sidekick (geoffmcc/sidekick) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 115 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.
Enables persistent remote VPS collaboration with MCP tools, live dashboard, and autonomous AI agent for code execution, memory, and task automation.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Monitored 19 days · every push re-verified
Who stands behind it
gmail.com (@geoffmcc) · Verified Publisher
Source: Glama
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
GROQ_MODELGroq model nameOLLAMA_URLOllama API URL for the local Compute providerSIDEKICK_AGENT_PORTAgent bridge portSIDEKICK_ALLOWED_IPSBearer token auth + IP whitelist (SIDEKICK_ALLOWED_IPS) + dangerous command blocklist + configurable tool policySIDEKICK_AUTO_MEMORYEnable bounded automatic memory summariesSIDEKICK_AUTO_MEMORY_MAXMax retained automatic memory entriesSIDEKICK_BACKUP_DIRSIDEKICK_BIND_HOSTSIDEKICK_BLACKBOX_AUTO_COMPRESSSIDEKICK_BLACKBOX_DAILY_LIMITSIDEKICK_BLACKBOX_DEFAULT_RETENTION_CLASSSIDEKICK_BLACKBOX_MAX_BYTESSIDEKICK_BLACKBOX_MAX_INCIDENTSSIDEKICK_BLACKBOX_PURGE_GRACE_DAYSSIDEKICK_BLACKBOX_SOURCE_LIMIT_BYTESSIDEKICK_BLACKBOX_SOURCE_TIMEOUT_MSSIDEKICK_BLACKBOX_TOTAL_TIMEOUT_MSSIDEKICK_BLACKBOX_TTL_ARCHIVE_DAYSSIDEKICK_BLACKBOX_TTL_IMPORTANT_DAYSSIDEKICK_BLACKBOX_TTL_STANDARD_DAYSSIDEKICK_BLACKBOX_TTL_TRANSIENT_DAYSSIDEKICK_CERTIFICATION_DATA_DIRSIDEKICK_DASHBOARD_ALLOWED_IPSsubnets to SIDEKICK_ALLOWED_IPS and beforeSIDEKICK_DASHBOARD_BIND_HOSTSIDEKICK_DASHBOARD_PORTDashboard portSIDEKICK_DASHBOARD_RATE_LIMIT_MAXSIDEKICK_DASHBOARD_RATE_LIMIT_WINDOW_MSSIDEKICK_DASHBOARD_TRUST_PROXYSIDEKICK_DASHBOARD_USER/SIDEKICK_DASHBOARD_PASS are optional legacy BasicSIDEKICK_DATA_DIRData directory for logs, KV, conversationsSIDEKICK_DB_FILESIDEKICK_EMBEDDINGSEnable semantic memory embeddings when Ollama/Qdrant are availableSIDEKICK_EMBEDDING_MODELOllama embedding model for semantic memory recallSIDEKICK_ENVIRONMENTSIDEKICK_GRAFANA_ADMIN_USERSIDEKICK_GRAFANA_PORTLocal Grafana port used by dashboard health checks and proxyingSIDEKICK_HOMESIDEKICK_INFLUX_ALLOWED_HOSTSSIDEKICK_INFLUX_URLInfluxDB URLSIDEKICK_LOCALSIDEKICK_MAX_ITERATIONSLegacy tool-loop iteration ceiling; durable task profiles add bounded model/tool/wall-clock/resource budgetsSIDEKICK_MAX_LOGSIDEKICK_MIGRATIONS_DIRSIDEKICK_PORTMCP server portSIDEKICK_POSTGRES_DBSIDEKICK_POSTGRES_HOSTSIDEKICK_POSTGRES_PORTSIDEKICK_POSTGRES_URLOptional PostgreSQL connection string; overrides the discrete connection fieldsSIDEKICK_POSTGRES_USERSIDEKICK_QDRANT_URLQdrant vector DB URLSIDEKICK_REDIS_URLRedis connection stringSIDEKICK_SESSION_IDSIDEKICK_TEST_APPROVAL_MODESIDEKICK_TEST_TOOL_POLICYSIDEKICK_OPENVINO_MODELS_DIRDependencies
23 runtime dependencies (2 dev), 1 flagged: playwright-core
[](https://m8ven.ai/mcp/geoffmcc-sidekick-1j2km0)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check