chimera-agent (brcampidelli/chimera-agent) is an MCP server listed on the M8ven Trust Index. It scores 43 out of 100, grade D. It declares 50 tools. No publisher has claimed this listing.

D
Warning
43/100

chimera-agent

Open-source AI agent that reasons by blending many AI models, does real work on its own, and keeps learning — safe, self-hostable, and fully yours.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

brcampidelli

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: OPENROUTER_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Reads files from sensitive locations
Touches: /opt/data/.env, ~/.aws/credentials, ~/.aws/credentials\
🔐
You'll be asked for 1 credential: OPENROUTER_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes47 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

chimera_solve

Autonomously solve a task with Chimera's plan + verify-or-revert loop. Returns the final answer. Use for multi-step work, not a single Q&A turn.

chimera_fuse

Answer a prompt through Chimera's LLM-Fusion engine (panel -> judge ->

chimera_memory_search

Search Chimera's long-term memory and return the top matching facts.

activity
mcp
mcplist
mcpdescribe
mcpcall
governed
ledgered
browser
echo
calendarevents
renderchart
codeinterpreter
executecode
toollist
tooldescribe
toolcall
_workspace
readdocument
downloadmedia
editfile
applypatch
editbatch
sendemail
reademail
readfile
writefile
listdir
httpget
imagegen
texttospeech
transcribeaudio
arxivsearch
youtubetranscript
scrape
extract
map
crawl
grep
glob
runshell
todowrite
websearch
_stub
_shaped
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configCHIMERA_DEFAULT_MODEL
configCHIMERA_COST_MODE
configCHIMERA_WORKSPACE
configCHIMERA_BROWSER_AUTO_INSTALL
configCHIMERA_WHISPER_MODEL
configOTEL_EXPORTER_OTLP_ENDPOINT
configCHIMERA_DIGEST_MAX_AGE_H
configCHIMERA_DIGEST_CHECKS_TIMEOUT_S
configLOOPSBENCH_TASKS
configCHIMERA_HOMEwritten for you at .chimera/traces.jsonl (or $CHIMERA_HOME)
configBENCH_MODEL
configBENCH_TOP_MODEL
configBENCH_TASKS
configREAD_MULT
configWRITE_MULT
configBENCH_AXIS
configBENCH_POINTS
configBENCH_FIXED_D
configBENCH_FIXED_REPS
configBENCH_TIMEOUT
configPROBE_OUT
configBENCH_OUT
configBENCH_SEEDS
configBENCH_SUITE
configBENCH_CONNECT
configBENCH_SEMANTIC
configBENCH_ARM
configGITHUB_STEP_SUMMARY
configCHIMERA_LB_MODEL
configCHIMERA_LB_SOLVE_TIMEOUT
🔐 secretOPENROUTER_API_KEY
configCHIMERA_RECEIPTS
configCHIMERA_FUSION_JUDGE
configPILOT_SLICE
configPILOT_OUT
configPILOT_RESERVE
configBENCH_MAX_STEPS
configBENCH_SLICE
configSWE_DJANGO_REF
configSWE_WORK
configBENCH_ROLE_MODELS
configCHIMERA_TB_MODEL
configCHIMERA_TB_WHEEL
configCHIMERA_WHEELHOUSE_TAR
configCHIMERA_SOLVE_TIMEOUT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

50/50 tools missing one or more hints — chimera_solve (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); chimera_fuse (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); chimera_memory_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +47 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

20/50 tools referenced in tests (40%)

Write tests that reference each tool by name so every tool has at least one test.

No access to sensitive paths

Reads sensitive paths: /opt/data/.env, ~/.aws/credentials, ~/.aws/credentials\

Remove reads of sensitive system paths. If you genuinely need them, document why in the README.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/brcampidelli/chimera-agent?variant=verified)](https://m8ven.ai/mcp/brcampidelli/chimera-agent)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 44e11a44703892c696135bc1abb417f6b7e23529
code hash: 348a7db6177496c097d304f0448e92c4cef3a7ffcbb2025d78a5e39e8cd6ede3
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client