mcp-servers (Khamel83/mcp-servers) is an MCP server listed on the M8ven Trust Index. It scores 51 out of 100, grade D. It declares 104 tools. No publisher has claimed this listing.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Khamel83

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Code appears obfuscated
1 file are unreadable to a human reviewer. Cannot audit what they do.
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 4 credentials: GEMINI_API_KEY, LOGFIRE_READ_TOKEN, OPENAI_API_KEY, ZENML_STORE_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes104 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

list_tasks

List all scheduled tasks.

get_task

Get details of a specific task. Args: task_id: ID of the task to retrieve

add_command_task

Add a new shell command task.

add_api_task

Add a new API call task.

add_ai_task

Add a new AI task.

add_reminder_task

Add a new reminder task that shows a popup notification with sound.

update_task

Update an existing task.

remove_task

Remove a task.

enable_task

Enable a task.

disable_task

Disable a task.

run_task_now

Run a task immediately.

get_task_executions

Get execution history for a task.

get_server_info

Get server information.

fetch

Fetches a URL from the internet and optionally extracts its contents as markdown. Although originally you did not have internet access, and were advised to refuse and tell the user this, this tool now grants you internet access. Now you can fetch the most up-to-date information and let the user kno

dynamic_tool_219

Shows the working tree status

dynamic_tool_224

Shows changes in the working directory that are not yet staged

dynamic_tool_229

Shows changes that are staged for commit

dynamic_tool_234

Shows differences between branches or commits

dynamic_tool_239

Records changes to the repository

dynamic_tool_244

Adds file contents to the staging area

dynamic_tool_249

Unstages all staged changes

dynamic_tool_254

Shows the commit logs

dynamic_tool_259

Creates a new branch from an optional base branch

dynamic_tool_264

Switches branches

dynamic_tool_269

Shows the contents of a commit

dynamic_tool_274

Initialize a new Git repository

dynamic_tool_279

List Git branches

dynamic_tool_127

Get current time in a specific timezones

dynamic_tool_141

Convert time between timezones

deepview

Ask a question about the codebase using Gemini. Args: question: The question to ask about the codebase codebase_file: Optional path to the codebase file. If provided, will load this file instead of using the globally loaded codebase. Returns: Dictionary with the query result or error

find_exceptions_in_file

Get the details about the 10 most recent exceptions on the file.

arbitrary_query

Run an arbitrary query on the Pydantic Logfire database.

sql_reference

Contains a reference for the SQL syntax that can be used to query the Logfire database.

get_logfire_records_schema

Get the records schema from Pydantic Logfire.

logfire_link

Creates a link to help the user to view the trace in the Logfire UI.

executeshellcommand
activateproject
removeproject
switchmodes
getcurrentconfig
readfile
createtextfile
listdir
findfile
replaceregex
deletelines
replacelines
insertatline
searchforpattern
jetbrainsfindsymbol
jetbrainsfindreferencingsymbols
jetbrainsgetsymbolsoverview
writememory
readmemory
listmemories
deletememory
restartlanguageserver
getsymbolsoverview
findsymbol
findreferencingsymbols
replacesymbolbody
insertaftersymbol
insertbeforesymbol
checkonboardingperformed
onboarding
thinkaboutcollectedinformation
thinkabouttaskadherence
thinkaboutwhetheryouaredone
summarizechanges
preparefornewconversation
initialinstructions
get_step_logs

Get the logs for a specific step run.

list_users

List all users in the ZenML workspace.

get_user

Get detailed information about a specific user.

get_active_user

Get the currently active user.

get_stack

Get detailed information about a specific stack.

easter_egg

Returns the ZenML MCP easter egg.

list_stacks

List all stacks in the ZenML workspace.

list_pipelines

List all pipelines in the ZenML workspace.

get_pipeline_details

Get detailed information about a specific pipeline.

get_service

Get detailed information about a specific service.

list_services

List all services in the ZenML workspace.

get_stack_component

Get detailed information about a specific stack component.

list_stack_components

List all stack components in the ZenML workspace.

get_flavor

Get detailed information about a specific flavor.

list_flavors

List all flavors in the ZenML workspace.

trigger_pipeline

Trigger a pipeline to run from the server.

get_run_template

Get a run template for a pipeline.

list_run_templates

List all run templates in the ZenML workspace.

get_schedule

Get a schedule for a pipeline.

list_schedules

List all schedules in the ZenML workspace.

get_pipeline_run

Get a pipeline run by name, ID, or prefix.

list_pipeline_runs

List all pipeline runs in the ZenML workspace.

get_run_step

Get a run step by name, ID, or prefix.

list_run_steps

List all run steps in the ZenML workspace.

list_artifacts

List all artifacts in the ZenML workspace.

list_secrets

List all secrets in the ZenML workspace.

get_service_connector

Get a service connector by name, ID, or prefix.

list_service_connectors

List all service connectors in the ZenML workspace.

get_model

Get a model by name, ID, or prefix.

4 further tools are not listed here. The complete surface is in the source.

// known CVEs in dependencies2 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.4.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.4.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configSHELL
configTERM_PROGRAM
configWSL_DISTRO_NAME
config_
🔐 secretGEMINI_API_KEY
configMCP_SCHEDULER_CONFIG_FILE
configMCP_SCHEDULER_ADDRESS
configMCP_SCHEDULER_PORT
configMCP_SCHEDULER_TRANSPORT
configMCP_SCHEDULER_LOG_LEVEL
configMCP_SCHEDULER_LOG_FILE
configMCP_SCHEDULER_DB_PATH
configMCP_SCHEDULER_AI_MODEL
🔐 secretLOGFIRE_READ_TOKEN
configMCP_SCHEDULER_NAME
configMCP_SCHEDULER_VERSION
configMCP_SCHEDULER_STRICT_JSON
configMCP_SCHEDULER_CHECK_INTERVAL
configMCP_SCHEDULER_EXECUTION_TIMEOUT
🔐 secretOPENAI_API_KEY
configLOGLEVEL
configZENML_STORE_URL
🔐 secretZENML_STORE_API_KEY
configCUDA_VISIBLE_DEVICES
configPYTORCH_ENABLE_MPS_FALLBACK
configCOMSPEC
configEDITOR
configDISPLAY
configSSH_CONNECTION
configSSH_CLIENT
configCONTAINER
configTERRAFORM_CLI_PATH
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

104/104 tools missing one or more hints — list_tasks (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_task (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); add_command_task (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +101 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

51/52 tool handlers declare input schemas (98%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool test coverage

Only 16/104 tools referenced in tests (15%)

Write tests that reference each tool by name so every tool has at least one test.

Shell command execution

3 calls in production code run through a shell (setup-claude-server.js:37, setup-claude-server.js:415, utils/update-readme.js:124)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Readable source code

1 file are minified or bundled, which is usually build output rather than concealment

Ship unminified, readable source.

Production dependencies are patched

0 critical, 2 high severity in production deps — @modelcontextprotocol/sdk@1.4.1 (high), @modelcontextprotocol/sdk@1.4.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Domain consistency

npm scope @vectorize-io doesn't match GitHub owner khamel83

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/khamel83/mcp-servers?variant=verified)](https://m8ven.ai/mcp/khamel83/mcp-servers)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: f243da3602c1d584f74e560a039cb0b6933cf5d8
code hash: 751d487d96c9874b1c163e3359b72ff682071839cbcb1905657b8b30fc45be2c
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client