Pandaone-AI-Agent (hellob1889/Pandaone-AI-Agent) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 11 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.

B
Emerging
89/100

Pandaone-AI-Agent

AI Agent code audit & file protection tool — 让每一次代码改动都留下合规、可追溯的证据链

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored

every push re-verified

Who stands behind it

qq.com (@hellob1889) · Verified Publisher

Source: github_repo_search

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: PANDAX_FP_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
Are you the publisher? Confirm or correct these findings.
// tools this server exposes11 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

pandaone_init

在指定目录初始化 Pandaone AI Agent(创建 .pandaone/、config.json、pandaone.jsonl、可选 binary_snapshots.json)

pandaone_lock

锁定所有受保护扩展名的文件(attrib +r / chmod -w)

pandaone_unlock

解锁所有受保护扩展名的文件

pandaone_write

审计写入(核心命令):reason/problem/approach 必填;文本用 --old/--new 或 --content;二进制用 --from-file 或 --content-base64

pandaone_log

查看审计日志(按文件/recent/格式过滤)

pandaone_status

查看 Pandaone 状态(保护文件 / 审计次数 / 锁定状态等)

pandaone_install_hook

安装/卸载 pre-commit hook

pandaone_watch

启动 watchdog 守护进程(监控文件改动)

pandaone_install_git

安装便携版 git(用于项目内 git hook,无需全局 git)

pandaone_fingerprint_update

更新密码指纹(用于 watch 守护进程鉴权)

pandaone_ci

CI 审计验证:对比 base..head 的所有改动,确认每条变更都通过 pandaone write 审计

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configPANDAONE_SKIP_GIT_CHECK设 1 跳过 git 检测(无 git 环境用)
configNO_COLOR设 1 禁用彩色输出
configBASH_VERSION
configZSH_VERSION
configPANDAX_LANG界面语言(zh / en)
🔐 secretPANDAX_FP_PASSWORD仅 pandaone_fingerprint_update / pandaone_watch 守护进程鉴权需要;本地设置,不上传
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/hellob1889/pandaone-ai-agent)](https://m8ven.ai/mcp/hellob1889/pandaone-ai-agent)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: e83051b7fb8373e46555b47f0fec16797c702371
code hash: 3dbc2ccdd4773b8ad2c6f598c6b7d5177854fb2eee92a6349767e8ed1342f574
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client