C
Warning
74/100
2 days ago

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

ipJoseph

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
4 flows detected: FUB_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 21 credentials: AUTH_SECRET, GOOGLE_CLIENT_SECRET, FUB_API_KEY, FLASK_SECRET_KEY, DREAMS_API_KEY, NOTION_API_KEY, DASHBOARD_PASSWORD, CLIENT_PORTFOLIO_KEY, GOOGLE_MAPS_API_KEY, IPQS_API_KEY, HIVE_TOKEN, MLSGRID_TOKEN, NAVICA_BBO_TOKEN, NAVICA_IDX_TOKEN, BROWSERLESS_TOKEN, PROXY_PASS, LINEAR_API_KEY, FUB_SYSTEM_KEY, TODOIST_API_TOKEN, TODOIST_WEBHOOK_SECRET, CRAWL_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretAUTH_SECRET
configDREAMS_ENVdev # dev or prd
configGOOGLE_CLIENT_ID
🔐 secretGOOGLE_CLIENT_SECRET
configDREAMS_DB_PATH
🔐 secretFUB_API_KEY
configFUB_BASE_URL
🔐 secretFLASK_SECRET_KEY
configFLASK_DEBUG
configCORS_ALLOWED_ORIGINS
🔐 secretDREAMS_API_KEYxxx # X-API-Key header
🔐 secretNOTION_API_KEY
configNOTION_PROPERTIES_DB_ID
configDISABLE_NOTION_SYNC
configDASHBOARD_USERNAME
🔐 secretDASHBOARD_PASSWORD
🔐 secretCLIENT_PORTFOLIO_KEY
configFUB_MY_USER_ID
configFUB_MY_USER_NAME
🔐 secretGOOGLE_MAPS_API_KEY
configAGENT_HOME_ADDRESS
configGOOGLE_SHEET_ID
configDREAMS_PHOTOS_DIR
🔐 secretIPQS_API_KEY
configDASHBOARD_URL
configAGENT_EMAIL
configAGENT_NAME
configAGENT_LICENSE
configAGENT_PHONE
configAGENT_WEBSITE
configAGENT_OFFICE
configEMAIL_FROM_NAME
configBROKERAGE_NAME
configAGENT_HEADSHOT_URL
configBROKERAGE_LOGO_URL
configWEEKLY_SUMMARY_RECIPIENT
configMONTHLY_REPORT_RECIPIENT
configNEW_LISTING_MATCH_THRESHOLD
configALERT_LOOKBACK_HOURS
configTRACKED_COUNTIES
configAUTOMATION_LOG_LEVEL
configPUBLIC_SITE_URL
configGOOGLE_BACKUP_SHEET_ID
configEMAIL_TO
configEMAIL_SUBJECT_PREFIX
configSQLITE_SYNC_ENABLED
configREQUEST_SLEEP_SECONDS
configDEFAULT_FETCH_LIMIT
configMAX_PARALLEL_WORKERS
configENABLE_STAGE_SYNC
configENABLE_CACHE
configCACHE_MAX_AGE_MINUTES
configCALL_LIST_MIN_PRIORITY
configCALL_LIST_MAX_ROWS
configEXCLUDE_LEAD_IDS
configEXCLUDE_EMAILS
configFUB_USER_ID
configFETCH_POND_IDS_ALL
configFETCH_POND_ID_CAPPED
configFETCH_POND_CAP
configENABLE_SHEETS_BACKUP
🔐 secretHIVE_TOKEN
🔐 secretMLSGRID_TOKEN
configMLSGRID_USE_DEMO
configNAVICA_API_URL
configNAVICA_DATASET_CODE
🔐 secretNAVICA_BBO_TOKEN
🔐 secretNAVICA_IDX_TOKEN
configIDX_EMAIL
configIDX_PHONE
🔐 secretBROWSERLESS_TOKEN
configPROXY_HOST
configPROXY_PORT
configPROXY_USER
🔐 secretPROXY_PASS
configFORCE_LOCAL_BROWSER
configSKIP_PROXY
configDISPLAY
configHEAT_WEIGHT_WEBSITE_VISIT
configHEAT_WEIGHT_PROPERTY_VIEWED
configHEAT_WEIGHT_PROPERTY_FAVORITED
configHEAT_WEIGHT_PROPERTY_SHARED
configHEAT_WEIGHT_CALL_INBOUND
configHEAT_WEIGHT_TEXT_INBOUND
configRECENCY_BONUS_0_3_DAYS
configRECENCY_BONUS_4_7_DAYS
configRECENCY_BONUS_8_14_DAYS
configRECENCY_BONUS_15_30_DAYS
configPRIORITY_WEIGHT_HEAT
configPRIORITY_WEIGHT_VALUE
configPRIORITY_WEIGHT_RELATIONSHIP
configSTAGE_MULTIPLIER_HOT_LEAD
configSTAGE_MULTIPLIER_ACTIVE_BUYER
configSTAGE_MULTIPLIER_ACTIVE_SELLER
configSTAGE_MULTIPLIER_NURTURE
configSTAGE_MULTIPLIER_NEW_LEAD
configSTAGE_MULTIPLIER_COLD
configSTAGE_MULTIPLIER_CLOSED
configSTAGE_MULTIPLIER_TRASH
configLINEAR_SYNC_ENV
🔐 secretLINEAR_API_KEY
configFUB_SYSTEM_NAME
🔐 secretFUB_SYSTEM_KEY
configLINEAR_POLL_INTERVAL
configFUB_POLL_INTERVAL
configDEAL_CACHE_REFRESH
configLINEAR_SYNC_API_HOST
configLINEAR_SYNC_API_PORT
configLINEAR_SYNC_LOG_LEVEL
configLINEAR_DEVELOP_TEAM_ID
configLINEAR_TRANSACT_TEAM_ID
configLINEAR_GENERAL_TEAM_ID
configLINEAR_FUB_SYNCED_LABEL_ID
configTASK_SYNC_ENV
🔐 secretTODOIST_API_TOKEN
configTODOIST_USE_WEBHOOKS
🔐 secretTODOIST_WEBHOOK_SECRET
configTODOIST_POLL_INTERVAL
configTASK_SYNC_API_HOST
configTASK_SYNC_API_PORT
configTASK_SYNC_LOG_LEVEL
configCRAWL_TARGET
configCRAWL_USER
🔐 secretCRAWL_PASSWORD
configDREAMS_LOG_LEVEL
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployNEXT_PUBLIC_API_URL
deployNEXT_PUBLIC_GOOGLE_AUTH_ENABLED
deployNEXT_PUBLIC_GOOGLE_MAPS_API_KEY
deployNEXT_PUBLIC_GOOGLE_MAPS_KEY
deployNEXT_PUBLIC_SUPABASE_ANON_KEY
deployNEXT_PUBLIC_SUPABASE_URL
deployDATABASE_URL
deployFUB_APP_URL
deploySMTP_ENABLED
deploySMTP_SERVER
deploySMTP_PORT
deploySMTP_USERNAME
deploySMTP_PASSWORD
deploySENTRY_DSN
deploySENTRY_TRACES_SAMPLE_RATE
deploySENTRY_RELEASE
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

18/18 tools missing one or more hints — call_tool (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); query_leads (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); query_properties (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +15 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tool test coverage

Only 1/18 tools referenced in tests (6%)

Write tests that reference each tool by name so every tool has at least one test.

Secrets stay with their owner

4 secret/sensitive values flow into network calls (FUB_API_KEY → dynamic, FUB_API_KEY → dynamic)

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/ipjoseph-mydreams-11i7g3?variant=verified)](https://m8ven.ai/mcp/ipjoseph-mydreams-11i7g3)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: f63d2061146a4283596c2c99359a43e07508a65b
code hash: 345ed70097b5f6274f5e3c595879eeecfa1d189052347149375ea7cce574d6b0
verified: 8/16/2026, 6:52:59 PM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client