mcp-agent-bridge (catesandrew/mcp-agent-bridge) is an MCP server listed on the M8ven Trust Index. It scores 62 out of 100, grade C. It declares 35 tools. No publisher has claimed this listing.
Bridge AI coding agents (Claude Code, Codex, Copilot) as MCP servers for cross-agent code review and collaboration
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
catesandrew
Source: github_repo_search
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
reviewSend a plan, diff, or implementation to a Claude instance for independent review. Returns structured JSON with verdict, issues, and suggestions.
askAsk a Claude instance a freeform question about the codebase. Returns text.
implementcode_reviewSpecialized code review that analyzes a git diff. Returns structured JSON with verdict, issues, and suggestions.
analyze_failureAnalyze a Playwright release-failure evidence bundle and return a structured diagnostic report. The caller supplies the full prompt (run summary, failed/flaky results, and repo context) as `content`; the model's output is constrained to the findings[] schema (runSummary + per-finding rootCause, conf…
quick_analysisLightweight, non-agentic triage for a stale or low-priority item — e.g. deciding what to do with a PR review that's gone quiet. Returns a verdict from a small fixed set plus a one-sentence reason. Not a full code review.
agent_chatOne turn of an interactive chat with resource context and optional tool proposals. The caller assembles the full prompt (system instructions, resource context, available tool descriptions, and conversation history) — this tool has no memory of prior turns. Returns a text reply plus zero or more prop…
cover_letter_generatorGenerate a personalized, compelling cover letter from a resume and job description. Returns an analysis, the complete letter, alternative opening hooks, and interview talking points.
creative_portfolio_resumeGenerate both an ATS-compatible and a designed resume for creative professionals (graphic designers, UX, marketing, writers, photographers, etc.). Returns both versions plus field-specific tips and portfolio link strategy.
executive_resume_writerCraft a C-suite, VP, or Director-level resume that tells a transformation story. Returns executive profile, core competencies, career highlights, full experience section, and coaching notes.
interview_prep_generatorGenerate STAR stories, predicted questions, self-introduction pitch, and interview strategy tailored to a specific role.
job_description_analyzerAnalyze a job posting to extract requirements, calculate match score, detect red flags, and generate tailored application strategy.
linkedin_profile_optimizerOptimize a LinkedIn profile with keyword-rich headline options, rewritten About section, experience bullet rewrites, skills recommendations, and a 30-day action plan.
portfolio_case_study_writerTransform a project into a compelling portfolio case study with problem, process, solution, results, and learnings. Returns full case study, executive summary, and interview prep notes.
reference_list_builderBuild a formatted professional reference list with briefing emails, permission scripts, talking points, and timing strategy for each reference.
resume_ats_optimizerOptimize a resume to pass ATS screening. Returns keyword gap analysis, match score, formatting fixes, and optimized sections with projected score improvement.
resume_bullet_writerTransform weak, duty-focused resume bullets into achievement-focused statements using the X-Y-Z formula. Returns diagnosed issues, metric-extraction questions, and 2-3 rewritten versions per bullet.
resume_formatterAudit and fix resume formatting for ATS compatibility and human readability. Returns formatting audit, specific fixes, reformatted sections, and ATS compatibility score.
resume_quantifierAdd metrics and data-driven impact to resume bullets. Returns discovery questions, estimated metrics, and 2 quantified versions (conservative and optimistic) per bullet.
resume_section_builderBuild all resume sections optimized for career stage and target role. Returns section order, professional summary, skills section, experience guidance, and complete section checklist.
resume_tailorTailor a resume to a specific job posting with keyword extraction, match audit, rewritten summary, prioritized skills, and bullet rewrites. Maintains authenticity — all changes reflect genuine experience.
resume_version_managerCreate and organize a master resume, manage tailored versions with naming conventions, track applications, and establish an update workflow.
tech_resume_optimizerOptimize resumes for software engineering, PM, data, and DevOps roles with skill section restructuring, technical bullet rewrites, projects section guidance, and GitHub recommendations.
career_fact_extractorExtract a structured, fact-ID-tagged database of career facts from a resume, LinkedIn profile, brag document, or any source material. Preserves truthfulness for downstream resume tailoring.
recruiter_first_screen_simulationSimulate a skeptical hiring manager's 45-second resume screen. Returns a Yes/Maybe/No decision, top reasons and concerns, scores across 6 dimensions, and exact rewrites to make before applying.
open_pr_ghPush the active branch and open a GitHub pull request with a structured description, linked ticket, reviewers, and labels. Returns step-by-step workflow instructions.
review_pr_ghSystematic file-by-file GitHub PR code review. Posts inline comments and a verdict. Returns step-by-step workflow instructions.
open_pr_adoPush the active branch and open an Azure DevOps pull request with a structured description, linked work items, and optional auto-complete. Returns step-by-step workflow instructions.
review_pr_adoSystematic file-by-file ADO PR code review. Posts inline thread comments and a vote. Returns step-by-step workflow instructions.
codexSend a prompt to OpenAI Codex CLI for code generation or analysis.
codex_replyContinue a conversation with Codex by sending a follow-up reply. Note: Does not maintain actual session state; context is passed inline.
narrate_videoExtract frames from a video (fixed-fps or scene-change sampling) and narrate the sequence with Claude. Returns both the per-frame descriptions and a single synthesized narration string.
extract_framesExtract frames from a video (fixed-fps or scene-change sampling) without narrating them. Returns a sessionId plus a thumbnail per frame; pass the sessionId to narrate_frames to describe them, or to close_session to free the extracted files early. Sessions auto-expire after 30 minutes.
narrate_framesNarrate frames previously extracted via extract_frames, identified by sessionId. Can be called more than once against the same sessionId (e.g. with a different prompt or batchSize) without re-extracting. Pass close: true to free the session's frame files immediately after this call instead of waitin…
close_sessionFree the frame files held by a session started with extract_frames. Safe to call on an already-closed or expired sessionId (no-op).
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
CLAUDE_ALLOWED_CWD_ROOTSCLAUDE_ANALYSIS_MODELCLAUDE_MCP_HTTPCLAUDE_MCP_HTTP_PORTClaude HTTP portCLAUDE_REVIEW_ALLOWED_TOOLSCLAUDE_REVIEW_CWDCLAUDE_REVIEW_MAX_TURNSCLAUDE_REVIEW_MODELModel for Claude reviewsCLAUDE_REVIEW_PERMISSION_MODECLAUDE_REVIEW_TIMEOUT_MSCODEX_REVIEW_AGENT_PATHCODEX_REVIEW_MODELCOPILOT_REVIEW_MODELVIDEO_CLAUDE_PERMISSION_MODEVIDEO_FFMPEG_TIMEOUT_MSVIDEO_MCP_HTTPVIDEO_MCP_HTTP_PORTVIDEO_NARRATION_MODELVIDEO_NARRATION_TIMEOUT_MSVIDEO_SESSION_TTL_MSTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
35/35 tools missing one or more hints — review (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); ask (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); implement (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +32 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/catesandrew/mcp-agent-bridge)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check