C
Limited view
67/100
12 days ago

Limited view. Automated analysis covers part of this stack. Findings reflect what we verified. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

Limited view: static analysis for Python is partially covered.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

huozao

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 34 credentials: EXECUTOR_TOKEN, MCP_OAUTH_SIGNING_SECRET, FEISHU_SESSION_CONSOLE_APP_TOKEN, WEB_DOCK_API_TOKEN, FEISHU_APP_SECRET, FEISHU_COMPANY_A_APP_SECRET, FEISHU_COMPANY_A_SESSION_CONSOLE_APP_TOKEN, FEISHU_SYSTEM_CONFIG_APP_TOKEN, FEISHU_TENANT_KEY, OPENCLAW_INTERNAL_TOKEN, OPENCLAW_BRIDGE_ADMIN_SECRET, ADVENTURELOG_API_TOKEN, AUTH_TOKEN_SECRET, ADMIN_BOOTSTRAP_PASSWORD, IMMICH_API_KEY, OSS_ACCESS_KEY_SECRET, CHANJET_APP_KEY, CHANJET_APP_SECRET, CHANJET_OPEN_TOKEN, PRODUCT_CENTER_PAPERLESS_TOKEN, PRODUCT_CENTER_PAPERLESS_PASSWORD, PRODUCT_CENTER_ERPNEXT_API_KEY, PRODUCT_CENTER_ERPNEXT_API_SECRET, WECOM_KF_APP_SECRET, WECOM_KF_CALLBACK_TOKEN, WECOM_KF_CALLBACK_AES_KEY, BACKUP_REPORT_TOKEN, WEBDOCK_PHOTO_API_TOKEN, GOLD_SPREAD_ALERT_TOKEN, VERSION_DIGEST_FEISHU_APP_SECRET, MINIAPP_SERVICE_TOKEN, WECOM_B_CAPTURE_TOKEN, OPS_ALERT_FEISHU_APP_SECRET, CHANJET_WEBHOOK_AES_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configMCP_HOST
configMCP_PORT
configAPP_BASE_URL
configCORS_ALLOWED_ORIGINS
configEXECUTOR_MAX_WORKERS
configEXECUTOR_HOST
configEXECUTOR_PORT
configEXECUTOR_TIMEOUT_SECONDS
configEXECUTOR_BASE_URL
🔐 secretEXECUTOR_TOKEN
configEXECUTOR_TOKEN_FILE
configMCP_OAUTH_ENABLED
configMCP_OAUTH_ISSUER
configMCP_OAUTH_PASSPHRASE
🔐 secretMCP_OAUTH_SIGNING_SECRET
configMCP_OAUTH_STORE_PATH
🔐 secretFEISHU_SESSION_CONSOLE_APP_TOKEN
configWEB_DOCK_FALLBACK_MESSAGE
configMAX_BRIDGE_IMAGES
configOPENCLAW_BRIDGE_FEISHU_POLICY_CACHE_SECONDS
configOPENCLAW_INBOUND_MEDIA_DIR
configWEB_DOCK_BASE_URL
🔐 secretWEB_DOCK_API_TOKEN
configWEB_DOCK_TIMEOUT_SECONDS
configWEB_DOCK_MODEL
configWECOM_ASSISTANT_NAME
configFEISHU_API_BASE
configFEISHU_COMPANY_A_API_BASE
configFEISHU_APP_ID
configFEISHU_COMPANY_A_APP_ID
🔐 secretFEISHU_APP_SECRET
🔐 secretFEISHU_COMPANY_A_APP_SECRET
🔐 secretFEISHU_COMPANY_A_SESSION_CONSOLE_APP_TOKEN
🔐 secretFEISHU_SYSTEM_CONFIG_APP_TOKEN
configFEISHU_BITABLE_LIST_CACHE_SECONDS
configFEISHU_BITABLE_SNAPSHOT_REFRESH_SECONDS
🔐 secretFEISHU_TENANT_KEY
configFEISHU_CHAT_MODE_CACHE_SECONDS
configOPENCLAW_BRIDGE_TRACE
configOPENCLAW_BRIDGE_PLACEHOLDER_ROTATE_SECONDS
configOPENCLAW_BRIDGE_TAG
🔐 secretOPENCLAW_INTERNAL_TOKEN
configWECOM_ASSISTANT_API_BASE
configOPENCLAW_BRIDGE_KEEPALIVE_SECONDS
🔐 secretOPENCLAW_BRIDGE_ADMIN_SECRET
configOPENCLAW_BRIDGE_HOSTS
configOPENCLAW_BRIDGE_HOST
configFEISHU_ALERT_CHAT_ID
configFEISHU_BITABLE_RECONCILE_AT
configOPENCLAW_BRIDGE_PORT
configADVENTURELOG_BASE_URL
🔐 secretADVENTURELOG_API_TOKEN
configADVENTURELOG_SOURCE_DATABASE_URL
configENV
🔐 secretAUTH_TOKEN_SECRET
configAUTH_TOKEN_TTL_SECONDS
configADMIN_BOOTSTRAP_USERNAME
🔐 secretADMIN_BOOTSTRAP_PASSWORD
configADMIN_BOOTSTRAP_DISPLAY_NAME
configCOUPLE_FEATURE_ENABLED
configCOUPLE_ROUTE
configCOUPLE_ALLOWED_USERS
configCOUPLE_ALLOWED_EMAILS
configIMMICH_ENABLED
configIMMICH_TIMEOUT_SECONDS
configIMMICH_BASE_URL
🔐 secretIMMICH_API_KEY
configOSS_ENDPOINT
configOSS_BUCKET
configOSS_ACCESS_KEY_ID
🔐 secretOSS_ACCESS_KEY_SECRET
configOSS_TIMEOUT_SECONDS
configEXECUTOR_REPOS
configCHANJET_BASE_URL
🔐 secretCHANJET_APP_KEY
🔐 secretCHANJET_APP_SECRET
🔐 secretCHANJET_OPEN_TOKEN
configOUTPUT_DIR
configDATA_DIR
configPRODUCT_CENTER_PAPERLESS_API_BASE
configPRODUCT_CENTER_PAPERLESS_PUBLIC_BASE
🔐 secretPRODUCT_CENTER_PAPERLESS_TOKEN
configPRODUCT_CENTER_PAPERLESS_USERNAME
🔐 secretPRODUCT_CENTER_PAPERLESS_PASSWORD
configPRODUCT_CENTER_ERPNEXT_API_BASE
configPRODUCT_CENTER_ERPNEXT_PUBLIC_BASE
🔐 secretPRODUCT_CENTER_ERPNEXT_API_KEY
🔐 secretPRODUCT_CENTER_ERPNEXT_API_SECRET
configPRODUCT_CENTER_ERPNEXT_DOCTYPE
configWECOM_KF_CORP_ID
🔐 secretWECOM_KF_APP_SECRET
🔐 secretWECOM_KF_CALLBACK_TOKEN
🔐 secretWECOM_KF_CALLBACK_AES_KEY
configWECOM_KF_PROCESSOR_URL
configRECIPE_ACTIVE_BOM_DIR
configRECIPE_BOM_INPUT_PATH
configRECIPE_BOM_INPUT_DIR
configRECIPE_BOM_INPUT_GLOB
configRECIPE_EXPORT_DIR
configTPLUS_EXPORT_DIR
configLOCAL_LOGIN_ENABLED
configOIDC_ENABLED
🔐 secretBACKUP_REPORT_TOKEN
configMAX_UPLOAD_MB
configPHOTO_MAX_UPLOAD_MB
configWEBDOCK_PHOTO_BASE_URL
🔐 secretWEBDOCK_PHOTO_API_TOKEN
configWEBDOCK_PHOTO_TIMEOUT_SECONDS
configLOCAL_UPLOAD_DIR
configUPLOAD_DISK_WARN_PCT
configSTORAGE_DRIVER
configSHARE_BASE_URL
configEXTERNAL_EXPORT_DIR
🔐 secretGOLD_SPREAD_ALERT_TOKEN
configGOLD_SPREAD_FEISHU_RECEIVE_ID
configVERSION_DIGEST_FEISHU_APP_ID
🔐 secretVERSION_DIGEST_FEISHU_APP_SECRET
🔐 secretMINIAPP_SERVICE_TOKEN
configOPS_HEALTH_HTTP_TARGETS_JSON
configOPS_HEALTH_BACKEND_URL
configOPS_HEALTH_PUBLIC_WEB_URL
configOPS_HEALTH_WEBDOCK_API_URL
configOPS_HEALTH_WEBDOCK_NOVNC_URL
configOPENCLAW_WECHAT_LOGIN_QR_URL
configOPENCLAW_WECHAT_LOGIN_QR_FILE
🔐 secretWECOM_B_CAPTURE_TOKEN
configCHANJET_OPEN_TOKEN_FILE
configOPS_ALERT_FEISHU_RECEIVE_ID
configOPS_ALERT_FEISHU_APP_ID
🔐 secretOPS_ALERT_FEISHU_APP_SECRET
configCHANJET_TOKEN_ALERT_INTERVAL_SECONDS
configCHANJET_TOKEN_ALERT_ENABLED
configQUALITY_REPORT_MAX_UPLOAD_MB
configTPLUS_BOM_SYNC_REQUEST_DIR
configRECIPE_CACHE_WARM_INTERVAL
configRECIPE_CACHE_WARM
configTPLUS_BOM_WRITE_ENABLED
configVERSION_DIGEST_FEISHU_RECEIVE_ID
configWECOM_RND_DOCID
configWECOM_RND_SOURCE_SHEET
configWECOM_GROUP_MEDIA_DIR
configDOC_SYNC_INTERVAL_SECONDS
configTPLUS_PARENT_MATCH_WECOM_PROFILE
configTPLUS_PARENT_MATCH_DOCUMENT
configTPLUS_PARENT_MATCH_SHEET
configTPLUS_PARENT_MATCH_CHAT_ID
configTPLUS_PARENT_MATCH_FEISHU_PROFILE
configWECOM_STRUCTURE_BACKUP_ENABLED
configWECOM_STRUCTURE_BACKUP_MAX_SHEETS
configWECOM_DOC_ADMIN_USERS
configWECOM_STRUCTURE_BACKUP_PROFILE
configWECOM_STRUCTURE_BACKUP_DOCID
configFEISHU_ENV_PROFILES
configFEISHU_ENV_PROFILE
configWECOM_ENV_PROFILES
configCHANJET_AUTO_EXCHANGE_OAUTH_CODE
configCHANJET_CERTIFICATE
configCHANJET_CERTIFICATE_FILE
configCHANJET_EVENT_SPOOL_DIR
🔐 secretCHANJET_WEBHOOK_AES_KEY
configCHANJET_WEBHOOK_AES_KEY_FILE
configCHANJET_OPENAPI_BASE_URL
configFEISHU_WEBHOOK_REQUIRE_SIGNATURE
configFEISHU_EVENT_SPOOL_DIR
configWECOM_KF_POLL_INTERVAL_SECONDS
configTPLUS_BOM_WRITE_POLL_SECONDS
configTPLUS_DB_SYNC_REQUESTS_ENABLED
configPRICE_SYNC_BEGIN_DATE
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployDATABASE_URL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

8/8 tools missing one or more hints — ping (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); server_info (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_coding_targets (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +5 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

6/8 tool handlers declare input schemas (75%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

6/8 tool handlers wrap calls in try/catch (75%)

Wrap each tool handler body in try/catch and return a structured error response.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/huozao-aliecs-1sd1f9)](https://m8ven.ai/mcp/huozao-aliecs-1sd1f9)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: e6bc5ce73eac7e9f2d701a23100d7b34a124c3a7
code hash: 238de4aeedf9ffc4b551d8063c165f10906a18899ac279e187501566310adde4
verified: 8/8/2026, 8:03:04 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client