Reef (diepzee/reef) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. The publisher has proved control of what we score (Verified Publisher).

Grade pending
2 days ago

Reef

reef is a hosted remote MCP server that gives a group shared, long-term assistant memory: a private cove per person plus shared coves for a household, a trip, or a project, stored as human-editable Markdown pages with privacy enforced by Postgres row-level security. Works from Claude (including mobile), ChatGPT desktop, and Codex at https://reefwith.me/mcp, with a CLI on PyPI (reef-cli) and

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

rugvin.be (@diepzee) · Verified Publisher

Source: Glama

⚡ Upgrade to Live Monitored

Connect your repo and M8ven re-verifies it on the push itself. Without it we re-check verified listings about once a day, so a fix can sit unseen. Read-only, one click, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: REEF_ACCESS_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
Are you the publisher? Confirm or correct these findings.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretREEF_ACCESS_TOKEN
// quality suggestions

Domain consistency

npm scope @haai doesn't match GitHub owner diepzee

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/diepzee-reef-1sjg8x)](https://m8ven.ai/mcp/diepzee-reef-1sjg8x)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: bad8bd431567f7622991514bc4d5207e518ba229
code hash: ec5db4b28115090b18bfcd60e6a9e357247e1380538057b9f5491b0f8f56e321
verified: 9/6/2026, 7:33:45 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client