Pandaone-AI-Agent (hellob1889/Pandaone-AI-Agent) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 11 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.
AI Agent code audit & file protection tool — 让每一次代码改动都留下合规、可追溯的证据链
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
every push re-verified
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
pandaone_init在指定目录初始化 Pandaone AI Agent(创建 .pandaone/、config.json、pandaone.jsonl、可选 binary_snapshots.json)
pandaone_lock锁定所有受保护扩展名的文件(attrib +r / chmod -w)
pandaone_unlock解锁所有受保护扩展名的文件
pandaone_write审计写入(核心命令):reason/problem/approach 必填;文本用 --old/--new 或 --content;二进制用 --from-file 或 --content-base64
pandaone_log查看审计日志(按文件/recent/格式过滤)
pandaone_status查看 Pandaone 状态(保护文件 / 审计次数 / 锁定状态等)
pandaone_install_hook安装/卸载 pre-commit hook
pandaone_watch启动 watchdog 守护进程(监控文件改动)
pandaone_install_git安装便携版 git(用于项目内 git hook,无需全局 git)
pandaone_fingerprint_update更新密码指纹(用于 watch 守护进程鉴权)
pandaone_ciCI 审计验证:对比 base..head 的所有改动,确认每条变更都通过 pandaone write 审计
PANDAONE_SKIP_GIT_CHECK设 1 跳过 git 检测(无 git 环境用)NO_COLOR设 1 禁用彩色输出BASH_VERSIONZSH_VERSIONPANDAX_LANG界面语言(zh / en)PANDAX_FP_PASSWORD仅 pandaone_fingerprint_update / pandaone_watch 守护进程鉴权需要;本地设置,不上传[](https://m8ven.ai/mcp/hellob1889/pandaone-ai-agent)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check