caura (caura-ai/caura) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it yet. No publisher has claimed this listing.

D
Warning
45/100

caura

Caura (formerly MemClaw) — governed shared memory for AI agent fleets. Multi-agent, multi-tenant, MCP-native. Trust tiers, keystone policies, audit trails, knowledge graph, self-improving retrieval. Apache 2.0.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

caura-ai

Source: Glama · also listed on github_topic, github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: OPENAI_API_KEY, GOOGLE_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Reads files from sensitive locations
Touches: /tmp/e2e.env
🔐
You'll be asked for 10 credentials: OPENAI_API_KEY, GOOGLE_API_KEY, CORE_STORAGE_SHARED_SECRET, CAURA_API_KEY, PLATFORM_EMBEDDING_API_KEY, ANTHROPIC_API_KEY, OPENROUTER_API_KEY, GEMINI_API_KEY, PLATFORM_LLM_API_KEY, RANK_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configTESTING
configUVICORN_ACCESS_LOG
🔐 secretOPENAI_API_KEY
🔐 secretGOOGLE_API_KEY
🔐 secretCORE_STORAGE_SHARED_SECRETSet the same non-empty on core-api, every
configMEMCLAW_RUN_DESTRUCTIVE_MIGRATIONS
🔐 secretCAURA_API_KEY
configENTITY_EXTRACTION_PROVIDER
configGITHUB_EVENT_NAME
configGITHUB_EVENT_PATH
configGITHUB_ACTIONS
configPLATFORM_EMBEDDING_PROVIDER
🔐 secretPLATFORM_EMBEDDING_API_KEY
configPLATFORM_EMBEDDING_BASE_URL
configPLATFORM_EMBEDDING_TRUNCATE_TO_DIM
configPLATFORM_EMBEDDING_MODEL
configOPENAI_EMBEDDING_BASE_URL
configEMBEDDING_QUERY_INSTRUCTION
configOPENAI_EMBEDDING_TRUNCATE_TO_DIM
configLOCAL_EMBEDDING_MODEL
configEMBEDDING_PROVIDER
configOPENAI_EMBEDDING_MODEL
configEMBEDDING_RETRY_ATTEMPTS
configEMBEDDING_RETRY_DELAY_S
configEVENT_BUS_BACKEND
configGCP_PROJECT_ID
configEVENT_BUS_SUBSCRIPTION_PREFIX
configEVENT_BUS_TOPIC_PREFIX
configEVENT_BUS_DUAL_SUBSCRIBE
configEVENT_BUS_ENV
configENVIRONMENT
configEVENT_BUS_PUBSUB_MAX_MESSAGES
🔐 secretANTHROPIC_API_KEY
🔐 secretOPENROUTER_API_KEY
🔐 secretGEMINI_API_KEY
configENTITY_EXTRACTION_MODEL
configPLATFORM_LLM_PROVIDER
configPLATFORM_LLM_GCP_PROJECT_ID
configPLATFORM_LLM_GCP_LOCATION
configPLATFORM_LLM_MODEL
🔐 secretPLATFORM_LLM_API_KEY
configLLM_FALLBACK_MODEL_OPENAI
🔐 secretRANK_API_KEY
configRANK_PROVIDER
configRANK_ENABLED
configRANK_MODEL
configRANK_MAX_LENGTH
configRANK_BASE_URL
configRANK_TIMEOUT_SECONDS
configRANK_RETRY_ATTEMPTS
configRANK_RETRY_DELAY_S
configRANK_CANDIDATE_LIMIT
configRANK_REMOTE_MAX_BATCH
// quality suggestions

No access to sensitive paths

Reads sensitive paths: /tmp/e2e.env

Remove reads of sensitive system paths. If you genuinely need them, document why in the README.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/caura-ai/caura?variant=verified)](https://m8ven.ai/mcp/caura-ai/caura)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: daa3e63f28104266378f06b74a16a4fbdf465c48
code hash: d1d48d202b84662357f5948aa2c2c6a8e918f8ab1a4161d24530bd23376c8c85
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client