vibegate-security-playground (jiarong0423/vibegate-security-playground) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 1 tool. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.

B
Emerging
89/100

vibegate-security-playground

Agentic security playground for Strands SDK & Amazon Nova. Demonstrates runtime tool interception with zero-execution evidence against prompt injection.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored

every push re-verified

Who stands behind it

gmail.com (@jiarong0423) · Verified Publisher

Source: github_repo_search

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
Are you the publisher? Confirm or correct these findings.
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

4/4 tools missing one or more hints — read_synthetic_sample (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); read_synthetic_sample (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); send_synthetic_sample (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +1 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

3/4 tools referenced in tests (75%)

Write tests that reference each tool by name so every tool has at least one test.

// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/jiarong0423/vibegate-security-playground)](https://m8ven.ai/mcp/jiarong0423/vibegate-security-playground)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: da52b06d96a8c3e99432ca4fbabfeae405a3197b
code hash: b550d30b2db6d59695c6a885133c3785ad6952e081bfb36053884481edca8616
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client