halofy (halofyai/halofy) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 24 tools. No publisher has claimed this listing.

B
Emerging
89/100
7 days ago

halofy

Halofy is the open access and governance layer for AI agents across your organization. Identity, policy, provenance, audit, and signed erasure.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

halofyai

Source: github_topic

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: HALOMEM_BENCH_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 20 credentials: ANTHROPIC_API_KEY, AZURE_OPENAI_API_KEY, AZURE_OPENAI_CONFLICT_API_KEY, AZURE_OPENAI_EMBED_API_KEY, AZURE_OPENAI_LLM_API_KEY, HALOMEM_AIRTABLE_CLIENT_SECRET, HALOMEM_API_KEY, HALOMEM_BOOTSTRAP_TOKEN, HALOMEM_GOOGLE_CHAT_MANAGED_ROUTE_KEY, HALOMEM_GOOGLE_DRIVE_CLIENT_SECRET, HALOMEM_LLM_API_KEY, HALOMEM_MANAGED_ANTHROPIC_API_KEY, HALOMEM_MASTRA_V2_CAPABILITY_SECRET, HALOMEM_MASTRA_V2_INTERNAL_API_TOKEN, HALOMEM_MEM0_TOKEN, HALOMEM_NANGO_CONNECT_API_KEY, HALOMEM_NANGO_PROXY_API_KEY, HALOMEM_NOTION_CLIENT_SECRET, OPENAI_API_KEY, SKILL_SCAN_LLM_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretANTHROPIC_API_KEYunset → StubLlm
🔐 secretAZURE_OPENAI_API_KEY
configAZURE_OPENAI_API_VERSION
🔐 secretAZURE_OPENAI_CONFLICT_API_KEY
configAZURE_OPENAI_CONFLICT_DEPLOYMENT
configAZURE_OPENAI_CONFLICT_ENDPOINT
🔐 secretAZURE_OPENAI_EMBED_API_KEY
configAZURE_OPENAI_EMBED_DEPLOYMENT
configAZURE_OPENAI_EMBED_ENDPOINT
configAZURE_OPENAI_ENDPOINT
🔐 secretAZURE_OPENAI_LLM_API_KEY
configAZURE_OPENAI_LLM_DEPLOYMENT
configAZURE_OPENAI_LLM_ENDPOINT
configAZURE_OPENAI_SCAN_DEPLOYMENT
configCODEX_HOME
configHALOMEM_AIRTABLE_CLIENT_ID
🔐 secretHALOMEM_AIRTABLE_CLIENT_SECRET
🔐 secretHALOMEM_API_KEYCaller credential for the CLI and the MCP server. —
🔐 secretHALOMEM_BOOTSTRAP_TOKEN
configHALOMEM_CHANNELS_ENABLED
configHALOMEM_CHANNEL_BACKLOG_LIMIT
configHALOMEM_CHANNEL_CONFIG_VERSION
configHALOMEM_CHANNEL_DEPLOYMENT_VERSION
configHALOMEM_CHANNEL_DISCORD_GATEWAY_ENABLED
configHALOMEM_CHANNEL_ENVIRONMENT
configHALOMEM_CHANNEL_INFRASTRUCTURE_VERSION
configHALOMEM_CHANNEL_LEASE_MS
configHALOMEM_CHANNEL_OUTBOUND_ENABLED
configHALOMEM_CHANNEL_PINNED_BACKLOG_RESERVE
configHALOMEM_CHANNEL_RECEIPT_LEASE_MS
configHALOMEM_CHANNEL_SECRET_KEK
configHALOMEM_CHANNEL_SECRET_KEK_ID
configHALOMEM_CHANNEL_SECRET_KEY_VERSION
configHALOMEM_CHANNEL_TELEMETRY_SALT
configHALOMEM_CHANNEL_WORKER_POLL_MS
configHALOMEM_COLD_KEK
configHALOMEM_COLD_STORAGE
configHALOMEM_CONSOLE_DIR
configHALOMEM_DATA_DIRHermetic vitest suite via scripts/run-hermetic-tests.mjs: clears DATABASE_URL, TEST_DATABASE_URL, HALOMEM_DATA_DIR and HALOMEM_KNOWLEDGE_DIR, marks the lane hermetic so the Postgres and perf files are excluded, then runs every remaining file in its own forked process.
configHALOMEM_DB_ENTRA_CLIENT_ID
configHALOMEM_DB_ENTRA_USER
configHALOMEM_DEDUPE_THRESHOLD
configHALOMEM_GOOGLE_CHAT_MANAGED_AZURE_APP_ID_URI
configHALOMEM_GOOGLE_CHAT_MANAGED_AZURE_CLIENT_ID
configHALOMEM_GOOGLE_CHAT_MANAGED_INSTALL_URL
configHALOMEM_GOOGLE_CHAT_MANAGED_PROJECT_NUMBER
🔐 secretHALOMEM_GOOGLE_CHAT_MANAGED_ROUTE_KEY
configHALOMEM_GOOGLE_CHAT_MANAGED_SERVICE_ACCOUNT_EMAIL
configHALOMEM_GOOGLE_CHAT_MANAGED_SERVICE_ACCOUNT_JSON
configHALOMEM_GOOGLE_CHAT_MANAGED_WIF_PROVIDER
configHALOMEM_GOOGLE_DRIVE_CLIENT_ID
🔐 secretHALOMEM_GOOGLE_DRIVE_CLIENT_SECRET
configHALOMEM_KNOWLEDGE_DIRHermetic vitest suite via scripts/run-hermetic-tests.mjs: clears DATABASE_URL, TEST_DATABASE_URL, HALOMEM_DATA_DIR and HALOMEM_KNOWLEDGE_DIR, marks the lane hermetic so the Postgres and perf files are excluded, then runs every remaining file in its own forked process.
🔐 secretHALOMEM_LLM_API_KEYunset
configHALOMEM_LLM_BASE_URLunset
configHALOMEM_LLM_MODELunset
🔐 secretHALOMEM_MANAGED_ANTHROPIC_API_KEY
configHALOMEM_MANAGED_ANTHROPIC_BASE_URL
configHALOMEM_MANAGED_ANTHROPIC_LABEL
configHALOMEM_MANAGED_ANTHROPIC_MODEL
🔐 secretHALOMEM_MASTRA_V2_CAPABILITY_SECRET
🔐 secretHALOMEM_MASTRA_V2_INTERNAL_API_TOKEN
configHALOMEM_MASTRA_V2_MANAGED_LABEL
configHALOMEM_MASTRA_V2_MANAGED_MODEL
configHALOMEM_MASTRA_V2_PUBLIC_MCP_URL
configHALOMEM_MASTRA_V2_RUNTIME_BASE_URL
configHALOMEM_MASTRA_V2_TIMEOUT_MS
🔐 secretHALOMEM_MEM0_TOKEN
configHALOMEM_MEM0_URL
configHALOMEM_MODEL_ALLOWED_HOSTS
configHALOMEM_MODEL_CREDENTIAL_KEK
configHALOMEM_NANGO_CONNECTION_LIMIT
🔐 secretHALOMEM_NANGO_CONNECT_API_KEY
configHALOMEM_NANGO_ENVIRONMENT_ID
configHALOMEM_NANGO_INTEGRATIONS
🔐 secretHALOMEM_NANGO_PROXY_API_KEY
configHALOMEM_NOTION_CLIENT_ID
🔐 secretHALOMEM_NOTION_CLIENT_SECRET
configHALOMEM_PORT
configHALOMEM_PUBLIC_URLunset
configHALOMEM_SECURE_COOKIES
configHALOMEM_SOURCE_CONFIG_KEK
configHALOMEM_TEST_LANE
configHALOMEM_TOKEN_BUDGET
configHALOMEM_WARMSTORE_NAMESPACES
configIDENTITY_ENDPOINT
configIDENTITY_HEADER
🔐 secretOPENAI_API_KEYunset → HashEmbedder (dim 256)
🔐 secretSKILL_SCAN_LLM_API_KEY
configSKILL_SCAN_LLM_BASE_URL
configSKILL_SCAN_LLM_MODEL
configSKILL_VETTING_V2
configHALOMEM_MEM0_VERBOSE
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployDATABASE_URL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

24/24 tools missing one or more hints — mem_read (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); mem_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); source_list (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +21 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

23/24 tool handlers declare input schemas (96%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Secrets not logged

1 secret value sent to error

Redact or omit secret values from log output.

Dependency freshness

1/11 production deps stale: gray-matter@2023-07-12 (3.1y)

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/halofyai/halofy)](https://m8ven.ai/mcp/halofyai/halofy)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 3763e64f521df8dc58d00d4632e732e702dd76ef
code hash: 4ad9d680316157a1b3296dddf0d6180a2328abe632ffa6f4a76dc1a70ba33ef4
verified: 9/3/2026, 4:57:42 PM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client