metis-ai (f1shyondrugs/metis-ai) is an MCP server listed on the M8ven Trust Index. It scores 40 out of 100, grade D. It declares 111 tools. No publisher has claimed this listing.
A private, self-hosted workspace for AI agents with tools, memory, browser control, MCP servers and multi-provider support.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
f1shyondrugs
Source: github_repo_search
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
provide_fileAttach a file to the current chat and make it available as a protected download link and preview. Whenever the user asks to attach, send, share, export, or provide a file, you MUST call provide_file; creating the file or mentioning its path is not enough. Call once for each file.
create_automationCreate a one-time or recurring autonomous agent automation. Every run gets its own persistent chat transcript and can use the same allowed tools, child MCPs, remote tools, and persistent Metis browser as a normal Agent-mode run. Recurring schedules can use minutes, days, or a calendar day each month…
list_automationsList the current user's automations, including creator, node graph, isolated persistent run chats, status, and recent runs.
update_automationUpdate an existing automation's name, prompt, context chat, models, maximum run duration, timezone, or schedule.
run_automationStart an automation immediately as a manual run. The run is isolated in its own persistent chat and does not replace the recurring schedule.
pause_automationPause an automation so it will not run until resumed.
resume_automationResume a paused automation.
delete_automationPermanently delete an automation and its run history.
write_todosCreate or replace a short in-chat checklist. Use only for work with 3+ distinct steps; skip it for a single edit. It appears in the message, not as a side-panel plan. Use create_plan only when the user asked for a plan document.
create_planCreate or replace a real Metis plan workspace in the current chat. Provide the complete plan content; a title alone is not sufficient.
create_canvasCreate or replace a real Metis canvas workspace in the current chat. Provide the complete canvas content; a title alone is not sufficient.
edit_planEdit an existing plan workspace in the current chat.
edit_canvasEdit an existing canvas workspace in the current chat.
update_chat_titleSet the current chat title.
update_chat_keywordsAdd concise, non-sensitive keywords to the current chat so it can be found later. Use this silently when the topic becomes clear or changes.
search_chatsSearch the signed-in user's chats by title, keywords, or message content.
context_searchSearch the owner's personal context hub: devices, servers, services, projects, preferences, and long-term facts. Use before answering questions about the user's setup, before planning changes to their infrastructure, or when background knowledge about the owner would change the answer. Returns groun…
context_profileRead the owner's canonical profile: identity, core preferences, infrastructure overview, and active projects. Cheaper than context_search when a general overview is enough.
context_rememberStore one durable, non-secret fact about the owner in the shared context hub (same fact_id updates the fact). Never store passwords, API keys, cookies, tokens, or auth material. Use sparingly for stable preferences and environment facts the owner confirmed.
list_notesList active shared notes in the current chat or workspace scope.
search_notesSearch shared notes by title or content.
create_noteCreate a shared note or project for the current chat. Use kind=project with todos for multi-chat planning. Deletion is intentionally not exposed to agents.
update_noteUpdate a shared note using optimistic version checking.
list_memoriesRetrieve the user's saved memories for the current account.
add_memoryAdd a durable memory for the current user. Only save useful user-approved facts or preferences.
edit_memoryEdit one existing memory by id for the current user.
delete_memoryDelete one existing memory by id for the current user.
list_workspacesList plan and canvas workspaces in the current chat.
delete_planDelete a plan workspace by id after confirmation.
delete_canvasDelete a canvas workspace by id after confirmation.
git_statusReturn git status for the agent workspace.
git_diffReturn the current unstaged git diff for the agent workspace.
browser_extract_textExtract readable text from the current browser page and all embedded frames. Use this instead of reloading or shell inspection.
browser_form_stateReturn structured form controls plus compact text from the page and embedded frames. Controls include a frame hint and stable selector. Prefer this over screenshots or shell/Playwright inspection for forms.
browser_batchExecute up to 100 browser actions in one round-trip, including embedded-frame controls. Use for repetitive form filling/clicking instead of one tool call per field.
browser_wait_forWait for a selector or visible text condition. Prefer this over fixed wait/sleep calls.
browser_fill_formFill a browser form field using a CSS selector.
browser_downloadTrigger a download from the current browser page by clicking a CSS selector.
browser_dragDrag an element to a target element (HTML5 and mouse-based drag & drop).
browser_hoverHover over an element by CSS selector (reveals hover menus and tooltips).
browser_select_optionSelect an option in a <select> dropdown by value.
browser_upload_fileUpload a local file into a file input on the current browser page.
gateway_statuslist_mcp_serversList the dynamic MCP registry. Disabled entries show integrations that still need authorization.
search_toolsSearch tools on enabled child MCP servers. Use only when you do not already know the gateway tool name (read_file, edit_file, execute_command, …). Do not call this at the start of ordinary tasks.
list_server_toolsList full tool schemas from one child MCP server.
call_mcp_toolCall any tool exposed by a registered child MCP server.
ask_userrequest_mode_changeRequired when the current mode cannot perform the user's requested action. Use the exact mode ID: agent for implementation/file changes, plan for read-only planning, or ask for read-only answers; custom mode IDs are supplied in the chat instructions. Opens a real confirmation prompt for switching th…
waitPause this agent for a bounded amount of time. Use this when work is expected to finish asynchronously; the wait always has a server-enforced maximum.
delegate_subagentSpawn a real provider-neutral Metis child agent with its own persistent chat/run. Use wait=false to launch independent workstreams in parallel, then subagent_status to collect them before final synthesis. The child inherits the parent mode policy, so delegation cannot bypass read-only restrictions.
subagent_statusInspect delegated subagents for this chat and optionally wait for a status change. Returns compact status data while preserving full tool logs in the chat.
ensure_capabilityFind an existing matching tool, or autonomously search the complete official MCP Registry, provision and probe the best supported MCP, then return its available tools. Use this when a requested capability is not already visible.
sync_agent_knowledgeWrite or update managed MCP instructions for AGENTS.md, CLAUDE.md, GEMINI.md, Copilot, Cursor, and OpenCode on the server, Windows PC, or laptop.
upsert_mcp_serverAdd or update a remote URL or stdio MCP server in the dynamic registry. The server remains centrally available through this gateway URL.
set_mcp_server_enabledEnable or disable one child MCP server.
web_searchSearch the current web through the local SearXNG instance first, with Exa as fallback. Suitable for current information, products, code, and research.
web_fetchFetch and extract one or more public read-only web pages. Uses the local Scrapling static scraper first for speed, then Exa as fallback. If a page requires login, interaction, JavaScript state, or a challenge, use the persistent browser_* tools instead.
browser_navigateNavigate the server-side browser to an allowed URL. The browser can reach server localhost URLs from the configured allowlist.
browser_snapshotReturn the current server-browser accessibility snapshot for selecting and understanding page elements.
browser_screenshotCapture the current server-browser page as a JPEG and return it to the agent. Use only when visual inspection is necessary.
browser_clickClick a page element by CSS selector, exact/partial visible text, or viewport coordinates. Selectors/text are searched across embedded frames automatically.
browser_typeFill a page input by selector or type at the current focus. Selectors are searched across embedded frames automatically.
browser_pressPress a keyboard key in the server browser.
browser_resizeSet the server-browser viewport resolution for the current tab.
browser_scrollScroll the current server-browser page vertically.
browser_tabsList and select tabs in the current server-browser session.
context7_resolveResolve a library name to the best Context7 library id before querying documentation.
context7_queryRetrieve current, version-specific library documentation from Context7.
system_infoGet system overview for the server, CachyOS laptop, or Windows PC.
execute_commandRun Bash on server/laptop or PowerShell on the Windows PC. Use dedicated Windows UI and Electron tools for visible desktop testing.
remote_client_terminalOpen and control a persistent shell session on a connected remote client. The session keeps its working directory and environment between calls.
list_remote_clientsList the connected remote clients belonging to the current account, including their IDs, capabilities, policy, and online status.
list_directoryList a directory on any device.
read_fileRead a UTF-8 text file from the server or a connected remote client. Prefer offset+limit around the relevant region instead of reading the whole file. For a client use target client:<remote-client-id>.
repo_searchSearch the persistent local repository index for relevant files, symbols, imports, and paths before broad filesystem exploration.
inspect_codebaseReturn compact indexed codebase findings for a query without dumping whole files.
verify_workProve work claims with real command output instead of asserting them. Each claim pairs a short label with a command and expected output markers; every command is executed and the result recorded in a per-job evidence ledger (see ledger_review). Use for 'tests pass', 'server is up', 'config applied' …
ledger_reviewRead the evidence ledger for the current job: every verify_work claim with verified/failed status. Use before reporting task completion so the summary cites real evidence.
audio_fingerprintIdentify or register audio Shazam-style: spectral landmark hashing against a local reference database. Actions: match (identify an audio file), ingest (register a reference track with title/artist), stats (database overview). Requires ffmpeg. Audio argument may be any file ffmpeg can decode.
find_symbolFind functions, classes, interfaces, types, and exported symbols through the persistent repository index.
write_fileCreate or overwrite a UTF-8 text file on the server or a connected remote client. For a client use target client:<remote-client-id>.
edit_fileReplace one exact oldText block with newText in a UTF-8 file on the server or a connected remote client. Pass the smallest unique snippet, never the whole file. For a client use target client:<remote-client-id>.
delete_fileDelete a file on the server or a connected remote client. For a client use target client:<remote-client-id>.
docker_psList Docker containers on a Linux device.
service_controlInspect, restart, start, stop, or read logs for a systemd service on server/laptop.
windows_uiInspect and control visible Windows applications through Microsoft's winapp UI Automation. Supports Electron, Win32, WPF, WinForms, and WinUI. Actions include list-windows, inspect, search, status, get-property, get-value, invoke, click, set-value, send-keys, focus, hover, scroll, wait-for, screensh…
windows_screenshotCapture a visible Windows app or UI element and return the PNG directly to the agent.
electron_testAnalyze, install, audit, lint, type-check, unit-test, E2E-test, build, package, launch, or comprehensively validate an Electron project on the Windows PC. Use full first, then launch and windows_ui/windows_screenshot for feature-by-feature visual validation.
windows_desktop_jobRun an arbitrary command inside the active interactive Windows desktop session. Use only when windows_ui or electron_test cannot express the operation.
workflow_saveSave a reusable workflow of allowlisted core gateway tool calls.
workflow_listList saved workflows.
workflow_getGet a saved workflow.
workflow_deleteDelete a saved workflow.
workflow_runRun a saved workflow in order, stopping at the first failure. Use dry_run to validate without device side effects.
assistant_statusReturn compact live status for all devices, gateway services, and available tool count.
gateway_bootstrapReturn the public bootstrap document with connection URL, transport, and discovery tool names.
search_registrySearch the complete mirrored official MCP Registry for installable servers. Delegates to the registry-autobroker child.
registry_statusShow official MCP Registry sync state, catalog version, total entries, and knowledge targets.
registry_changesReturn catalog additions, updates, deletions, and provisioning events after a timestamp.
11 further tools are not listed here. The complete surface is in the source.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js is vulnerable to RCE in React flight protocol
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
AI_CHAT_HOSTThe custom server listens on (default 127.0.0.1) and defaultsAI_CHAT_INTERNAL_MCP_SERVERAI_CHAT_INTERNAL_ORIGINAI_CHAT_INTERNAL_TOKENAI_CHAT_JOB_IDAI_CHAT_JOB_LEASE_TOKENAI_CHAT_MCP_STATE_DIR3. Set AI_CHAT_ROOT, and AGENT_CWD explicitly.AI_CHAT_PUBLIC_URLAI_CHAT_ROOT3. Set , AI_CHAT_MCP_STATE_DIR and AGENT_CWD explicitly.AI_CHAT_RUNTIME_MODEAI_CHAT_WORKER_CONCURRENCYAI_CHAT_WORKER_CRASH_RETRIESAI_CHAT_WORKER_IDAI_CHAT_WORKER_MAX_JOB_MSAI_CHAT_WORKER_POLL_MSAPP_NAMECHAT_PASSWORDadmin / requiredCONTEXT_HUB_URLGITHUB_SHAMCP_AGENT_CWDMCP_ALLOW_ROOT_AGENTSMCP_AUTOMATIONMCP_BEARER_TOKEN1. Set a long, random .MCP_CAPABILITY_HASHMCP_CAPABILITY_MANIFESTMCP_CHAT_IDMCP_COMPRESSION_ENABLEDMCP_COMPRESSION_MODEMCP_COMPRESSION_TOOL_RESULTSMCP_CORS_ORIGINMCP_DOCKER_NETWORKMCP_INCOGNITOMCP_IS_HOST_ADMINMCP_JOB_IDMCP_LAPTOP_HOMEMCP_LAPTOP_HOSTMCP_LAPTOP_LABELMCP_LAPTOP_USERMCP_LOCAL_SCRAPER_SEARCH_URLMCP_LOCAL_SCRAPER_URLMCP_LOCAL_SEARCH_URLUnsetMCP_MODE_IDMCP_MODE_POLICYMCP_OS_GIDMCP_OS_UIDMCP_OS_USERNAMEMCP_PC_HOMEMCP_PC_HOSTMCP_PC_LABELMCP_PC_USERMCP_SDK_ROOTMCP_SERVER_HOMEMCP_SERVER_LABELMCP_SERVER_OSMCP_SERVER_USERMCP_USER_IDMETIS_RELEASE_COMMITMETIS_RELEASE_TAGNEXT_DIST_DIRPNPM_BINGEMINI_API_KEYGOOGLE_API_KEYGOOGLE_GENAI_USE_VERTEXAIGOOGLE_CLOUD_PROJECTGOOGLE_CLOUD_LOCATIONMETIS_SCRAPER_HOSTMETIS_SCRAPER_PORTMETIS_SCRAPER_FETCH_TIMEOUTSESSIONNAMENEXT_PUBLIC_AGENT_CWDNEXT_PUBLIC_APP_NAMENEXT_PUBLIC_CHAT_USERNAMENEXT_PUBLIC_STORAGE_PREFIXPORTDependencies
43 runtime dependencies (16 dev), 1 flagged: playwright
Tool annotations
48/111 tools have annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
111/111 tools missing one or more hints — provide_file (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); create_automation (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_automations (missing: destructiveHint, idempotentHint, openWorldHint), +108 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
42/111 tools referenced in tests (38%)
Write tests that reference each tool by name so every tool has at least one test.
No eval / new Function
1 eval() or new Function() call — dynamic code execution
Replace eval / Function with explicit parsing or safer alternatives.
Secrets stay with their owner
18 secrets sent to a request target we could not resolve (MCP_BEARER_TOKEN → dynamic, MCP_BEARER_TOKEN → dynamic) — often a configured endpoint, not necessarily third-party
Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.
Secrets not written to files
1 secret value written to files
Avoid persisting secrets to disk. Keep them in memory or your secret manager.
Production dependencies are patched
3 critical, 11 high severity in production deps — next@15.5.0 (critical), next@15.5.0 (critical)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
2/43 production deps stale: remark-math@2023-11-20 (2.8y), rehype-katex@2024-08-19 (2.1y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/f1shyondrugs/metis-ai)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check