C
Warning
74/100
2 days ago

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

mansourMP

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
11 flows detected: API_WALL_SMOKE_PASSWORD, STABILITY_API_KEY, EMPYRALIS_CERT_RUNTIME_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 59 credentials: EMPYRALIS_BLUEBUBBLES_PASSWORD, EMPYRALIS_IMESSAGE_BRIDGE_TOKEN, EMPYRALIS_SIGNAL_BRIDGE_TOKEN, GOOGLE_AUTH_CLIENT_SECRET, GOOGLE_AUTH_WEB_CLIENT_SECRET, GOOGLE_CLIENT_SECRET, GOOGLE_OAUTH_CLIENT_SECRET, GOOGLE_WEB_CLIENT_SECRET, OPENAI_API_KEY, RUNTIME_KEY, ORION_API_KEY, EMPYRALIS_TOOL_BROKER_SECRET, EMPYRALIS_SECRETS_BROKER_SECRET, STABILITY_API_KEY, EMPYRALIS_PLATFORM_REGISTRY_KEY, OPENAI_ACCESS_TOKEN, ANTHROPIC_API_KEY, GEMINI_API_KEY, GOOGLE_API_KEY, VERTEX_ACCESS_TOKEN, EMPYRALIS_SUPERVISOR_SECRET, EMPYRALIS_CERT_SELF_HOSTED_NODE_TOKEN, EMPYRALIS_CERT_PASSWORD, EMPYRALIS_CERT_BEARER_TOKEN, EMPYRALIS_CERT_RUNTIME_KEY, ORION_MACHINE_ENROLLMENT_TOKEN, CREW_API_KEY, ORION_DISABLE_OPENAI_API_KEY, ORION_LOCAL_WORKER_OPENAI_TOKEN, CODEX_OAUTH_TOKEN, OPENAI_OAUTH_TOKEN, ORION_LOCAL_WORKER_OPENAI_API_KEY, ORION_LOCAL_WORKER_ANTHROPIC_API_KEY, ORION_LOCAL_WORKER_GEMINI_API_KEY, ORION_LOCAL_WORKER_QWEN_API_KEY, QWEN_API_KEY, DASHSCOPE_API_KEY, ORION_LOCAL_WORKER_DEEPSEEK_API_KEY, DEEPSEEK_API_KEY, ORION_LOCAL_WORKER_MISTRAL_API_KEY, MISTRAL_API_KEY, ORION_LOCAL_WORKER_GROQ_API_KEY, GROQ_API_KEY, ORION_LOCAL_WORKER_OPENROUTER_API_KEY, OPENROUTER_API_KEY, ORION_LOCAL_WORKER_AZURE_OPENAI_API_KEY, AZURE_OPENAI_API_KEY, ORION_LOCAL_WORKER_CUSTOM_OPENAI_COMPATIBLE_API_KEY, CUSTOM_OPENAI_COMPATIBLE_API_KEY, ORION_LOCAL_WORKER_OLLAMA_CLOUD_API_KEY, OLLAMA_API_KEY, CLOUD_SESSION_HMAC_SECRET, API_SECRET, EMPYRALIS_VISION_API_KEY, EMPYRALIS_STRIPE_SECRET_KEY, STRIPE_SECRET_KEY, EMPYRALIS_STRIPE_WEBHOOK_SECRET, EMPYRALIS_API_KEY, DISCORD_APP_PUBLIC_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configEAS_BUILD_PROFILE
configEAS_PROJECT_ID
configEMPYRALIS_AUTH_ALLOWED_ORIGINS
🔐 secretEMPYRALIS_BLUEBUBBLES_PASSWORD
configEMPYRALIS_BLUEBUBBLES_SERVER_URL
configEMPYRALIS_IMESSAGE_BRIDGE_PORT
🔐 secretEMPYRALIS_IMESSAGE_BRIDGE_TOKEN
configEMPYRALIS_LOCAL_BRIDGE_HARNESS_PORT
configEMPYRALIS_SIGNAL_BRIDGE_PORT
🔐 secretEMPYRALIS_SIGNAL_BRIDGE_TOKEN
configEMPYRALIS_SIGNAL_CLI_ACCOUNT
configEMPYRALIS_SIGNAL_CLI_RPC_URL
configEMPYRALIS_WEB_URL
configEXPO_PUBLIC_API_URL
configEXPO_PUBLIC_APP_ENV
configEXPO_PUBLIC_EAS_PROJECT_ID
configEXPO_PUBLIC_EMPYRALIST_API_URL
configEXPO_PUBLIC_EMPYRALIS_DEPLOY_ENV
configEXPO_PUBLIC_RUNTIME_URL
configEXPO_PUBLIC_UPDATES_URL
configGOOGLE_AUTH_CLIENT_ID
🔐 secretGOOGLE_AUTH_CLIENT_SECRET
configGOOGLE_AUTH_WEB_CLIENT_ID
🔐 secretGOOGLE_AUTH_WEB_CLIENT_SECRET
configGOOGLE_CLIENT_ID
🔐 secretGOOGLE_CLIENT_SECRET
configGOOGLE_OAUTH_CLIENT_ID
🔐 secretGOOGLE_OAUTH_CLIENT_SECRET
configGOOGLE_OAUTH_REDIRECT_URI
configGOOGLE_WEB_CLIENT_ID
🔐 secretGOOGLE_WEB_CLIENT_SECRET
configLOG_LEVEL
configNEXT_DIST_DIR
configPLAYWRIGHT_BACKEND_PORT
configPLAYWRIGHT_DISABLE_WEBSERVER
configPLAYWRIGHT_FRONTEND_PORT
configPLAYWRIGHT_REUSE_EXISTING_SERVER
configORION_ENV
configENV
configORION_RUNTIME_HOST
configHOST
configORION_RUNTIME_PORT
🔐 secretOPENAI_API_KEY
configOPENAI_RESPONSES_URL
configORION_MODEL
configORION_GOAL
🔐 secretRUNTIME_KEY
🔐 secretORION_API_KEY
configEMPYRALIS_DEV_ALLOW_HTTP_MCP
configLOCAL_SHELL_TIMEOUT
configLOCAL_FILE_READ_MAX_BYTES
configENVIRONMENT
🔐 secretEMPYRALIS_TOOL_BROKER_SECRET
🔐 secretEMPYRALIS_SECRETS_BROKER_SECRET
🔐 secretSTABILITY_API_KEY
configSTABLE_DIFFUSION_MODEL_ID
🔐 secretEMPYRALIS_PLATFORM_REGISTRY_KEY
configEMPYRALIS_NICHES_FILE
configORION_NICHES_FILE
configORION_COGNITIVE_SKILL_REPLAY_MIN_CONFIDENCE
configORION_COGNITIVE_SKILL_REPLAY_ENABLED
configORION_COGNITIVE_OPERATOR_APPROVAL_LEVELS_AUTO
configORION_COGNITIVE_OPERATOR_STRICT_APPROVAL_ALL
configORION_COGNITIVE_OPERATOR_APPROVAL_LEVELS_STRICT
configORION_COGNITIVE_OPERATOR_APPROVAL_LEVELS_GUARDED
configORION_COGNITIVE_SKILL_DECAY_INTERVAL_SECONDS
configORION_COGNITIVE_SKILL_DECAY_MAX_AGE_SECONDS
configORION_COGNITIVE_SKILL_DECAY_MIN_SAMPLES
configORION_COGNITIVE_SKILL_DECAY_MIN_SUCCESS_RATE
configORION_COGNITIVE_RUN_MODE
configORION_API_URL
configORION_COGNITIVE_WORKSPACE_ID
configORION_COGNITIVE_TRUST_MODE
configORION_COGNITIVE_EXECUTION_TARGET
configORION_COGNITIVE_RUN_POLL_SECONDS
configORION_COGNITIVE_RUN_WAIT_SECONDS
configORION_COGNITIVE_OPERATOR_ENABLED
configORION_COGNITIVE_OPERATOR_ROOT
configORION_COGNITIVE_OPERATOR_TIMEOUT_SECONDS
configORION_COGNITIVE_OPERATOR_MAX_OUTPUT_CHARS
configORION_COGNITIVE_OPERATOR_ALLOW_SHELL_FALLBACK
configORION_LOCAL_COMPANION_COMMAND_ALLOW_PREFIXES
configORION_COGNITIVE_OPERATOR_ALLOW_PREFIXES
configORION_COGNITIVE_OPERATOR_TRUST_MODE
configCHEAP_MODEL
configSMART_MODEL
configEMBEDDING_MODEL
configOPENAI_EMBEDDINGS_URL
configOPENAI_CHAT_COMPLETIONS_URL
configANTHROPIC_MESSAGES_URL
🔐 secretOPENAI_ACCESS_TOKEN
🔐 secretANTHROPIC_API_KEY
🔐 secretGEMINI_API_KEY
🔐 secretGOOGLE_API_KEY
🔐 secretVERTEX_ACCESS_TOKEN
configVERTEX_PROJECT_ID
configVERTEX_LOCATION
configEMPYRALIS_STATE_HOME
configEMPYRALIS_AUTONOMOUS_CONTROL_MODEL
configEMPYRALIS_AUTONOMOUS_ALLOW_DANGEROUS_CLASSES
configEMPYRALIS_AUTONOMOUS_ROLE
configEMPYRALIS_AUTONOMOUS_IS_ADMIN
🔐 secretEMPYRALIS_SUPERVISOR_SECRET
configEMPYRALIS_CERT_GATEWAY_ID
configEMPYRALIS_CERT_WORKSPACE_ID
configEMPYRALIS_CERT_TENANT_ID
configEMPYRALIS_CERT_SELF_HOSTED_PROFILE_ID
🔐 secretEMPYRALIS_CERT_SELF_HOSTED_NODE_TOKEN
configEMPYRALIS_CERT_SELF_HOSTED_NODE_ID
configEMPYRALIS_CERT_EMAIL
🔐 secretEMPYRALIS_CERT_PASSWORD
🔐 secretEMPYRALIS_CERT_BEARER_TOKEN
🔐 secretEMPYRALIS_CERT_RUNTIME_KEY
configEMPYRALIS_CERT_BACKEND_URL
configEMPYRALIS_CERT_GATEWAY_FILE_PATH
configEMPYRALIS_CERT_GATEWAY_SAFE_COMMAND
configEMPYRALIS_CERT_GATEWAY_RISKY_COMMAND
configEMPYRALIS_CERT_GATEWAY_LONG_COMMAND
configEMPYRALIS_CERT_SELF_HOSTED_SAFE_COMMAND
configEMPYRALIS_CERT_SELF_HOSTED_LONG_COMMAND
configEMPYRALIS_CERT_GATEWAY_CHAT_MESSAGE
configORION_LOCAL_WORKER_USE_LLM
configORION_LOCAL_WORKER_LLM_REQUIRED
🔐 secretORION_MACHINE_ENROLLMENT_TOKEN
🔐 secretCREW_API_KEY
configORION_RUNTIME_POLICY_MODE_DEFAULT
configORION_MAX_LOCAL_OPS
configORION_LOCAL_COMPANION_ROOT
configORION_LOCAL_FILE_LOCK_TIMEOUT_SECONDS
configORION_LOCAL_FILE_LOCK_POLL_SECONDS
configORION_LOCAL_WORKER_MAX_TOKENS
🔐 secretORION_DISABLE_OPENAI_API_KEY
configORION_AUTH_MODE
🔐 secretORION_LOCAL_WORKER_OPENAI_TOKEN
🔐 secretCODEX_OAUTH_TOKEN
🔐 secretOPENAI_OAUTH_TOKEN
configCODEX_AUTH_FILE
🔐 secretORION_LOCAL_WORKER_OPENAI_API_KEY
🔐 secretORION_LOCAL_WORKER_ANTHROPIC_API_KEY
configORION_LOCAL_WORKER_ANTHROPIC_MODEL
🔐 secretORION_LOCAL_WORKER_GEMINI_API_KEY
🔐 secretORION_LOCAL_WORKER_QWEN_API_KEY
🔐 secretQWEN_API_KEY
🔐 secretDASHSCOPE_API_KEY
🔐 secretORION_LOCAL_WORKER_DEEPSEEK_API_KEY
🔐 secretDEEPSEEK_API_KEY
🔐 secretORION_LOCAL_WORKER_MISTRAL_API_KEY
🔐 secretMISTRAL_API_KEY
🔐 secretORION_LOCAL_WORKER_GROQ_API_KEY
🔐 secretGROQ_API_KEY
🔐 secretORION_LOCAL_WORKER_OPENROUTER_API_KEY
🔐 secretOPENROUTER_API_KEY
🔐 secretORION_LOCAL_WORKER_AZURE_OPENAI_API_KEY
🔐 secretAZURE_OPENAI_API_KEY
🔐 secretORION_LOCAL_WORKER_CUSTOM_OPENAI_COMPATIBLE_API_KEY
🔐 secretCUSTOM_OPENAI_COMPATIBLE_API_KEY
🔐 secretORION_LOCAL_WORKER_OLLAMA_CLOUD_API_KEY
🔐 secretOLLAMA_API_KEY
configORION_LOCAL_WORKER_OLLAMA_URL
configORION_LOCAL_WORKER_OLLAMA_ENABLED
configORION_LOCAL_WORKER_CODEX_MODEL
configCODEX_MODEL
configORION_LOCAL_WORKER_OPENAI_MODEL
configORION_LOCAL_WORKER_CLAUDE_CODE_MODEL
configORION_LOCAL_WORKER_GEMINI_MODEL
configORION_LOCAL_WORKER_OLLAMA_MODEL
configORION_LOCAL_WORKER_OLLAMA_CLOUD_MODEL
configORION_LOCAL_WORKER_QWEN_MODEL
configORION_LOCAL_WORKER_DEEPSEEK_MODEL
configORION_LOCAL_WORKER_MISTRAL_MODEL
configORION_LOCAL_WORKER_QWEN_URL
configORION_LOCAL_WORKER_DEEPSEEK_URL
configORION_LOCAL_WORKER_MISTRAL_URL
configORION_LOCAL_WORKER_GROQ_URL
configORION_LOCAL_WORKER_OPENROUTER_URL
configORION_LOCAL_WORKER_OPENAI_URL
configORION_LOCAL_WORKER_GROQ_MODEL
configORION_LOCAL_WORKER_OPENROUTER_MODEL
configORION_LOCAL_WORKER_TEMPERATURE
configORION_LOCAL_WORKER_LLM_TIMEOUT_SECONDS
configORION_LOCAL_WORKER_ANTHROPIC_URL
configORION_LOCAL_WORKER_GEMINI_URL
configORION_LOCAL_WORKER_OLLAMA_TIMEOUT_SECONDS
configORION_LOCAL_WORKER_OLLAMA_NUM_PREDICT
configORION_LOCAL_WORKER_CODEX_TIMEOUT_SECONDS
configORION_LOCAL_WORKER_CODEX_REASONING_EFFORT
configORION_LOCAL_WORKER_CODEX_RESPONSES_URL
configORION_LOCAL_WORKER_OPENAI_RESPONSES_URL
configORION_LOCAL_WORKER_CLAUDE_CODE_TIMEOUT_SECONDS
configORION_LOCAL_WORKER_OLLAMA_CLOUD_URL
configORION_LOCAL_WORKER_OLLAMA_CLOUD_NUM_PREDICT
configORION_LOCAL_WORKER_OLLAMA_CLOUD_TIMEOUT_SECONDS
configORION_LOCAL_WORKER_PROVIDER_ORDER
configORION_LOCAL_WORKER_PROVIDER
configORION_LOCAL_WORKER_USE_CODEX_CLI
configORION_LOCAL_WORKER_PREFER_DIRECT_OPENAI
configORION_LOCAL_WORKER_FALLBACK_PROVIDER
configORION_LOCAL_WORKER_PROVIDER_FALLBACK
configORION_RUNTIME_SESSION_ROOT
configORION_SPREADSHEET_ROOT
configORION_OPS_DAEMON_AUTORECOVER
configORION_OPS_DAEMON_HEALTH_POLL_SECONDS
configORION_OPS_DAEMON_FAILURE_THRESHOLD
configORION_OPS_DAEMON_RECOVERY_COOLDOWN_SECONDS
configORION_OPS_DAEMON_MAX_RECOVERIES_PER_HOUR
configORION_OPS_DAEMON_REQUIRE_WORKER
configORION_OPS_DAEMON_REQUIRE_TELEGRAM
configORION_OPS_DAEMON_STARTUP_GRACE_SECONDS
configORION_OPS_DAEMON_ALLOW_REMOTE
configORION_TELEGRAM_AUTOPILOT_WORKSPACE_ID
configWORKSPACE_ID
configORION_OPS_DAEMON_HOST
configORION_OPS_DAEMON_PORT
configEMPYRALIS_DESKTOP_ELECTRON_BIN
configORION_DESKTOP_ELECTRON_BIN
configORION_STATE_HOME
configEMPYRALIS_VIRAL_FACTORY_DB_PATH
configORION_VIRAL_FACTORY_DB_PATH
configRUNTIME_URL
configORION_ACCOUNT_SHELL_CACHE_TTL_SECONDS
configCLOUD_SESSION_MANAGER_URL
🔐 secretCLOUD_SESSION_HMAC_SECRET
🔐 secretAPI_SECRET
configCLOUD_SESSION_MANAGER_ENABLED
configORION_OPS_DAEMON_ENABLED
🔐 secretEMPYRALIS_VISION_API_KEY
configORION_JWT_EXP_SECONDS
configORION_MOBILE_JWT_EXP_SECONDS
configORION_MOBILE_REFRESH_EXP_SECONDS
configORION_PUBLIC_REGISTRATION_ENABLED
configORION_ADMIN_USER_IDS
configORION_ADMIN_EMAILS
configORION_SERVICE_RATE_LIMIT_PER_MINUTE
configORION_AUTH_LOGIN_RATE_LIMIT_PER_MINUTE
configORION_AUTHENTICATED_API_RATE_LIMIT_PER_MINUTE
configORION_MOBILE_AUTHENTICATED_API_RATE_LIMIT_PER_MINUTE
configORION_MODEL_INVOCATION_RATE_LIMIT_PER_MINUTE
configORION_MOBILE_MODEL_INVOCATION_RATE_LIMIT_PER_MINUTE
configORION_AUTH_CSRF_FAILURE_RATE_LIMIT_PER_MINUTE
configORION_AUTH_REFRESH_RATE_LIMIT_PER_MINUTE
configORION_MOBILE_BETA_AUTO_SIGNIN_ENABLED
configEMPYRALIS_AUTH_ACCESS_COOKIE
configEMPYRALIS_AUTH_REFRESH_COOKIE
configEMPYRALIS_AUTH_CSRF_COOKIE
configEMPYRALIS_AUTH_ACCESS_COOKIE_MAX_AGE_SECONDS
configEMPYRALIS_AUTH_REFRESH_COOKIE_MAX_AGE_SECONDS
configORION_PROVIDER_JWKS_CACHE_TTL_SECONDS
configORION_PROVIDER_JWKS_STALE_TTL_SECONDS
configORION_PROVIDER_JWKS_RETRY_ATTEMPTS
configORION_PROVIDER_HTTP_TIMEOUT_SECONDS
configORION_AUTH_HOT_CACHE_TTL_SECONDS
configEMPYRALIS_AUTH_COOKIE_DOMAIN
configEMPYRALIS_AUTH_COOKIE_SAMESITE
configORION_AUTH_REQUIRED
configORION_LOCAL_DEV_AUTH_ROLE
configORION_LOCAL_DEV_WORKSPACE_IDS
configORION_LOCAL_DEV_USER_ID
configORION_LOCAL_DEV_EMAIL
configORION_LOCAL_DEV_TENANT_ID
🔐 secretEMPYRALIS_STRIPE_SECRET_KEY
🔐 secretSTRIPE_SECRET_KEY
🔐 secretEMPYRALIS_STRIPE_WEBHOOK_SECRET
configEMPYRALIS_STRIPE_PRICE_IDS
configEMPYRALIS_BILLING_FRONTEND_ORIGIN
configFRONTEND_ORIGINS
configEMPYRALIS_BILLING_SUCCESS_URL
configEMPYRALIS_BILLING_CANCEL_URL
configEMPYRALIS_BILLING_CREDIT_SUCCESS_URL
configEMPYRALIS_BILLING_CREDIT_CANCEL_URL
configEMPYRALIS_BILLING_PORTAL_RETURN_URL
configORION_BROWSER_ENGINE_ROOT
configORION_BROWSER_ATTACH_CDP_URL
configDISPLAY
configTAURI_ENV
configEMPYRALIS_PUBLIC_FRONTEND_ORIGIN
configBACKEND_PUBLIC_ORIGIN
configBACKEND_PUBLIC_HOST
configEMPYRALIS_API_URL
🔐 secretEMPYRALIS_API_KEY
configEMPYRALIS_WORKSPACE_ID
configEMPYRALIS_TRUSTED_PROXY_CIDRS
configEMPYRALIS_DEPLOY_ENV
configEMPYRALIS_EXTERNAL_AGENT_LOCAL_STORE
configPYTEST_CURRENT_TEST
configORION_TELEGRAM_AUTOPILOT_PUBLIC_BASE_URL
🔐 secretDISCORD_APP_PUBLIC_KEY
configORION_WORKSPACE_LOOKUP_CACHE_TTL_SECONDS
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployNEXT_PUBLIC_APP_URL
deploySENTRY_DSN
deployPORT
deployDATABASE_URL
// quality suggestions

Dependencies

2 dependencies, 1 flagged: @playwright/test

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

8/8 tools missing one or more hints — list_spaces (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_space_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_recent_alerts (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +5 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tool test coverage

Only 2/8 tools referenced in tests (25%)

Write tests that reference each tool by name so every tool has at least one test.

No eval / new Function

1 eval() or new Function() call — dynamic code execution

Replace eval / Function with explicit parsing or safer alternatives.

Shell command execution

2 child_process/subprocess calls in production code — runs shell commands (empyralis-gateway/src/browser/worker.ts:49, empyralis-gateway/src/health/service-inventory.ts:152)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets stay with their owner

8 secret/sensitive values flow into network calls (API_WALL_SMOKE_PASSWORD → dynamic, EMPYRALIS_CERT_RUNTIME_KEY → dynamic) (3 other flows matched canonical API hosts)

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Secrets not logged

7 secret values sent to console.log

Redact or omit secret values from log output.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/mansourmp-multi-agent-orchestrator-project-ka15fx?variant=verified)](https://m8ven.ai/mcp/mansourmp-multi-agent-orchestrator-project-ka15fx)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 30560615df55f129f718d47cde121c00762e933b
code hash: 12c093173d961ac43cf0916c9d65436e4cdab7227c9659a6a6ab6ad6bd47f720
verified: 8/16/2026, 9:41:44 PM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client