dns-aid-core (dns-aid/dns-aid-core) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: there is no public source to read and no endpoint we can reach, so there is nothing for us to inspect. No publisher has claimed this listing.

C
Emerging
74/100
8 days ago

dns-aid-core

DNS-based Agent Identification and Discovery - Reference Implementation for IETF BANDAID

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

dns-aid

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
22 tools verified — handlers match their declared behaviour
11 read-only tools verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 8 credentials: AKAMAI_CLIENT_TOKEN, AKAMAI_CLIENT_SECRET, AKAMAI_ACCESS_TOKEN, CLOUDFLARE_API_TOKEN, DDNS_KEY_SECRET, NS1_API_KEY, NIOS_PASSWORD, INFOBLOX_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configDNS_AID_BACKEND
configDNS_AID_POLICY_MODE
configGITHUB_ACTIONS
configDNS_AID_DOCTOR_DOMAIN
configAKAMAI_EDGERCNo ~/.edgerc Path to .edgerc credentials file
configAKAMAI_HOSTNo - EdgeGrid API hostname (e.g., akab-xxxx.luna.akamaiapis.net)
🔐 secretAKAMAI_CLIENT_TOKENNo - EdgeGrid client token
🔐 secretAKAMAI_CLIENT_SECRETNo - EdgeGrid client secret
🔐 secretAKAMAI_ACCESS_TOKENNo - EdgeGrid access token
configAKAMAI_EDGERC_SECTIONNo default Section within .edgerc to use
configGOOGLE_CLOUD_PROJECT
configGCP_PROJECT
configCLOUD_DNS_PROJECT
configCLOUD_DNS_MANAGED_ZONE
🔐 secretCLOUDFLARE_API_TOKENYes - API token with DNS edit permissions
configCLOUDFLARE_ZONE_IDNo - Zone ID (auto-discovered if not set)
configDDNS_SERVERYes - DNS server hostname or IP
configDDNS_PORTNo 53 DNS server port
configDDNS_TIMEOUT
configDDNS_KEY_NAMEYes - TSIG key name
🔐 secretDDNS_KEY_SECRETYes - TSIG key secret (base64)
🔐 secretNS1_API_KEY
configNS1_BASE_URL
configROUTE53_ZONE_ID
configAWS_REGION
configDNS_AID_LEGACY_01_FALLBACK
configDNS_AID_SDK_HTTP_PUSH_URL
configDNS_AID_POLICY_CACHE_TTL
configDNS_AID_CALLER_DOMAIN
configDNS_AID_SVCB_STRING_KEYS
configDNS_AID_DANE_ALLOWED_PORTS
configDNS_AID_SDK_TIMEOUT
configDNS_AID_SDK_MAX_RETRIES
configDNS_AID_SDK_CALLER_ID
configDNS_AID_SDK_OTEL_ENABLEDotel_enabled=True (or =true) to emit spans +
configDNS_AID_SDK_OTEL_ENDPOINT
configDNS_AID_SDK_OTEL_EXPORT_FORMAT
configDNS_AID_SDK_OTEL_SAMPLER
configDNS_AID_SDK_OTEL_ENVIRONMENT
configDNS_AID_SDK_OTEL_METRIC_LABELS
configDNS_AID_SDK_CONSOLE_SIGNALS
configDNS_AID_SDK_DIRECTORY_API_URLCan also be set via .
configDNS_AID_SDK_TELEMETRY_API_URL
configDNS_AID_CIRCUIT_BREAKER
configDNS_AID_CIRCUIT_BREAKER_THRESHOLD
configDNS_AID_CIRCUIT_BREAKER_COOLDOWN
configDNS_AID_CREDENTIAL_PROVIDER_TIMEOUT
configDNS_AID_LOG_STREAM
configDNS_AID_LOG_LEVEL
configDNS_AID_SSRF_RESOLVER_THREADS
configDNS_AID_FETCH_ALLOWLIST
🔐 secretNIOS_PASSWORD
🔐 secretINFOBLOX_API_KEYYes - Infoblox UDDI API key from Cloud Portal
configINFOBLOX_BASE_URLNo https://csp.infoblox.com API base URL
configINFOBLOX_DNS_VIEWNo default DNS view name (zones exist within views)
configNIOS_HOST
configNIOS_USERNAME
configNIOS_WAPI_VERSION
configNIOS_VERIFY_SSL
configNIOS_DNS_VIEW
configNIOS_TIMEOUT
configOTEL_TRACES_SAMPLER
configOTEL_TRACES_SAMPLER_ARG
// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/dns-aid-dns-aid-core-12jun1)](https://m8ven.ai/mcp/dns-aid-dns-aid-core-12jun1)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: e3adf8b2f2b7d2ddb61e36f61b65b0a19261887b
code hash: fd0aed5158a36bfade8ec4a026e4d66127a188bc9fc0c3e907278478a38e54b8
verified: 8/18/2026, 9:21:43 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client