A unified backend MCP server that aggregates and filters data from external services like Zaim, GitHub, Google, and Notion, providing cross-cutting views via MCP and REST API without heavy AI inference.
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
guchi-apps
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
AIDE_AUTH_DISABLED認証 許可したGoogleアカウント(AIDE_STATUS_ALLOWED_EMAILS)。Supabase未設定の環境では AIDE_AUTH_PASSWORD。=1 なら素通しし、画面上で警告を出すAIDE_AUTH_PASSWORD.env は Node 標準の --env-file-if-exists で読ませている。 が未設定だとAIDE_BASE_URL/status/auth/callback を登録しておく必要がある。AIDE_CACHE_DIRAIDE_GITHUB_ISSUE_TOKEN(Issues: Read and write)を使う。フォールバックはしないAIDE_GITHUB_ORGguchi-appsAIDE_GITHUB_REPOSarchived を除き、直近 AIDE_GITHUB_ACTIVE_DAYS 日にpushがあったものを自動で拾うAIDE_GITHUB_TOKENトークンを分ける。 取得用の はRead-onlyのままで、起票はAIDE_INGEST_SECRET送信・受信の共通シークレットAIDE_INGEST_URLローカルのキャッシュへ直接書く(開発機) そのURLへHTTPで送る(本番)AIDE_OPS_DASHBOARD_TOKEN取得を試みず「未設定」を返す Authorization: Bearer で認証するAIDE_OPS_DASHBOARD_URLAIDE_READ_SECRET認証 Authorization: Bearer $AIDE_SIGNALY_WEBHOOK_URLAIDE_ の一部だけで、ZAIM_ と は含まれない)。サーバー側のAIDE_SUBSCRIPTIONS_TOKEN取得を試みず「未設定」を返す Authorization: Bearer で認証するAIDE_SUBSCRIPTIONS_URLAIDE_WORKER_STATE_DIRHOSTデフォルトで 127.0.0.1:4747 を listen する。PORT / で変更可。ZAIM_EMAILと ZAIM_PASSWORD の両方が設定されている環境でだけ有効になる。片方だけの設定は設定漏れとみなし、未設定として扱う。ZAIM_PASSWORDZAIM_EMAIL と の両方が設定されている環境でだけ有効になる。片方だけの設定は設定漏れとみなし、未設定として扱う。PORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
5/5 tools missing one or more hints — aide_dev_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); aide_create_issue (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); aide_money_summary (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +2 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tool test coverage
Only 0/5 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
2 child_process/subprocess calls in production code — runs shell commands (src/core/connectors/zaim/session.ts:79, src/core/connectors/zaim/session.ts:92)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Secrets stay with their owner
3 secret/sensitive values flow into network calls (AIDE_OPS_DASHBOARD_TOKEN → dynamic, AIDE_SUBSCRIPTIONS_TOKEN → dynamic) (1 other flows matched canonical API hosts)
Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/guchi-apps-aide-1jam0a)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check