Kith-space (CKang-J/Kith-space) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 55 tools. No publisher has claimed this listing.

C
Caution
74/100

Kith-space

面向个人的本地多 Agent 协同工作空间。与拥有独立身份与持久记忆的 AI 队友深度协作:频道分工、任务指派、无限矢量画布与原生 MCP。A local-first multi-agent collaborative workspace.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

CKang-J

Source: github_topic

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: KITH_SPACE_AGENT_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 1 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 2 credentials: KITH_SPACE_AGENT_TOKEN, KITH_SPACE_INTRODUCTION_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes55 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

session.context_check

Read only the authoritative active-turn inputs; optionally refresh later surface refs.

turn.reply

Commit a server-targeted Chat reply and settle the listed input obligations.

turn.cede

Cede optional inputs with an explicit reason.

turn.progress

Record bounded progress for the active turn.

turn.get

Inspect the active turn, attempts, context, operations, usage, and outcome.

session.checklist_list

List the current surface session checklist.

session.checklist_upsert

Create or CAS-update a current surface session checklist item.

session.checklist_complete

CAS-complete a current surface session checklist item.

session.checklist_clear

Clear checklist items in the current surface session.

session.schedule_wakeup

Schedule a one-shot wake of this surface session in 60–3600 seconds.

conversation.read

Read an ACL-checked conversation and audit the later query.

conversation.search

Search ACL-checked current Agent conversations and audit returned sources.

memory.recall

Recall disclosure-projected episodic memory for the active output surface.

memory.get

Get one accessible episodic-memory revision by opaque id.

task.list

List tasks in one currently accessible channel.

task.get

Read one currently accessible task and its linked reports/deliveries.

task.create

Create one idempotent task in an accessible channel.

task.claim

Idempotently claim an accessible task for the current Agent.

task.update

CAS-update an accessible task status.

task.assign

CAS-handoff an accessible task to another Agent.

task.unclaim

CAS-release the current Agent's task claim.

task.report

Post one idempotent structured report to the task thread.

task.deliver

Publish an idempotent delivery summary and move the task to in_review.

capability.describe

Describe the active kith-core capability mode and scopes.

canvas.snapshot_get

Read the authorized immutable Canvas Selection Snapshot for this turn.

canvas.elements_get

Read live authorized Canvas elements/Frames within the current grant.

canvas.elements_apply

Map Recombyn ToolOps onto Canvas Core under the current grant and CAS revision.

canvas.export

Export the authorized immutable Selection Snapshot as a Canvas side effect.

canvas.context_bundle_create

Create a bounded Canvas context bundle from the authorized snapshot.

canvas.asset_import

Import a turn-bound local attachment into the authorized Canvas asset store.

canvas.scene_summary
canvas.skill_list
canvas.skill_get
canvas.design_review
canvas.generation_status
canvas.create_frame
canvas.create_text
canvas.create_shape
canvas.create_image
canvas.create_svg
canvas.create_icon
canvas.update_node
canvas.delete_nodes
canvas.delete_frame
canvas.update_frame
canvas.align_nodes
canvas.distribute_nodes
canvas.reorder_nodes
canvas.group_nodes
canvas.ungroup_nodes
canvas.duplicate_nodes
canvas.flip_nodes
canvas.boolean_op
canvas.set_canvas_background
canvas.video_generate
// known CVEs in dependencies1 high5 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highundici@7.28.0GHSA-4cwx-7wf7-3272

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

lowundici@7.28.0GHSA-8xcm-r25x-g524

undici vulnerable to downstream response desynchronization via retry interceptor

lowundici@7.28.0GHSA-jr45-8vmc-qm54

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

lowundici@7.28.0GHSA-m8rv-5g2x-5cg5

undici vulnerable to CRLF Injection via blob-like body 'type' property

lowundici@7.28.0GHSA-v3r7-h72x-cjcm

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configComSpec
configDAEMON_VERSION
configENV_FILE
configHERMES_PROFILE_DIR
configKITH_CANVAS_AGENT_EXECUTION
configKITH_SPACE_ACTIVATION_FILE
configKITH_SPACE_AGENT_ID
🔐 secretKITH_SPACE_AGENT_TOKEN
configKITH_SPACE_BROKER_HANDLE
configKITH_SPACE_DAEMON_SERVER_STALE_MS
configKITH_SPACE_DB
configKITH_SPACE_DELIVER_DEBOUNCE_MS
configKITH_SPACE_DESKTOP_DEV
configKITH_SPACE_DESKTOP_MANAGED
configKITH_SPACE_DESKTOP_SMOKE_EXIT_MS
configKITH_SPACE_DESKTOP_START_HIDDEN
configKITH_SPACE_HERMES_DELIVER_DEBOUNCE_MS
configKITH_SPACE_HOME
configKITH_SPACE_IDLE_MS
🔐 secretKITH_SPACE_INTRODUCTION_TOKEN
configKITH_SPACE_LOG_DIR
configKITH_SPACE_LOG_LEVEL
configKITH_SPACE_MIGRATIONS_DIR
configKITH_SPACE_ONE_SHOT_DELIVER_DEBOUNCE_MS
configKITH_SPACE_PENDING_DELIVER_TTL_MS
configKITH_SPACE_REPO_ROOT
configKITH_SPACE_RUNTIME_CAPACITY
configKITH_SPACE_RUNTIME_QUEUE_LIMIT
configKITH_SPACE_RUNTIME_QUEUE_TTL_MS
configKITH_SPACE_RUNTIME_RESIDENT_LIMIT
configKITH_SPACE_SERVER_URL
configKITH_SPACE_SPACES_DIR
configKITH_SPACE_TURN_FILE
configKITH_SPACE_WEB_DIST
configSystemRoot
configVITE_PORT
configWINDIR
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

55/55 tools missing one or more hints — session.context_check (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); turn.reply (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); turn.cede (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +52 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

43/55 tools referenced in tests (78%)

Write tests that reference each tool by name so every tool has at least one test.

Secrets not logged

27 secret values sent to log/error

Redact or omit secret values from log output.

Production dependencies are patched

0 critical, 1 high severity in production deps — undici@7.28.0 (high), undici@7.28.0 (low)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/ckang-j/kith-space?variant=verified)](https://m8ven.ai/mcp/ckang-j/kith-space)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 5a3f1c5888559eef307edaea4cb4f77d44d755e2
code hash: 0f010eaa5d0a94a1c1b1d81a35b9712481bd6ee048e00aeaf03910988589925f
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client