAMA_MODEL
configACCESS_LOG
configGITHUB_STEP_SUMMARY
configBACKUP_DB
configBACKUP_STORE
configARCHIVER_DB
configARCHIVE_DIR
configENVIRONMENT
configHOST
🔐 secretOPENAI_API_KEY
configOLLAMA_BASE_URL
configCLAUDE_OFFICE_STRIP_PREFIXES
configCLAUDE_SESSION_ID
configATLASSIAN_BASE_URL
configATLASSIAN_EMAIL
🔐 secretATLASSIAN_API_TOKEN
configPRISM_CALENDAR_EVENT_LOG
🔐 secretCODEX_SSH_KEY
configCODEX_SSH_ACCEPT_NEW
🔐 secretGIT_TOKEN
configCODEX_REPOS_BASE
configSERVICES_BLOB
configCRM_BACKEND
configSALESFORCE_INSTANCE_URL
🔐 secretSALESFORCE_ACCESS_TOKEN
🔐 secretHUBSPOT_API_KEY
configPRISM_EMAIL_SMTP_HOST
configPRISM_EMAIL_SMTP_PORT
configPRISM_EMAIL_SMTP_USERNAME
🔐 secretPRISM_EMAIL_SMTP_PASSWORD
configPRISM_EMAIL_FROM
configPRISM_EMAIL_SMTP_USE_TLS
configPRISM_EMAIL_LOG_FILE
configERP_BACKEND
configSAP_BASE_URL
configSAP_USERNAME
🔐 secretSAP_PASSWORD
configNETSUITE_ACCOUNT_ID
🔐 secretNETSUITE_CONSUMER_KEY
🔐 secretNETSUITE_CONSUMER_SECRET
configNETSUITE_TOKEN_ID
🔐 secretNETSUITE_TOKEN_SECRET
configHOLO_MQTT_TOPIC
configHOLO_MQTT_HOST
configHOLO_MQTT_PORT
configHOLO_MQTT_USERNAME
🔐 secretHOLO_MQTT_PASSWORD
configHOLO_MQTT_QOS
configHOLO_MQTT_KEEPALIVE
configHOLO_MQTT_TIMEOUT
configHOLO_MQTT_RETAIN
configHOLO_MQTT_CLIENT_ID
configHOLO_SHOWCASE_INTERVAL
configHOLO_SHOWCASE_CYCLES
configOPENAI_BASE
configMODEL
configAI_BACKEND
configPRISM_READ_ONLY
configPRISM_TENANT
configPRISM_WEB_SEARCH_INDEX
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

4/4 tools missing one or more hints — route_request (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_models (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); gateway_stats (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +1 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

3/4 tools referenced in tests (75%)

Write tests that reference each tool by name so every tool has at least one test.

No eval / new Function

1 eval() or new Function() call — dynamic code execution

Replace eval / Function with explicit parsing or safer alternatives.

Shell command execution

13 child_process/subprocess calls in production code — runs shell commands (services/blackroad-tools/server.js:74, services/blackroad-tools/server.js:184, services/deploy-platform/road-deploy/server.js:174)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets stay with their owner

4 secret/sensitive values flow into network calls (PRISM_TOKEN → dynamic, SESSION_SECRET → dynamic) (8 other flows matched canonical API hosts)

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Secrets never reach shell commands

1 secret value passed to shell commands — possible command injection

Never pass secrets through shell commands. Use library APIs that accept credentials as arguments.

Secrets not logged

11 secret values sent to console.log

Redact or omit secret values from log output.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/blackroad-os-inc-source-13nxxd?variant=verified)](https://m8ven.ai/mcp/blackroad-os-inc-source-13nxxd)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: ecdee15e3ddf4ec735f0476ac534a09cc4e1e28b
code hash: 5999c4f75d9c5edce843626ace7c2e31d0367ef4e8c611bd9f1c4205f5a976b2
verified: 8/19/2026, 4:06:02 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client