mori (fjwood69/mori) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: there is no public source to read and no endpoint we can reach, so there is nothing for us to inspect. No publisher has claimed this listing.

C
Limited view
71/100
21 days ago

mori

Mori (森) is a shared memory layer for AI coding agents — one that compounds.

Limited view. Automated analysis covers part of this stack. Findings reflect what we verified. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

Limited view: static analysis for Python is partially covered.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

fjwood69

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: MORI_API_KEY, MORI_ADVISOR_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configCLAUDE_CONFIG_DIR
configCOMPUTERNAME
configHOSTNAME
🔐 secretMORI_API_KEYEdit .env: set to your provider key (Novita, DeepInfra, OpenAI, …)
configMORI_API_URL
configMORI_CLIENT
configMORI_CLIENT_ID
configMORI_POST_COMPACT_BRIEF
configMORI_SERVER_URL
configMORI_SESSION_CONTEXT_FILE
configMORI_SKIP_HEALTH_CHECK
configMORI_SKIP_SETUP_NUDGE
configXDG_CACHE_HOME
configMORI_ADVISOR_DATA
configMORI_MCP_SERVER_NAME
configMORI_BASE_URLand to the provider's OpenAI-compatible endpoint.
configMORI_BIFROST_TIMEOUT
configMORI_LLM_CALL_TIMEOUT
configMORI_TRUSTED_DREAMERSComma-separated trusted hostnames
configMORI_STANDARDS_DIRStandards-aware: set to a directory of .md files
configMORI_SKILLS_DIR
configMORI_NATS_URL
configMORI_CONSULT_CAPTURE
configMORI_FRESHNESS_ON_BRIEF
configMORI_CONSULT_FILE_ROOTS
configMORI_STANDARDS_ROOTS
configMORI_ORPHAN_SCAN_INTERVAL_SEC
configMORI_ORPHAN_SCAN_DRY_RUN
configMORI_VERSION
configMORI_POST_COMPACT_WINDOW
configMORI_BRIEF_SCOPEagents chased phantom APIs in 20/20 runs; with provenance-safe scoping (,
configMORI_CLIENT_HOSTNAME
configMORI_DEVICES_CONFIG
configMORI_INSTANCE_URL
configMORI_CAPTURE_THINKING
configGCE_METADATA_HOST
configMORI_CORS_ORIGINSelsewhere and point it at a mori instance — set for that cross-origin
configAPP_PORT
configMORI_INGESTION_PORT
🔐 secretMORI_ADVISOR_API_KEY
configMORI_INGESTION_MAX_FILE_MB
configMORI_API_KEYSEnter any valid API key (the same your clients use) and you can search,
configMORI_PROVIDER_MODEbifrost direct or bifrost
configMORI_MODELmoonshotai/kimi-k2.6 Advisor + consult model
configMORI_BIFROST_ADVISOR_VK
configMORI_BIFROST_DREAM_VK
configMORI_BIFROST_FAST_VK
configMORI_ADVISOR_MODEL
configMORI_DREAM_MODELfalls back to MORI_MODEL Dream + ingest distillation model
configMORI_FAST_MODELdeepseek/deepseek-v4-flash Contradiction scan + freshness checks
configMORI_INTAKE_PROMOTION_ENABLED
configMORI_INTAKE_DATABASE_URL
configMORI_PROJECT
configMORI_CURATE
configOTEL_SERVICE_NAME
configOTEL_EXPORTER_OTLP_ENDPOINT
configOTEL_METRIC_EXPORT_INTERVAL
configMORI_DATABASE_URL
configMORI_MSG_HEADLESS_ENABLEDfalse Spawn headless Claude for incoming tasks
configMORI_MSG_HEADLESS_TRUSTEDComma-separated hostnames allowed to trigger headless CC
configMORI_TD_MODE
configMORI_LOCAL_FULL_ACCESS
configMORI_API_KEY_ROLES
configMORI_PROMPTS_DIR
configMORI_TIER_ENFORCE
configMORI_ANATOMY_ENFORCE
configMORI_INTAKE_LEASE_SECONDS
configMORI_INTAKE_PORT
configMORI_INTAKE_HOST
configMORI_INTAKE_WORKER_INTERVAL
configMORI_INTAKE_PENDING_TTL_HOURS
configMORI_INTAKE_PURGE_INTERVAL_SEC
configMORI_INTAKE_MAX_CONTENT_BYTES
configMORI_INTAKE_POOL_MIN
configMORI_INTAKE_POOL_MAX
configMORI_INTAKE_RATE_LIMIT_PER_MIN
configXDG_CONFIG_HOME
configMORI_RATE_LIMIT
configMORI_RATE_LIMIT_SCOPE
configMORI_THROTTLE_STORE
configWEB_CONCURRENCY
configUVICORN_WORKERS
configMORI_INTAKE_URL
configMORI_INTAKE_AGENT_ID
configMORI_INTAKE_SESSION_ID
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

37/37 tools missing one or more hints — brief (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); consult_advisor (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); consult_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +34 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

34/37 tool handlers declare input schemas (92%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 18/37 tool handlers wrap calls in try/catch (49%)

Wrap each tool handler body in try/catch and return a structured error response.

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/fjwood69-mori-1jqqg5)](https://m8ven.ai/mcp/fjwood69-mori-1jqqg5)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: ebe19203c13e5e62cf1f758dcfd78dd6233c1761
code hash: 1b536283cd81a8cf7a0180150ce126133af7872d76984198421fec131d1b18ef
verified: 8/5/2026, 6:42:18 PM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client