maxia-mcp (majorelalexis-stack/maxia) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 40 tools. No publisher has claimed this listing.

C
Warning
74/100

maxia-mcp

AI-to-AI marketplace MCP server with 46 tools — swap 65+ crypto tokens on 7 chains, rent GPUs, trade 25 tokenized stocks, on-chain escrow (Solana + Base), DeFi yields, sentiment analysis, wallet monitoring, and image generation. Supports USDC payments across 14 blockchains.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

majorelalexis-stack

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
28 flows detected: DISCORD_ASSISTANT_TOKEN, TELEGRAM_BOT_TOKEN, DISCORD_BOT_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🚨
Code appears obfuscated
1 file are unreadable to a human reviewer. Cannot audit what they do.
🔐
You'll be asked for 33 credentials: MAXIA_API_KEY, RUNPOD_API_KEY, CEO_API_KEY, DISCORD_ASSISTANT_TOKEN, TELEGRAM_BOT_TOKEN, DISCORD_BOT_TOKEN, GITHUB_TOKEN, REDDIT_CLIENT_SECRET, REDDIT_PASSWORD, ADMIN_KEY, MISTRAL_API_KEY, EMAIL_PASSWORD, CREDIT_SCORE_SECRET, JWT_SECRET, AGENTID_API_KEY, AGENTOPS_API_KEY, TOGETHER_API_KEY, CEREBRAS_API_KEY, GOOGLE_AI_KEY, GROQ_API_KEY, ANTHROPIC_API_KEY, LUNARCRUSH_API_KEY, STRIPE_SECRET_KEY, BLOCKFROST_API_KEY, LNBOT_API_KEY, SUBSCAN_API_KEY, ADMIN_TOTP_SECRET, HELIUS_API_KEY, ALCHEMY_SOLANA_KEY, AKASH_API_KEY, KITE_API_KEY, AP2_SIGNING_KEY, FINNHUB_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configHOST
🔐 secretMAXIA_API_KEY
configMAXIA_BASE_URL
configENV
configBROKER_MARGIN
configAUCTION_DURATION_S
🔐 secretRUNPOD_API_KEY
configSANDBOX_MODE
configFORCE_HTTPS
configPROD_MODE
configCORS_ORIGINS
🔐 secretCEO_API_KEY
🔐 secretDISCORD_ASSISTANT_TOKEN
🔐 secretTELEGRAM_BOT_TOKEN
configTELEGRAM_ALERT_CHAT_ID
🔐 secretDISCORD_BOT_TOKEN
configDISCORD_CHANNEL_ID
🔐 secretGITHUB_TOKEN
configREDDIT_CLIENT_ID
🔐 secretREDDIT_CLIENT_SECRET
configREDDIT_USERNAME
🔐 secretREDDIT_PASSWORD
configKASPA_MINING_ENABLED
configVPS_URL
🔐 secretADMIN_KEY
configDISCORD_WEBHOOK_URL
configTELEGRAM_CHAT_ID
configTELEGRAM_CEO_CHAT_ID
configTELEGRAM_ALEXIS_USER_ID
configOLLAMA_URL
configOLLAMA_MODEL_FAST
configVISION_MODEL
configOLLAMA_NUM_CTX
configOLLAMA_FLASH_ATTENTION
configOLLAMA_KEEP_ALIVE
🔐 secretMISTRAL_API_KEY
configMISTRAL_MODEL
configBROWSER_PROFILE_DIR
configEMAIL_RAMP_UP_DAYS
configEMAIL_RAMP_UP_START
configTEAMREDMINER_DIR
configEMAIL_ADDRESS
🔐 secretEMAIL_PASSWORD
configIMAP_SERVER
configIMAP_PORT
configEMAIL_BOUNCE_PAUSE_PCT
configEMAIL_REPLY_FLOOR_PCT
configEMAIL_REP_WINDOW_DAYS
configMAXIA_VPS_BASE
configMAXIA_A2A_SIGNING_KEY_HEX
🔐 secretCREDIT_SCORE_SECRET
🔐 secretJWT_SECRET
configAGENTID_API_URL
🔐 secretAGENTID_API_KEY
configAGENTID_ENABLED
🔐 secretAGENTOPS_API_KEY
configENVIRONMENT
🔐 secretTOGETHER_API_KEY
configOLLAMA_MODEL
🔐 secretCEREBRAS_API_KEY
configCEREBRAS_MODEL
🔐 secretGOOGLE_AI_KEY
configGOOGLE_AI_MODEL
🔐 secretGROQ_API_KEY
🔐 secretANTHROPIC_API_KEY
🔐 secretLUNARCRUSH_API_KEY
🔐 secretSTRIPE_SECRET_KEY
configSTRIPE_PRICE_PREMIUM_API
configREFERRAL_COMMISSION_PCT
configREFERRAL_RATE_BPS
configMAX_REFERRAL_EARNED_USD
configARBITRUM_RPC
configARBITRUM_MIN_TX_USDC
configAVALANCHE_RPC
configAVALANCHE_MIN_TX_USDC
configBASE_RPC
configESCROW_CONTRACT_BASE
configBNB_RPC
configBNB_MIN_TX_USDC
🔐 secretBLOCKFROST_API_KEY
configBRIDGE_SLIPPAGE_PCT
configTREASURY_ADDRESS_NEAR
configTREASURY_ADDRESS_APTOS
configTREASURY_ADDRESS_SEI
configTREASURY_ADDRESS_BASE
🔐 secretLNBOT_API_KEY
configLNBOT_WALLET_ID
🔐 secretSUBSCAN_API_KEY
configPOLYGON_RPC
configPOLYGON_MIN_TX_USDC
configXRPL_RPC
🔐 secretADMIN_TOTP_SECRET
configTREASURY_ADDRESSFiYWC9NGUdCbRdNftajVDTpY3siQQUtcaHk58ZvEAE4h
configESCROW_ADDRESS58qNUncK41FjkFaQNkkuzzzxP8Gm9CAUSMQ16nWYvGKP
configESCROW_PRIVKEY_B582. NE JAMAIS partager ta
configESCROW_PROGRAM_ID
configSOLANA_RPC
🔐 secretHELIUS_API_KEY
configCHAINSTACK_RPC
🔐 secretALCHEMY_SOLANA_KEY
configFEE_BPS
configTRUSTED_PROXY_IPS
configGROQ_MODEL
🔐 secretAKASH_API_KEY
configAKASH_WALLET
configAKASH_ENABLED
configMARKETING_WALLET_ADDRESS
configMARKETING_WALLET_PRIVKEY
configMICRO_WALLET_ADDRESS
configMICRO_WALLET_PRIVKEY
configBASE_MIN_TX_USDC
configETH_RPC
configTREASURY_ADDRESS_ETH
configETH_MIN_TX_USDC
configKITE_API_URL
🔐 secretKITE_API_KEY
configKITE_AGENT_ID
configKITE_AIR_URL
configAP2_ENABLED
configAP2_AGENT_ID
🔐 secretAP2_SIGNING_KEY
configX402_FACILITATOR_URL
🔐 secretFINNHUB_API_KEY
configWEB_CONCURRENCY
configAGENT_TIMEOUT_S
configGROWTH_MAX_PROSPECTS_PER_DAY
configGROWTH_MAX_SPEND_PER_DAY_USDC
configGROWTH_MAX_SPEND_PER_TX_USDC
configGROWTH_MIN_PROSPECT_SOL
configGROWTH_MONTHLY_BUDGET_USDC
configGROWTH_RESERVE_ALERT_USDC
configTELEGRAM_CHANNEL
configPROSPECT_MIN_SOL
configPROSPECT_MAX_PER_DAY
configPROSPECT_COOLDOWN_DAYS
configDYNAMIC_PRICING_ENABLED
configDYNAMIC_PRICING_MIN_BPS
configDYNAMIC_PRICING_MAX_BPS
configDYNAMIC_PRICING_VOLUME_THRESHOLD_PCT
configLIFI_API_URL
configBRIDGE_ENABLED
configSTAKING_MIN_USDC
configSTAKING_SLASH_PCT
configSTAKING_DISPUTE_DELAY_H
configSCALE_OUT_QUEUE_THRESHOLD
configSCALE_OUT_COOLDOWN_S
configFINETUNE_SERVICE_FEE
configFINETUNE_GPU_MARKUP
configCURRENCY_SLIPPAGE_PCT
configXRPL_USDC_ISSUER
configTREASURY_ADDRESS_XRPL
configTON_API_URL
configTREASURY_ADDRESS_TON
configSUI_RPC
configTREASURY_ADDRESS_SUI
configTREASURY_ADDRESS_POLYGON
configTREASURY_ADDRESS_ARBITRUM
configTREASURY_ADDRESS_AVALANCHE
configTREASURY_ADDRESS_BNB
configZKSYNC_RPC
configTREASURY_ADDRESS_ZKSYNC
configLINEA_RPC
configTREASURY_ADDRESS_LINEA
configSCROLL_RPC
configTREASURY_ADDRESS_SCROLL
configSONIC_RPC
configTREASURY_ADDRESS_SONIC
configCOSMOS_LCD_URL
configTREASURY_ADDRESS_COSMOS
configHEDERA_MIRROR_URL
configTREASURY_ADDRESS_HEDERA
configTREASURY_ADDRESS_CARDANO
configTREASURY_ADDRESS_POLKADOT
configTREASURY_ADDRESS_BITCOIN
configTRON_API_URL
configTREASURY_ADDRESS_TRON
configNEAR_RPC
configAPTOS_API
configSEI_RPC
configSEI_MIN_TX_USDC
configCEO_LOCAL_MODE
configCEO_ALLOWED_IPS
configFOUNDER_IP
configAUDIT_BUFFER_SIZE
configAUDIT_RETENTION_DAYS
configPOLICY_MAX_SINGLE_TRADE
configPOLICY_MAX_DAILY_VOLUME
configPOLICY_MAX_SWAPS_HOUR
configPOLICY_MAX_ESCROW
configPOLICY_KYC_THRESHOLD
configBILLING_ENABLED
configMETRICS_ENABLED
configMETRICS_PREFIX
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deploySENTRY_DSN
deployDATABASE_URL
deploySMTP_SERVER
deploySMTP_PORT
deployPORT
deployREDIS_URL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

40/40 tools missing one or more hints — maxia_discover (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); maxia_execute (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); maxia_gpu_tiers (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +37 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

Only 0/40 tools referenced in tests (0%)

Write tests that reference each tool by name so every tool has at least one test.

Readable source code

1 file are minified or bundled, which is usually build output rather than concealment

Ship unminified, readable source.

Secrets not logged

8 secret values sent to logger.error/logger.warning/print/log.warning

Redact or omit secret values from log output.

Domain consistency

npm scope @maxia doesn't match GitHub owner majorelalexis-stack

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/majorelalexis-stack/maxia?variant=verified)](https://m8ven.ai/mcp/majorelalexis-stack/maxia)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 2f545d04db4b36a02cee3fe7b01c07b77bd7c9bc
code hash: 074a3791917d46c54f9e3bd7f0676fdb0108bc328232a73f798ccb390c55ebf1
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client