F
Warning
32/100
20 hours ago

cortex-platform

Archived — Cortex platform monorepo: microservices, MCP servers, shared libraries, and agent coordination.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

cortex-io

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
3 flows detected: CLOUDFLARE_API_TOKEN, YOUTUBE_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Hardcoded credentials detected
1 live-looking API key in source: 1 Anthropic API key
🔐
You'll be asked for 13 credentials: ANTHROPIC_API_KEY, POSTGRES_PASSWORD, GITHUB_TOKEN, N8N_API_KEY, SANDFLY_PASSWORD, TAILSCALE_API_KEY, CLOUDFLARE_API_TOKEN, YOUTUBE_API_KEY, UNIFI_API_KEY, UNIFI_CONTROLLER_PASSWORD, REDIS_PASSWORD, SANDFLY_API_KEY, CORTEX_REDIS_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretANTHROPIC_API_KEY
configANTHROPIC_MODEL
configCACHE_DIR
configCHECKMK_MCP_URL
configCLOUDFLARE_MCP_URL
configCORTEX_ROOT
configCORTEX_URL
configEMBEDDER_PROVIDER
configHEALTH_PORT
configK8S_MCP_URL
configKNOWLEDGE_DIR
configLEARNING_ENABLED
configLOG_LEVEL
configN8N_MCP_URL
configPOSTGRES_DB
configPOSTGRES_HOST
🔐 secretPOSTGRES_PASSWORD
configPOSTGRES_PORT
configPOSTGRES_USER
configPROXMOX_MCP_URL
configQDRANT_COLLECTION_EXECUTIONS
configQDRANT_URL
configREDIS_ENABLED
configREDIS_HOST
configREDIS_PORT
configSANDFLY_MCP_URL
configSCHOOL_MCP_URL
configSSE_PORT
configTAILSCALE_MCP_URL
configTRANSCRIPTS_DIR
configUNIFI_MCP_URL
configVECTOR_STORE_PROVIDER
configWORKER_CONFIG
configWORKER_ID
configYOUTUBE_MCP_URL
configMCP_PORT
🔐 secretGITHUB_TOKEN
configGITHUB_ORG
configGITHUB_API_URL
configGITHUB_TIMEOUT
configK8S_IN_CLUSTER
configKUBECONFIG
configN8N_HOST
configN8N_PORT
🔐 secretN8N_API_KEY
configN8N_VERIFY_SSL
configN8N_TIMEOUT
configSANDFLY_HOST
configSANDFLY_USERNAME
🔐 secretSANDFLY_PASSWORD
configSANDFLY_VERIFY_SSL
🔐 secretTAILSCALE_API_KEY
configTAILSCALE_TAILNET
configLOG_FORMAT
configPOD_NAME
configPOD_NAMESPACE
configCONFIG_PATH
configAWARENESS_URL
configCOMMIT_RELAY_URL
configBLOG_REPO_PATH
configRELEVANCE_THRESHOLD
configGITHUB_USER_EMAIL
configGITHUB_USER_NAME
configPOLL_INTERVAL
🔐 secretCLOUDFLARE_API_TOKEN
configCLOUDFLARE_ACCOUNT_ID
configCLOUDFLARE_PROJECT_NAME
configCLOUDFLARE_VERIFY_DEPLOYMENT
configAUTO_APPROVE_THRESHOLD
configHIGH_RISK_THRESHOLD
configMOE_ROUTER_URL
configRAG_VALIDATOR_URL
configFABRIC_URL
configCORTEX_PLATFORM_PATH
configCLIENT_TYPE
configRECONNECT_DELAY
configHEARTBEAT_INTERVAL
configMCP_STDIO_MODE
configMEMORY_SERVICE_URL
configMCP_GATEWAY_URL
configSESSION_TIMEOUT_HOURS
configKUBERNETES_MCP_URL
configGITHUB_MCP_URL
configGITHUB_SECURITY_MCP_URL
configOUTLINE_MCP_URL
configYOUTUBE_INGESTION_MCP_URL
configYOUTUBE_CHANNEL_MCP_URL
configCORTEX_SCHOOL_MCP_URL
configPROMETHEUS_URL
configHEALTH_CHECK_DURATION
configROLLBACK_ENABLED
configGITHUB_REPO
configGITHUB_BRANCH
configCOMMIT_AUTHOR_NAME
configCOMMIT_AUTHOR_EMAIL
configWORKER_TYPE
configSTACK_CONFIG
configQDRANT_PORT
configCOST_TRACKER_URL
configLLMD_ENDPOINT
configMOE_CACHE_TTL
configEXPERT_ARCHITECTURE_MODEL
configEXPERT_INTEGRATION_MODEL
configEXPERT_SECURITY_MODEL
configEXPERT_DATABASE_MODEL
configEXPERT_NETWORKING_MODEL
configEXPERT_MONITORING_MODEL
configQUOTA_HISTORY_WINDOW
configWARNING_THRESHOLD
configCRITICAL_THRESHOLD
configEMBEDDING_MODEL
configSIMILARITY_THRESHOLD
🔐 secretYOUTUBE_API_KEY
configINGESTION_URL
configDAILY_LIMIT
configCHECK_INTERVAL
🔐 secretUNIFI_API_KEY
configLOCAL_THRESHOLD
configDMR_THRESHOLD
configCLAUDE_THRESHOLD
configCONFIDENCE_THRESHOLD
configDMR_ENDPOINT
configCLAUDE_MODEL
configMAX_EXECUTION_TIME
configALLOWED_MCP_SERVERS
configMAX_COST_PER_REQUEST
configDMR_MODEL
configDMR_CONTEXT_LENGTH
configDMR_TEMPERATURE
configUNIFI_CONTROLLER_HOST
configUNIFI_CONTROLLER_USERNAME
🔐 secretUNIFI_CONTROLLER_PASSWORD
configUNIFI_VERIFY_SSL
configCORTEX_ENABLED
configCORTEX_MCP_URL
configLARRY_ID
configPHASE
🔐 secretREDIS_PASSWORD
configCOORDINATION_PATH
configWORKER_COUNT
configTOKEN_BUDGET_PERSONAL
configTOKEN_BUDGET_WORKERS
configAGENT_ID
configMASTER_ID
🔐 secretSANDFLY_API_KEY
configQDRANT_COLLECTION_SELECTIONS
configQDRANT_COLLECTION_OUTCOMES
configEMBEDDING_SERVICE_URL
configEXPERT_GENERAL
configEXPERT_INFRA
configEXPERT_SECURITY
configEXPERT_AUTO
configTELEMETRY_ENABLED
configQDRANT_COLLECTION_ROUTING
configQDRANT_COLLECTION_EVALUATIONS
configCORTEX_REDIS_HOST
configCORTEX_REDIS_PORT
🔐 secretCORTEX_REDIS_PASSWORD
configENVIRONMENT
configAGENT_NAME
configCORTEX_TASK_STREAM
configCORTEX_RESULT_STREAM
configCORTEX_CONSUMER_GROUP
configQDRANT_COLLECTION_QUERIES
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
deployREDIS_URL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

133/133 tools missing one or more hints — kubectl (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_infrastructure_summary (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); proxmox_list_vms (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +130 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

No hardcoded API keys

1 live-looking API key in source: 1 Anthropic API key

Move secrets to environment variables (process.env.X) or your secret manager.

Tool test coverage

Only 13/133 tools referenced in tests (10%)

Write tests that reference each tool by name so every tool has at least one test.

Shell command execution

5 child_process/subprocess calls in production code — runs shell commands (services/mcp-servers/cortex/src/sse-server.js:64, lib/worker-pool/fifo-channel.js:38, lib/worker-pool/fifo-channel.js:39)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets never reach shell commands

3 secret values passed to shell commands — possible command injection

Never pass secrets through shell commands. Use library APIs that accept credentials as arguments.

Secrets not logged

9 secret values sent to console.log

Redact or omit secret values from log output.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/cortex-io-cortex-platform-17ppvj?variant=verified)](https://m8ven.ai/mcp/cortex-io-cortex-platform-17ppvj)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 21f913f466dded58fbf0a5723eba3785ec12e5e3
code hash: 71cf6b5594c58469b63ac77662279fbcdd989eebc64e5882a425f03bb8cd0052
verified: 8/19/2026, 4:05:55 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client