mantisbt-mcp-server (dpesch/mantisbt-mcp-server) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.
Mirror of codeberg.org/dpesch/mantisbt-mcp-server — issues and PRs not monitored
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
dpesch
Source: npm · also listed on Glama, github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
MANTIS_API_KEYAPI token for authenticationMANTIS_BASE_URLBase URL of your MantisBT installation. Both https://your-mantis.example.com and https://your-mantis.example.com/api/rest are accepted — the /api/rest suffix is normalized automatically.MANTIS_CACHE_DIRDirectory for the metadata cacheMANTIS_CACHE_TTLCache lifetime in secondsMANTIS_SEARCH_BACKENDVector store backend: vectra (pure JS) or sqlite-vec (requires manual install)MANTIS_SEARCH_DIRDirectory for the search indexMANTIS_SEARCH_ENABLEDSet to true to enable semantic searchMANTIS_SEARCH_MODELEmbedding model name (downloaded once on first use, ~80 MB)MANTIS_SEARCH_THREADSNumber of ONNX intra-op threads for the embedding model. Default is 1 to prevent CPU saturation on multi-core machines and WSL. Increase only if index rebuild speed matters and the host is dedicated to this workload.MANTIS_UPLOAD_DIRRestrict upload_file's file_path to files within this directory (path traversal via ../ is blocked). In stdio mode file_path is unrestricted unless this is set. In HTTP mode file_path reads from the server's filesystem, so it is disabled unless this variable is set — HTTP clients should upload via the content (Base64) parameter instead.MANTIS_USE_INDEX_PHPSet to true when URL rewriting is unavailable — REST requests then use /api/rest/index.php/ instead of /api/rest/. Detected automatically when MANTIS_BASE_URL ends with /api/rest/index.php; an explicit value always wins. See the [cookbook](docs/cookbook.md#connect-to-an-installation-without-url-rewriting).MCP_HTTP_HOSTBind address for HTTP mode. Changed from 0.0.0.0 to 127.0.0.1 — the server now listens on localhost only by default. Set to 0.0.0.0 for Docker or remote access.MCP_HTTP_TOKENBearer token for the /mcp endpoint (Authorization: Bearer <token>). Required when TRANSPORT=http — the server refuses to start in HTTP mode without it, so tools are never exposed unauthenticated. Ignored in stdio mode. The /health endpoint is always public.MCP_TEST_ENVIRONMENTTRANSPORTTransport mode: stdio or httpPORTAll four hints declared on every tool
37/37 tools missing one or more hints — search_issues (missing: openWorldHint); get_search_index_status (missing: openWorldHint); rebuild_search_index (missing: openWorldHint), +34 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/npm-https-github-com-dpesch-mantisbt-mcp-server)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check