javis-os (blogminhquy/javis-os) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it yet. No publisher has claimed this listing.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

blogminhquy

Source: github_topic · also listed on github_code, github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: WATCHTOWER_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🚨
Code appears obfuscated
3 files are unreadable to a human reviewer. Cannot audit what they do.
🔐
You'll be asked for 6 credentials: WATCHTOWER_TOKEN, JAVIS_AGY_MCP_KEY, ELEVENLABS_API_KEY, JAVIS_ADMIN_PASSWORD, XAI_API_KEY, JAVIS_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configJAVIS_MEMORY_INDEX_MAX
configCLAUDE_CWDrepo root
configBRAIN_PATH
configBRAINS_DIRbrains/ (Docker: /brains)
configOBSIDIAN_VAULT_PATHvault/ (Docker: /data/vault)
configSOURCES_PATH
configJAVIS_SECURE_COOKIE(auto theo tên miền)
configJAVIS_FILES_ROOT
configWORKSPACE_NAME
configTTS_VOICEvi-VN-HoaiMyNeural / +5%
configTTS_RATEvi-VN-HoaiMyNeural / +5%
🔐 secretWATCHTOWER_TOKENjavis-update
configJAVIS_PORTNative: JAVIS_NAME=javis-shop =7778 ./install.sh.
configJAVIS_TERMINAL_CWD
configJAVIS_HOST127.0.0.1
configJAVIS_MCP_DISCOVER_TIMEOUT
configJAVIS_MCP_WARM_TIMEOUT
configJAVIS_AGY_BIN
configJAVIS_STATE_DIRserver/ (Docker: /data/state)
configJAVIS_AGY_PROMPT_DAI
🔐 secretJAVIS_AGY_MCP_KEY
configJAVIS_AGY_MCP_HOME
configJAVIS_AGY_MCP_CONFIG
configJAVIS_AGY_TIMEOUT
configJAVIS_AGY_GIU_NGU_CANH
configJAVIS_BG_MAX_WALL_S
configJAVIS_CLAUDE_ENGINE
configJAVIS_CODEX_BIN
configJAVIS_CODEX_SANDBOX
configJAVIS_CLAUDE_INIT_TIMEOUT
configCLAUDE_CODE_STREAM_CLOSE_TIMEOUT
configJAVIS_CLAUDE_CLI
🔐 secretELEVENLABS_API_KEY
configPYTHONUTF8
configJAVIS_REQUIRE_LOGIN(auto)
🔐 secretJAVIS_ADMIN_PASSWORDJAVIS_ADMIN_USER, , cộng một trường tuỳ chọn
configJAVIS_ADMIN_USER, JAVIS_ADMIN_PASSWORD, cộng một trường tuỳ chọn
configJAVIS_MAX_TOOL_ROUNDS
configJAVIS_SYNC_ANH_MAX_MB
configGROK_HOME
configJAVIS_GROK_BIN
🔐 secretXAI_API_KEY
configJAVIS_GROK_TIMEOUT
configJAVIS_IMAGE_HOST_MODEL
configJAVIS_IMAGE_MODEL
configJAVIS_DISABLE_PACKS
configJAVIS_SESSIONS_DB
configJAVIS_KANBAN_MAX_WORKERS
configJAVIS_TERMINAL
configJAVIS_TERMINAL_SHELL
configSHELL
configJAVIS_TERMINAL_REMOTE
configDISPLAY
configWAYLAND_DISPLAY
configJAVIS_LAUNCHD_LABEL
configJAVIS_CLAUDE_PROJECTS_DIR
configJAVIS_CODEX_SESSIONS_DIR
configJAVIS_ALLOWED_HOSTSlocalhost + tên miền đã đặt
configJAVIS_PUSH_CONTACT
configJAVIS_YOUTUBE_PROXY
configJAVIS_HOME
configJAVIS_PROFILE
configJAVIS_URL
🔐 secretJAVIS_TOKEN
configJAVIS_BRAIN
configNO_COLOR
configJAVIS_DEPLOY_TARGET
configDOMAIN_NAMEÔ Environment của mẫu mới chỉ còn 3 trường cần thiết: ,
// quality suggestions

Tools detected

No tools extracted — insufficient content to verify at Tier 2

Readable source code

3 files are minified or bundled, which is usually build output rather than concealment

Ship unminified, readable source.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/blogminhquy/javis-os)](https://m8ven.ai/mcp/blogminhquy/javis-os)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: af534c524b8aab09a91c08728e25d732065813ad
code hash: 510943141a6bd9af61d9c1ca49a5c87fcec3fac9a7de9a5e07679b7165dfec54
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client