rel-ai-chatgpt-web-harness (Kyne0328/rel-ai-chatgpt-web-harness) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 11 tools. No publisher has claimed this listing.

C
Warning
74/100

rel-ai-chatgpt-web-harness

Local agency/runtime harness for ChatGPT Web: repositories, tasks, commands, validation, Git, skills/memory, observability, and opt-in computer control.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Kyne0328

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Code appears obfuscated
2 files are unreadable to a human reviewer. Cannot audit what they do.
🔐
You'll be asked for 2 credentials: REL_AI_MCP_TOKEN, REL_AI_REQUEST_STATE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes11 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

relai_work

Manages one optional durable workspace task: begin, status, finish, or cancel. Status also reports fallback operations that outlive a connector request.

relai_search

Provides lexical or semantic discovery across repository content.

relai_inspect

Provides read-only symbol, reference, impact, trace, diagnostic, and architecture analysis.

relai_process

Manages persistent services, watchers, and interactive programs with stable process identity. Startup accepts direct executable + argv or a command string; one-shot work belongs in relai_exec or relai_validate.

relai_ui

Bounded QA for an allowed localhost app: snapshots, interactions, screenshots, console/network capture, viewport changes, and reloads. General machine-local browsing belongs in relai_browser; public web stays host-owned.

relai_browser

Local browser for localhost/LAN/intranet/VPN, machine-authenticated sessions, and workspace file transfer. Semantic snapshots explain page content, layout snapshots cover geometry/overflow, and screenshots provide pixel evidence. Public web stays host-owned.

relai_desktop

Structured local OS actions without pointer/keyboard simulation: open or reveal workspace paths, open URIs, launch apps, and read/write bounded clipboard text. relai_computer is the UI fallback.

relai_computer

User-authorized final fallback for local desktop input after structured local and browser capabilities. Windows uses UI Automation first, optional built-in OCR hybrid targeting for custom text UI, and Midscene pixels only when semantics cannot perform the action. activate revalidates targets and pre

relai_validate

Runs explicit repository checks, diagnostics, or local HTTP validation. Validation is factual repository evidence and may run directly against an authorized workspace; work_id optionally records task provenance.

relai_changes

Reviews, checkpoints or replays reviews, restores, resets, or tidies workspace changes. Read-only review/replay and explicitly scoped restore/reset can use an authorized workspace when their action contract permits.

relai_publish

Commits repository changes, pushes Git branches, or drafts PR text. Commit scope defaults to task-owned paths unless explicit paths or addAll are supplied. Commit, push, and draft-PR actions may use an authorized workspace directly. Real push remains approval-gated.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configREL_AI_FRONTEND_BACKEND
configREL_AI_MCP_ALLOW_NO_AUTH
configREL_AI_MCP_HOST
configREL_AI_MCP_ISOLATED
configREL_AI_MCP_MAX_BODY_BYTES
configREL_AI_MCP_MAX_TOOL_RESULT_BYTES
configREL_AI_MCP_MAX_TOOL_RESULT_CHARS
configREL_AI_MCP_MAX_TOOL_TEXT_BYTES
configREL_AI_MCP_NO_PROFILE_WRITE
configREL_AI_MCP_PORT
configREL_AI_MCP_TASK_IDLE_MS
🔐 secretREL_AI_MCP_TOKEN
🔐 secretREL_AI_REQUEST_STATE_KEY
// quality suggestions

Dependencies

28 runtime dependencies (19 dev), 1 flagged: playwright-core

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

11/11 tools missing one or more hints — relai_work (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); relai_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); relai_inspect (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +8 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Readable source code

2 files are minified or bundled, which is usually build output rather than concealment

Ship unminified, readable source.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/kyne0328/rel-ai-chatgpt-web-harness?variant=verified)](https://m8ven.ai/mcp/kyne0328/rel-ai-chatgpt-web-harness)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 103f8ff626359cdcb1b6b0cdc88ab659b75d2310
code hash: a02bd54f3755aaeaaed1a6b2def56077a64296df867f4a7988b43329f72bf2b7
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client