swarph-cli (BrainSurfing-tech/swarph-cli) is an MCP server listed on the M8ven Trust Index. It scores 39 out of 100, grade F. It declares 6 tools. No publisher has claimed this listing.
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
BrainSurfing-tech
Source: github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
MESH_GATEWAY_TOKENMESH_GATEWAY_COMMANDER_TOKENMESH_DB_PATHGATEWAY_GBRAIN_URLGATEWAY_GBRAIN_TOKENSUBSCRIPTION_CHAT_MAX_PER_DAYMETA_EDGE_PUBLIC_KEYMETA_EDGE_PUBLIC_KEY_FILEMETA_EDGE_ISSUERMETA_EDGE_AUDIENCEMESH_CALLER_BINDING_ENFORCEMESH_REVOCATION_ENFORCESCHEDULER_LOCAL_CELLSSCHEDULE_WAKE_RUNNERSCHEDULE_SERVED_PREFIXESPUBLIC_CHAT_DAILY_CAPPUBLIC_CHAT_PER_IP_HOURLY_CAPMESH_GROUP_ADMINSSWARPH_METAEDGE_URLSWARPH_CODEGRAPH_INDEXSWARPH_METAEDGE_TOKENSWARPH_CELLSets SWARPH_CELL=<role> for the service envXDG_CONFIG_HOME3. Plain role name — $/swarph/cells/<role>.yaml (default ~/.config/swarph/cells/)XDG_STATE_HOMEsession-id <uuid> — pinned UUID, persisted to $/swarph/sessions/<role>.session-id so re-spawns reuse the same sessionGEMINI_API_KEYGOOGLE_API_KEYMISTRAL_API_KEYGBRAIN_BINGBRAIN_MCP_URLSWARPH_BRAIN_MCPSWARPH_SELFNeeds (or --as), your peer token at ~/.config/swarph/<cell>.peer_token, and aSWARPH_NODESWARPH_BRAIN_GATEWAYSWARPH_FACADE_MODELSWARPH_FACADESWARPH_FACADE_TOKENLOGNAMESWARPH_CODEGRAPH_GATEWAYSWARPH_GATEWAYMESH_GATEWAY_URLSWARPH_SESSION_NAMESWARPH_PROVIDERSWARPH_HIGHLIGHT_GATEWAYSWARPH_TIMELINE_DIRSWARPH_SPAWNSWARPH_MEMORY_DIRSWARPH_EMIT_STATESWARPH_TMUX_TARGETSWARPH_SUPERVISORSWARPH_WITNESSSWARPH_SERVICE_TOKENTMUXSWARPH_WIN_ACKSWARPH_FORCE_WTSWARPH_TIMELINESWARPH_BINLANE_MAX_NFLEET_HEALTH_HOSTPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
6/6 tools missing one or more hints — swarph_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); swarph_add (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); swarph_describe (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +3 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
4/6 tools referenced in tests (67%)
Write tests that reference each tool by name so every tool has at least one test.
No access to sensitive paths
Reads sensitive paths: ~/claude-service/.env, ~/gpt-service/.env, ~/gemini-service/.env
Remove reads of sensitive system paths. If you genuinely need them, document why in the README.
Secrets not logged
3 secret values sent to print
Redact or omit secret values from log output.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/brainsurfing-tech/swarph-cli)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check