clervo/clervo (clervo/clervo) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.

C
Caution
74/100
27 days ago

clervo/clervo

A stdio MCP server backed by the TypeScript SDK that exposes frozen Clervo operations for web search and answer functionality, enabling agents to find and understand information through a clean-room outcome infrastructure.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

clervo

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
5 flows detected: GROQ_API_KEY, BRAVE_SEARCH_API_KEY, R2_ACCESS_KEY_ID. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 22 credentials: BLOCKSCOUT_API_KEY, BRAVE_SEARCH_API_KEY, CDP_API_KEY_SECRET, CLERVO_AI_API_KEY, CLERVO_RECOVERY_IDEMPOTENCY_KEY, CLERVO_STAGING_IDENTITY_TOKEN, CLERVO_X402_PROOF_IDEMPOTENCY_KEY, CLOUDFLARE_AI_TOKEN, CLOUDFLARE_API_TOKEN, DEEPGRAM_API_KEY, DEVTO_API_KEY, DRPC_API_KEY, GITLAB_TOKEN, GROQ_API_KEY, HASHNODE_API_KEY, HELIUS_API_KEY, MISTRAL_API_KEY, R2_SECRET_ACCESS_KEY, SERPER_API_KEY, TELEGRAM_BOT_TOKEN, WORKOS_API_KEY, ZERION_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretBLOCKSCOUT_API_KEY
🔐 secretBRAVE_SEARCH_API_KEY
configCDP_API_KEY_ID
🔐 secretCDP_API_KEY_SECRET
configCDP_X402_FACILITATOR_URL
🔐 secretCLERVO_AI_API_KEY
configCLERVO_AI_BASE_URL
configCLERVO_BASE_URL
configCLERVO_CLOUD_ACCEPTANCE
configCLERVO_CLOUD_BUILD_CONFIRM
configCLERVO_DATABASE_MIGRATION_CONFIRM
configCLERVO_DATABASE_URL
configCLERVO_ENV
configCLERVO_EXPECTED_RELEASE_SHA
configCLERVO_GCP_IAM_CONFIRM
configCLERVO_HTTP_HOST
configCLERVO_HTTP_PORT
configCLERVO_KUBECTL_BIN
configCLERVO_MANAGED_MIGRATION_CONFIRM
configCLERVO_MIGRATION_IMAGE
configCLERVO_N427R_BROWSER_KILL_SWITCH
configCLERVO_N427R_CERTIFICATE_SPKI
configCLERVO_N427R_EXPECTED_MARKER
configCLERVO_N427R_GATEWAY
configCLERVO_N427R_IMPLEMENTATION_DIGEST
configCLERVO_N427R_TARGET_URL
configCLERVO_N427S_BROWSER_KILL_SWITCH
configCLERVO_N427S_EXPECTED_MARKER
configCLERVO_N427S_GATEWAY
configCLERVO_N427S_GATEWAY_ALLOWED_HOSTS
configCLERVO_N427S_GATEWAY_MAXIMUM_ACTIVE
configCLERVO_N427S_IMAGE_DIGEST
configCLERVO_N427S_IMPLEMENTATION_DIGEST
configCLERVO_N427S_MARKER_MODE
configCLERVO_N427S_TARGET_URL
configCLERVO_N427T_BROWSER_KILL_SWITCH
configCLERVO_N427T_EXPECTED_MARKER
configCLERVO_N427T_FINAL_EXECUTION
configCLERVO_N427T_FIXTURE_BASE_URL
configCLERVO_N427T_FIXTURE_SPKI_SHA256
configCLERVO_N427T_GATEWAY
configCLERVO_N427T_IMPLEMENTATION_DIGEST
configCLERVO_N427T_MARKER_MODE
configCLERVO_N427T_POLICY_DIGEST
configCLERVO_N427T_TARGET_URL
🔐 secretCLERVO_RECOVERY_IDEMPOTENCY_KEY
configCLERVO_RECOVERY_PROXY_HOST
configCLERVO_RECOVERY_PROXY_PORT
configCLERVO_RECOVERY_TARGET
configCLERVO_RELEASE_ID
configCLERVO_RETENTION_CONFIRM
configCLERVO_SANDBOX_CAPACITY_CONFIRM
configCLERVO_SANDBOX_COMPONENT
configCLERVO_SANDBOX_CONNECTIVITY_CONFIRM
configCLERVO_SANDBOX_IMAGE
configCLERVO_SANDBOX_IMAGE_REFERENCE
configCLERVO_SANDBOX_PRODUCTION_CONFIRM
configCLERVO_SANDBOX_QUALIFICATION_ACK
configCLERVO_SANDBOX_QUALIFICATION_CLUSTER
configCLERVO_SANDBOX_QUALIFICATION_REPORT_PATH
configCLERVO_SANDBOX_QUALIFICATION_SUITE
configCLERVO_SANDBOX_SECRET_CONFIRM
configCLERVO_SENTRY_DELIVERY_CONFIRM
configCLERVO_SENTRY_DSN_SECRET_VERSION
configCLERVO_SITE_ORIGIN
configCLERVO_STAGE4_COMMERCE_ORIGIN
configCLERVO_STAGE4_EXPECTED_MARKER
configCLERVO_STAGE4_FIXTURE_SPKI_SHA256
configCLERVO_STAGE4_GATEWAY
configCLERVO_STAGE4_HOSTILE_RUNS
configCLERVO_STAGE4_JAVASCRIPT_RUNS
configCLERVO_STAGE4_MARKER_MODE
configCLERVO_STAGE4_TARGET_URL
configCLERVO_STAGING_EVIDENCE_PATH
🔐 secretCLERVO_STAGING_IDENTITY_TOKEN
configCLERVO_STAGING_ORIGIN
configCLERVO_STATE_NAMESPACE
configCLERVO_STUDIO_MODULE_ROOT
configCLERVO_STUDIO_TMUX_CONFIG
configCLERVO_X402_BOOTSTRAP_CONFIRM
configCLERVO_X402_NEW_PAY_TO
configCLERVO_X402_PROOF_DEPLOY_CONFIRM
configCLERVO_X402_PROOF_DISABLE_CONFIRM
🔐 secretCLERVO_X402_PROOF_IDEMPOTENCY_KEY
configCLERVO_X402_PROOF_IDENTITY_AUDIENCE
configCLERVO_X402_PROOF_PAYER
configCLERVO_X402_PROOF_PAY_TO
configCLERVO_X402_PROOF_PORT
configCLERVO_X402_PROOF_TARGET_ORIGIN
configCLERVO_X402_RECEIVER_ROTATION_CONFIRM
configCLERVO_X402_SOURCE_ENV_FILE
configCLOUDFLARE_ACCOUNT_ID
🔐 secretCLOUDFLARE_AI_TOKEN
🔐 secretCLOUDFLARE_API_TOKEN
configCLOUDFLARE_BENCHMARK_MODELS
configCLOUDFLARE_QUALIFICATION_MODELS
configCODEX_HOME
🔐 secretDEEPGRAM_API_KEY
🔐 secretDEVTO_API_KEY
🔐 secretDRPC_API_KEY
configDRPC_QUALIFICATION_SAMPLES
configGH_TOKEN_1
🔐 secretGITLAB_TOKEN
🔐 secretGROQ_API_KEY
configGROQ_BENCHMARK_MODELS
🔐 secretHASHNODE_API_KEY
🔐 secretHELIUS_API_KEY
configHELIUS_RPC
configKUBECONFIG
🔐 secretMISTRAL_API_KEY
configOWNED_BENCHMARK_MODELS
configOWNED_BENCHMARK_SOURCE
configR2_ACCESS_KEY_ID
configR2_BUCKET_NAME
configR2_S3_ENDPOINT
🔐 secretR2_SECRET_ACCESS_KEY
configR2_USE_DERIVED_ACCOUNT_ENDPOINT
configSECRET_SCAN_BASE_SHA
configSECRET_SCAN_HEAD_SHA
configSECRET_SCAN_SKIP_HISTORY
configSECRET_SCAN_SOURCE_ARCHIVE
🔐 secretSERPER_API_KEY
🔐 secretTELEGRAM_BOT_TOKEN
🔐 secretWORKOS_API_KEY
🔐 secretZERION_API_KEY
configCLERVO_N426_BROWSER_KILL_SWITCH
configCLERVO_N426_TARGET_URL
configCLERVO_N426_GATEWAY
configCLERVO_N427_BROWSER_KILL_SWITCH
configCLERVO_N427_TARGET_URL
configCLERVO_N427_GATEWAY
configCLERVO_N427_EXPECTED_MARKER
configCLERVO_N427_IMAGE_DIGEST
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool inputs are validated

Only 0/2 tool handlers declare input schemas (0%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 0/2 tool handlers wrap calls in try/catch (0%)

Wrap each tool handler body in try/catch and return a structured error response.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Shell command execution

6 child_process calls — runs shell commands

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets stay with their owner

1 secret/sensitive value flow into network calls (R2_ACCESS_KEY_ID → dynamic) (4 other flows matched canonical API hosts)

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Secrets not logged

1 secret value sent to console.log

Redact or omit secret values from log output.

No arbitrary install scripts

Has postinstall/preinstall script — runs arbitrary code on npm install

Remove postinstall/preinstall hooks unless they’re essential.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/clervo-clervo-1urjxf?variant=verified)](https://m8ven.ai/mcp/clervo-clervo-1urjxf)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 47dd8ac718ca99925540e424d0b96f041ce3320e
code hash: 392d9086b207852e17554beeb0ccd96bd3d539c9702b6d54a1643e8e40883144
verified: 8/4/2026, 9:02:15 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client