mantisbt-mcp-server (dpesch/mantisbt-mcp-server) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.

C
Emerging
74/100
3 days ago

mantisbt-mcp-server

Mirror of codeberg.org/dpesch/mantisbt-mcp-server — issues and PRs not monitored

dpesch/mantisbt-mcp-server· npm: @dpesch/mantisbt-mcp-server· listed on npm

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

dpesch

Source: npm · also listed on Glama, github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
37 tools verified — handlers match their declared behaviour
23 read-only tools verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: MANTIS_API_KEY, MCP_HTTP_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretMANTIS_API_KEYAPI token for authentication
configMANTIS_BASE_URLBase URL of your MantisBT installation. Both https://your-mantis.example.com and https://your-mantis.example.com/api/rest are accepted — the /api/rest suffix is normalized automatically.
configMANTIS_CACHE_DIRDirectory for the metadata cache
configMANTIS_CACHE_TTLCache lifetime in seconds
configMANTIS_SEARCH_BACKENDVector store backend: vectra (pure JS) or sqlite-vec (requires manual install)
configMANTIS_SEARCH_DIRDirectory for the search index
configMANTIS_SEARCH_ENABLEDSet to true to enable semantic search
configMANTIS_SEARCH_MODELEmbedding model name (downloaded once on first use, ~80 MB)
configMANTIS_SEARCH_THREADSNumber of ONNX intra-op threads for the embedding model. Default is 1 to prevent CPU saturation on multi-core machines and WSL. Increase only if index rebuild speed matters and the host is dedicated to this workload.
configMANTIS_UPLOAD_DIRRestrict upload_file's file_path to files within this directory (path traversal via ../ is blocked). In stdio mode file_path is unrestricted unless this is set. In HTTP mode file_path reads from the server's filesystem, so it is disabled unless this variable is set — HTTP clients should upload via the content (Base64) parameter instead.
configMANTIS_USE_INDEX_PHPSet to true when URL rewriting is unavailable — REST requests then use /api/rest/index.php/ instead of /api/rest/. Detected automatically when MANTIS_BASE_URL ends with /api/rest/index.php; an explicit value always wins. See the [cookbook](docs/cookbook.md#connect-to-an-installation-without-url-rewriting).
configMCP_HTTP_HOSTBind address for HTTP mode. Changed from 0.0.0.0 to 127.0.0.1 — the server now listens on localhost only by default. Set to 0.0.0.0 for Docker or remote access.
🔐 secretMCP_HTTP_TOKENBearer token for the /mcp endpoint (Authorization: Bearer <token>). Required when TRANSPORT=http — the server refuses to start in HTTP mode without it, so tools are never exposed unauthenticated. Ignored in stdio mode. The /health endpoint is always public.
configMCP_TEST_ENVIRONMENT
configTRANSPORTTransport mode: stdio or http
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

All four hints declared on every tool

37/37 tools missing one or more hints — search_issues (missing: openWorldHint); get_search_index_status (missing: openWorldHint); rebuild_search_index (missing: openWorldHint), +34 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/npm-https-github-com-dpesch-mantisbt-mcp-server)](https://m8ven.ai/mcp/npm-https-github-com-dpesch-mantisbt-mcp-server)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 08ce5e50b44a0d431926812785f532d81dc425ad
code hash: ce732eee1d1412350d53b58acba83bed41969334cc49ff37c9e52fa014161efd
verified: 9/5/2026, 7:51:54 PM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client