jiarong0423/ai-security-rules (jiarong0423/ai-security-rules) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 3 tools. The publisher has proved control of what we score (Verified Publisher).

B
Emerging
89/100

jiarong0423/ai-security-rules

Read-only local security gate & scanner for AI coding workflows, MCP, and package hallucination risks.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

gmail.com (@jiarong0423) · Verified Publisher

Source: github_app_install

⚡ Upgrade to Live Monitored

Connect your repo and M8ven re-verifies it on the push itself. Without it we re-check verified listings about once a day, so a fix can sit unseen. Read-only, one click, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
Are you the publisher? Confirm or correct these findings.
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

3/3 tools missing one or more hints — run_vibegate_agent_review (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); read_vibegate_queue (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); recommend_agent_next_action (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/jiarong0423/ai-security-rules)](https://m8ven.ai/mcp/jiarong0423/ai-security-rules)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: a6a034f0215fa6e3272bba11c0ae2ef9b6deee1b
code hash: 4359428ba6a665eebd8a89c4be1d0154a6bc004e4c012f043d6c1317f0d893b8
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client