sidekick (geoffmcc/sidekick) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 115 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.

B
Emerging
89/100
3 days ago

sidekick

Enables persistent remote VPS collaboration with MCP tools, live dashboard, and autonomous AI agent for code execution, memory, and task automation.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored

Monitored 19 days · every push re-verified

Who stands behind it

gmail.com (@geoffmcc) · Verified Publisher

Source: Glama

Maintenance & responsiveness
as of 2026-08-20
Issues closed (90d): 6 · 0 open
Releases (90d): none
Active contributors (6mo): 1

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
Are you the publisher? Confirm or correct these findings.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configGROQ_MODELGroq model name
configOLLAMA_URLOllama API URL for the local Compute provider
configSIDEKICK_AGENT_PORTAgent bridge port
configSIDEKICK_ALLOWED_IPSBearer token auth + IP whitelist (SIDEKICK_ALLOWED_IPS) + dangerous command blocklist + configurable tool policy
configSIDEKICK_AUTO_MEMORYEnable bounded automatic memory summaries
configSIDEKICK_AUTO_MEMORY_MAXMax retained automatic memory entries
configSIDEKICK_BACKUP_DIR
configSIDEKICK_BIND_HOST
configSIDEKICK_BLACKBOX_AUTO_COMPRESS
configSIDEKICK_BLACKBOX_DAILY_LIMIT
configSIDEKICK_BLACKBOX_DEFAULT_RETENTION_CLASS
configSIDEKICK_BLACKBOX_MAX_BYTES
configSIDEKICK_BLACKBOX_MAX_INCIDENTS
configSIDEKICK_BLACKBOX_PURGE_GRACE_DAYS
configSIDEKICK_BLACKBOX_SOURCE_LIMIT_BYTES
configSIDEKICK_BLACKBOX_SOURCE_TIMEOUT_MS
configSIDEKICK_BLACKBOX_TOTAL_TIMEOUT_MS
configSIDEKICK_BLACKBOX_TTL_ARCHIVE_DAYS
configSIDEKICK_BLACKBOX_TTL_IMPORTANT_DAYS
configSIDEKICK_BLACKBOX_TTL_STANDARD_DAYS
configSIDEKICK_BLACKBOX_TTL_TRANSIENT_DAYS
configSIDEKICK_CERTIFICATION_DATA_DIR
configSIDEKICK_DASHBOARD_ALLOWED_IPSsubnets to SIDEKICK_ALLOWED_IPS and before
configSIDEKICK_DASHBOARD_BIND_HOST
configSIDEKICK_DASHBOARD_PORTDashboard port
configSIDEKICK_DASHBOARD_RATE_LIMIT_MAX
configSIDEKICK_DASHBOARD_RATE_LIMIT_WINDOW_MS
configSIDEKICK_DASHBOARD_TRUST_PROXY
configSIDEKICK_DASHBOARD_USER/SIDEKICK_DASHBOARD_PASS are optional legacy Basic
configSIDEKICK_DATA_DIRData directory for logs, KV, conversations
configSIDEKICK_DB_FILE
configSIDEKICK_EMBEDDINGSEnable semantic memory embeddings when Ollama/Qdrant are available
configSIDEKICK_EMBEDDING_MODELOllama embedding model for semantic memory recall
configSIDEKICK_ENVIRONMENT
configSIDEKICK_GRAFANA_ADMIN_USER
configSIDEKICK_GRAFANA_PORTLocal Grafana port used by dashboard health checks and proxying
configSIDEKICK_HOME
configSIDEKICK_INFLUX_ALLOWED_HOSTS
configSIDEKICK_INFLUX_URLInfluxDB URL
configSIDEKICK_LOCAL
configSIDEKICK_MAX_ITERATIONSLegacy tool-loop iteration ceiling; durable task profiles add bounded model/tool/wall-clock/resource budgets
configSIDEKICK_MAX_LOG
configSIDEKICK_MIGRATIONS_DIR
configSIDEKICK_PORTMCP server port
configSIDEKICK_POSTGRES_DB
configSIDEKICK_POSTGRES_HOST
configSIDEKICK_POSTGRES_PORT
configSIDEKICK_POSTGRES_URLOptional PostgreSQL connection string; overrides the discrete connection fields
configSIDEKICK_POSTGRES_USER
configSIDEKICK_QDRANT_URLQdrant vector DB URL
configSIDEKICK_REDIS_URLRedis connection string
configSIDEKICK_SESSION_ID
configSIDEKICK_TEST_APPROVAL_MODE
configSIDEKICK_TEST_TOOL_POLICY
configSIDEKICK_OPENVINO_MODELS_DIR
// quality suggestions

Dependencies

23 runtime dependencies (2 dev), 1 flagged: playwright-core

// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/geoffmcc-sidekick-1j2km0)](https://m8ven.ai/mcp/geoffmcc-sidekick-1j2km0)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 4fd85599012b403316cb237491519f21704a1f99
code hash: b9686c72d63ea1684b25e625749bbda21f21230a2bbd95d231ee49e1e1e7d6ae
verified: 9/4/2026, 11:07:04 PM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client