C
Emerging
74/100
18 days ago

Arch AI Tools

Provides 63 production-ready API tools for AI agents, including web scraping, AI generation, crypto data, OCR, image generation, audio transcription, text-to-speech, email, and domain lookup.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Deesmo

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
6 flows detected: ANTHROPIC_API_KEY, ELEVENLABS_API_KEY, RUNWAY_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 33 credentials: ADMIN_KEY, ANTHROPIC_API_KEY, ARCHTOOLS_API_KEY, ARCH_API_KEY, ARCH_TOOLS_API_KEY, BRAVE_SEARCH_API_KEY, CDP_API_KEY, CDP_API_KEY_SECRET, CDP_API_SECRET, CDP_WALLET_SECRET, COINGECKO_API_KEY, CRYPTOPANIC_API_KEY, ELEVENLABS_API_KEY, EXA_API_KEY, FACILITATOR_PRIVATE_KEY, FIRECRAWL_API_KEY, GOOGLE_API_KEY, HUNTER_API_KEY, JWT_SECRET, OPENAI_API_KEY, PAYER_PRIVATE_KEY, POSTHOG_API_KEY, POSTMARK_SERVER_TOKEN, REMOVEBG_API_KEY, RESEND_API_KEY, RUNWAY_API_KEY, SERPER_API_KEY, STABILITY_API_KEY, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, TAVILY_API_KEY, UNSUBSCRIBE_SECRET, XAI_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configACTIVE_WINDOW_DAYS
🔐 secretADMIN_KEY
configADMIN_NOTIFY_EMAIL
configAI_ALLOWED_MODELS
configAI_MAX_PROMPT_CHARS
configAI_MAX_SYSTEM_CHARS
configAI_MAX_TOKENS
configAI_TIMEOUT_MS
configALGORAND_WALLET_ADDRESS
configALLOW_CUSTOM_EMAIL_FROM
🔐 secretANTHROPIC_API_KEY
configAPTOS_WALLET_ADDRESS
configARBITRUM_RPC_URL
🔐 secretARCHTOOLS_API_KEY
configARCHTOOLS_BASE_URL
configARCH_ALERT_AUTH_FAIL_THRESHOLD
configARCH_ALERT_AUTH_FAIL_WINDOW_MS
configARCH_ALERT_COOLDOWN_MS
configARCH_ALERT_CREDIT_DRAIN_THRESHOLD
configARCH_ALERT_CREDIT_DRAIN_WINDOW_MS
configARCH_ALERT_DISCORD_WEBHOOK
configARCH_API_BASE_URL
🔐 secretARCH_API_KEY"": "arch_your_key_here"
🔐 secretARCH_TOOLS_API_KEY
configARCH_TOOLS_URL
configAVALANCHE_RPC_URL
configBASE_RPC_URL
configBASE_SEPOLIA_RPC
configBNB_WALLET_ADDRESS
🔐 secretBRAVE_SEARCH_API_KEY
configBUSINESS_ADDRESS
🔐 secretCDP_API_KEY
configCDP_API_KEY_ID
🔐 secretCDP_API_KEY_SECRET
🔐 secretCDP_API_SECRET
configCDP_PROJECT_ID
🔐 secretCDP_WALLET_SECRET
configCHAT_GLOBAL_HOURLY_CAP
🔐 secretCOINGECKO_API_KEY
configCONFIRM_SEND
configCORS_ORIGIN
🔐 secretCRYPTOPANIC_API_KEY
🔐 secretELEVENLABS_API_KEY
configEMAIL_FROM
configEMAIL_RECIPIENT_DAILY_CAP
configETH_RPC_URL
configETH_WALLET_ADDRESS
🔐 secretEXA_API_KEY
configEXCLUDE_EMAIL_DOMAINS
configEXTRACT_PDF_MAX_BYTES
configEXTRACT_PDF_MAX_PAGES
configFACILITATOR_FEE_PERCENT
🔐 secretFACILITATOR_PRIVATE_KEY
🔐 secretFIRECRAWL_API_KEY
configFREE_MONTHLY_CREDITS
🔐 secretGOOGLE_API_KEY
🔐 secretHUNTER_API_KEY
🔐 secretJWT_SECRET
configLOG_RETENTION_DAYS
configLOW_CREDIT_THRESHOLD
configMCP_ANON_DAILY_LIMIT_GLOBAL
configMCP_ANON_DAILY_LIMIT_PER_IP
configMCP_DEMO_EMAIL
configMCP_DEMO_FLOOR
configMCP_DEMO_MONTHLY_CAP
configMCP_DEMO_TARGET
configMCP_SSE_PORT
configMCP_TRANSPORT
configMIN_CALLS
configNEAR_WALLET_ADDRESS
configNOBLE_WALLET_ADDRESS
🔐 secretOPENAI_API_KEY
configOPTIMISM_RPC_URL
configPARTITION_PRECREATE_MONTHS
🔐 secretPAYER_PRIVATE_KEY
configPDF_EXTRACTOR_URL
configPOLKADOT_WALLET_ADDRESS
configPOLYGON_RPC_URL
🔐 secretPOSTHOG_API_KEY
configPOSTHOG_HOST
🔐 secretPOSTMARK_SERVER_TOKEN
configPUBLIC_SITE_URL
configRATE_LIMIT_BUSINESS
configRATE_LIMIT_FREE
configRATE_LIMIT_PRO
configREFERRAL_DAILY_CAP
configREFERRAL_REWARD_CREDITS
🔐 secretREMOVEBG_API_KEY
🔐 secretRESEND_API_KEY
🔐 secretRUNWAY_API_KEY
configRUNWAY_VIDEO_MODEL
configSCRAPE_MAX_BYTES
configSCRAPE_MAX_REDIRECTS
configSCRAPE_MAX_SELECTOR_LEN
configSCRAPE_MAX_URL_LEN
configSECURITY_GATE_MAX_HIGH
configSEND_DELAY_MS
configSEND_LIMIT
🔐 secretSERPER_API_KEY
configSESSION_CONTEXT_MAX_CHARS
configSIGNUP_FREE_CREDITS
configSIGNUP_MAX_PER_EMAIL
configSIGNUP_MAX_PER_IP_PER_DAY
configSIGNUP_STARTER_CREDITS
configSOLANA_WALLET_ADDRESS
configSOL_BASE_WALLET_ADDRESS
configSOL_NATIVE_WALLET_ADDRESS
🔐 secretSTABILITY_API_KEY
configSTELLAR_WALLET_ADDRESS
configSTELLAR_WALLET_MEMO
configSTRIPE_PRICE_BUSINESS
configSTRIPE_PRICE_PRO
configSTRIPE_PRICE_STARTER
configSTRIPE_PRICE_SUB_BUSINESS_MONTHLY
configSTRIPE_PRICE_SUB_BUSINESS_MONTHLY_V2
configSTRIPE_PRICE_SUB_GROWTH_MONTHLY
configSTRIPE_PRICE_SUB_PRO_MONTHLY
configSTRIPE_PRICE_SUB_STARTER_MONTHLY
configSTRIPE_PRICE_SUB_STARTER_MONTHLY_V2
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
configSUI_WALLET_ADDRESS
configTAO_WALLET_ADDRESS
🔐 secretTAVILY_API_KEY
configTOOL_TIMEOUT_MS
configTOPUP_MIN_CREDITS
configTRANSCRIBE_MAX_AUDIO_BYTES
configTRIAL_CREDITS
configUNI_WALLET_ADDRESS
🔐 secretUNSUBSCRIBE_SECRET
configUSDT_ETH_WALLET_ADDRESS
configVERIFY_RESEND_COOLDOWN_MS
configVERIFY_RESEND_MAX_PER_HOUR
configVIDEO_HOURLY_CAP
configWALLET_ADDRESS
configX402_FACILITATOR_URL
configX402_NETWORK
🔐 secretXAI_API_KEY
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployDATABASE_URL
deployNEXT_PUBLIC_API_BASE
deployNEXT_PUBLIC_POSTHOG_HOST
deployNEXT_PUBLIC_POSTHOG_KEY
deployPORT
deployREDIS_URL
deploySENTRY_DSN
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

2/2 tools missing one or more hints — _archbase (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); archtoolbase (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tool test coverage

Only 0/2 tools referenced in tests (0%)

Write tests that reference each tool by name so every tool has at least one test.

Shell command execution

6 child_process calls — runs shell commands

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/deesmo-arch-ai-tools-1tmwy5)](https://m8ven.ai/mcp/deesmo-arch-ai-tools-1tmwy5)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 15150b1d51440683ae3903709b26715a36b4d296
code hash: 1c4af120c285dc255ceb25f26f53f33a218c0053ab546fde15f21a8890ddd254
verified: 8/1/2026, 8:42:59 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client