ateles (markmhendrickson/ateles) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 75 tools. No publisher has claimed this listing.

C
Emerging
74/100

ateles

Operating system for humans and AI agents to jointly initiate, execute, approve, and reconcile work under explicit authority

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

markmhendrickson

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
38 flows detected: NEOTOMA_BEARER_TOKEN, TELEGRAM_BOT_TOKEN, CYPHORHINUS_TELEGRAM_BOT_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 18 credentials: GITHUB_TOKEN, NEOTOMA_BEARER_TOKEN, TELEGRAM_BOT_TOKEN, SWARM_ROSTER_KEY, APIS_GITHUB_TOKEN, GH_TOKEN, OPENAI_API_KEY, WHATSAPP_ACCESS_TOKEN, TYPEFULLY_API_KEY, X_API_BEARER_TOKEN, X_API_USER_ACCESS_TOKEN, ATELES_LOCALE_PROFILE_KEY, ELEVENLABS_API_KEY, CYPHORHINUS_TELEGRAM_BOT_TOKEN, APIS_GITHUB_WEBHOOK_SECRET, APIS_APPROVE_EMAIL_SECRET, APUS_WEBHOOK_SECRET, SOPS_AGE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configATELES_AGENT_PAT
configDASHBOARD_GIT_SHA
configGITHUB_HARNESS_DEBUG
🔐 secretGITHUB_TOKEN
configNEOTOMA_AGENT_PAT
configNEOTOMA_BASE_URL
🔐 secretNEOTOMA_BEARER_TOKEN
configNEOTOMA_RC_DIR
configSEARCH_CONSOLE_CREDENTIALS_PATH
configSEARCH_CONSOLE_OAUTH_PATH
🔐 secretTELEGRAM_BOT_TOKEN
configTELEGRAM_CHAT_ID
🔐 secretSWARM_ROSTER_KEY
configGITHUB_API_URL
configATELES_PIPELINE_QUEUE_SCAN_LIMIT
configATELES_PIPELINE_QUEUE_WORKERS
configATELES_PIPELINE_MARKER_STALE_SECONDS
🔐 secretAPIS_GITHUB_TOKEN
🔐 secretGH_TOKEN
configAPIS_SWARM_REPOSITORIES
configATELES_GITHUB_OWNER
configAPIS_MAX_CONCURRENT_ISSUE_PIPELINES
configDISPATCH_FAILURE_LOG_DIR
configATELES_APIS_LAUNCHD_LABEL
configINTERVIEWS_ADMIN_BASE_URL
configINTERVIEWS_ADMIN_PASSPHRASE
configINTERVIEWS_ADMIN_ENFORCE_NEOTOMA_ENV
configINTERVIEWS_ADMIN_ENV
configINTERVIEWS_ADMIN_NEOTOMA_ENV
configNEOTOMA_ENV
configNEOTOMA_TARGET_ENV
configDATA_DIR
configMCP_FULL_SNAPSHOTS
🔐 secretOPENAI_API_KEY
configMCP_TRANSPORT
configMCP_PORT
configMCP_HOST
🔐 secretWHATSAPP_ACCESS_TOKEN
configWHATSAPP_PHONE_NUMBER_ID
configWHATSAPP_BUSINESS_ACCOUNT_ID
configASANA_SOURCE_PAT
configASANA_TARGET_PAT
configSOURCE_WORKSPACE_GID
configTARGET_WORKSPACE_GID
configFALLBACK_ASSIGNEE_EMAIL
configALLOW_OVERWRITE
configPARQUET_MCP_SERVER_PATH
🔐 secretTYPEFULLY_API_KEY
configPARQUET_MCP_PYTHON
🔐 secretX_API_BEARER_TOKEN
🔐 secretX_API_USER_ACCESS_TOKEN
configMCP_GRANT_PROXY_DEBUG
configATELES_AGENT_SUB
configATELES_HARNESS
configATELES_SESSION_ID
configATELES_CONFIG
configATELES_SECRET_BACKEND
configNEOTOMA_FLY_APP
configNEOTOMA_FLY_MACHINE
configNEOTOMA_FORENSICS_BUDGET_SECONDS
configNEOTOMA_HTTP_PORT
configNEOTOMA_EVENT_LOOP_BLOCKED_MS
configNEOTOMA_FORENSICS_DIR
configATELES_GMAIL_SEND_CMD
configOPERATOR_EMAIL
configRECORD_MEETING_FRAME_INTERVAL
configNEOTOMA_PROD_BASE_URL
configLANIUS_DRY_RUN
configLANIUS_STALE_DAYS
configLIVE_TRANSCRIPT_INTERVAL
configLIVE_TRANSCRIPT_FOLLOW
configLIVE_TRANSCRIPT_FOLLOW_TIMEOUT_MIN
configLOXIA_PR_NUMBER
configLOXIA_REPO
configLOXIA_DRY_RUN
configLOXIA_HEAD_SHA
configRECORD_MEETING_DEVICE
configRECORD_MEETING_REALTIME_INTERVAL
configRECORD_MEETING_MIC
configATELES_SECRETS_DIR
configSOPS_BIN
configOP_BIN
configENVIRONMENT
🔐 secretATELES_LOCALE_PROFILE_KEY
configSTREAM_TRANSCRIPT_LANGUAGE_CACHE_TTL
configLIVE_TRANSCRIPT_SILENCE_THRESHOLD_DB
configSTREAM_TRANSCRIPT_MODEL
configSTREAM_TRANSCRIPT_LANGUAGE
configSTREAM_TRANSCRIPT_STALL_S
configSTREAM_TRANSCRIPT_SOCKET_S
configSTREAM_TRANSCRIPT_SIGNAL_WINDOW_S
configSTREAM_TRANSCRIPT_SILENT_DBFS
configSTREAM_TRANSCRIPT_SPEECH_DBFS
configSTREAM_TRANSCRIPT_RECONNECT
configSTREAM_TRANSCRIPT_MAX_RECONNECTS
configSTREAM_TRANSCRIPT_RECONNECT_BACKOFF_S
configSTREAM_TRANSCRIPT_RECONNECT_BACKOFF_MAX_S
configSTREAM_TRANSCRIPT_RECONNECT_RESET_S
configSTREAM_TRANSCRIPT_GATE_WINDOW_S
configSTREAM_TRANSCRIPT_OVERLAP_TOLERANCE_S
configSTREAM_TRANSCRIPT_MAX_TURN_S
configSTREAM_TRANSCRIPT_VAD_SILENCE_MS
configSTREAM_TRANSCRIPT_VAD_PREFIX_PADDING_MS
configSTREAM_TRANSCRIPT_GATE_HANGOVER_S
configSTREAM_TRANSCRIPT_DEVICE
configSTREAM_TRANSCRIPT_LANGUAGES
configOPENAI_RATE_LIMIT_DELAY
configOPENAI_MAX_RETRIES
configOPENAI_INITIAL_RETRY_DELAY
configOPENAI_MAX_RETRY_DELAY
configTRANSCRIBE_LABEL_SYSTEM
configTRANSCRIBE_LABEL_MIC
configTRANSCRIBE_PROPER_NOUNS
configTRANSCRIBE_PROPER_NOUNS_FILE
configTRANSCRIBE_DISABLE_NEOTOMA_VOCAB
configTRANSCRIBE_VOCABULARY_ENTITY_ID
configTRANSCRIBE_CLEAN_STUTTERS
configELEVENLABS_STT_TIMEOUT
configELEVENLABS_STT_TIMEOUT_CONNECT
configELEVENLABS_STT_TIMEOUT_READ
configELEVENLABS_STT_COMPRESS_THRESHOLD_MB
configELEVENLABS_STT_UPLOAD_MP3_BITRATE
🔐 secretELEVENLABS_API_KEY
configELEVENLABS_STT_MODEL_ID
configTRANSCRIBE_TAG_AUDIO_EVENTS
configTRANSCRIBE_NUM_SPEAKERS
configELEVENLABS_STT_MULTICHANNEL_MAX_SECONDS
configNEOTOMA_CLI_SCRIPT
configNEOTOMA_TRANSCRIPTION_CONTACT_ENTITY_IDS
configTRANSCRIPTION_CONSENT_BASIS
🔐 secretCYPHORHINUS_TELEGRAM_BOT_TOKEN
configCYPHORHINUS_TELEGRAM_CHAT_ID
configTELEGRAM_TOPIC_CYPHORHINUS
configATELES_NOTIFY_EMAIL
configATELES_SWARM_EMAIL
configATELES_LOG_MAX_BYTES
configATELES_LOG_BACKUP_COUNT
configNEOTOMA_AAUTH_VIA_CLI
configNEOTOMA_AAUTH_SUB
configAPIS_READINESS_THRESHOLD
configATELES_EMAIL_DOMAIN
configATELES_RUN_EMAIL_DIR
configEND_SKILL_ID
configNEOTOMA_SSE_SUBSCRIPTION_ID
configAPIS_MAX_TASK_ATTEMPTS
configAPIS_RETRY_BACKOFF_BASE_SECONDS
configAPIS_RETRY_BACKOFF_CAP_SECONDS
configATELES_NOTIFY_TO
configATELES_DIGEST_QUEUE_PATH
configATELES_REPO_ROOT
configAPIS_A2A_TASK_VISIBILITY
configAPIS_A2A_ENABLE
configAPIS_A2A_HOST
configAPIS_A2A_PORT
configAPIS_A2A_REQUIRE_AUTH
configNEOTOMA_BEARER_TOKEN_PROD
configATELES_REPO_PATH
configAPIS_DRY_RUN
configAPIS_AUTO_EXECUTE
configAPIS_RUN_CONVERSATIONS
configAPIS_RUN_EMAIL
configAPIS_READINESS_GATE
configAPIS_DISPATCH_TIMEOUT
configAPIS_GITHUB_WEBHOOK_PORT
🔐 secretAPIS_GITHUB_WEBHOOK_SECRET
configAPIS_HARNESS_PROVIDERS
🔐 secretAPIS_APPROVE_EMAIL_SECRET
configAPIS_DEFERRED_REVIEW_SWEEP_SECONDS
configAPIS_HARNESS_HEADROOM_FILE
configAPIS_HARNESS_HEADROOM
configAPIS_OPERATOR_LOGIN
configAPIS_RELEASE_PUSH_REF
configAPIS_HARNESS_MIN_HEADROOM
configAPIS_HARNESS_COOLDOWN_SECONDS
configAPIS_CLAUDE_BIN
configAPIS_CODEX_BIN
configAPIS_CURSOR_BIN
configATELES_DISPATCH_FAILURE_NOTIFY_WINDOW
configATELES_PRIVATE_KEYS_DIR
configAPIS_REVIEW_MODELS
configNEOTOMA_LOCAL_CHECKOUT
configPHOENICURUS_RELEASE_BRANCH
configPHOENICURUS_PREPARE_TIMEOUT_S
configPHOENICURUS_PUBLISH_TIMEOUT_S
configAPIS_LIMIT_RESET_DEFAULT_SECONDS
configAPIS_PANEL_MAX
configAPIS_AUTONOMY_AUTO_MERGE
configATELES_SWARM_AUTO_BUILD
configAPIS_APPROVAL_TRIGGERS_MERGE
configAPIS_MAX_FIX_ROUNDS
configATELES_SWARM_AUTO_REREVIEW
configAPIS_REVIEW_STALL_SECONDS
configAPIS_REVIEW_STALL_MAX_RETRIES
configAPIS_REVISION_STALE_SECONDS
configAPIS_REVISION_MAX_RETRIES
configAPIS_APPROVED_STALE_DAYS
configAPIS_MISSING_LENS_MAX_RETRIES
configAPIS_RECONCILE_ENABLED
configAPIS_RECONCILE_INTERVAL_SECONDS
configAPIS_RECONCILE_MAX_PER_SWEEP
configAPIS_RECONCILE_GRACE_SECONDS
configAPIS_RECONCILE_QUERY_LIMIT
configAPIS_STALL_SECONDS
configAPIS_WATCHDOG_INTERVAL_SECONDS
configAPIS_WATCHDOG_QUERY_LIMIT
configAPIS_UNROUTABLE_WINDOW_SECONDS
configAPIS_UNROUTABLE_REASSERT_SECONDS
configAPIS_UNREADABLE_ATTEMPTS
configAPUS_PORT
🔐 secretAPUS_WEBHOOK_SECRET
configATELES_AGENT_GIT_NAME
configATELES_AGENT_GIT_EMAIL
configAQUILA_TIMEOUT_SECONDS
configTELEGRAM_TOPIC_COTINGA
configOPERATOR_NAME
configCOTINGA_CALENDAR_IDS
configCYPHORHINUS_POLL_TIMEOUT
configSOPS_AGE_KEY_FILE
🔐 secretSOPS_AGE_KEY
configNEOTOMA_REPO_PATH
configFORMICA_DRY_RUN
configFORMICA_CLAUDE_BIN
configFORMICA_DISPATCH_TIMEOUT
configFORMICA_TRIAGE_LABEL
configGORILLA_POLL_INTERVAL
configGORILLA_SUMMARY_WEEKDAY
configGORILLA_SUMMARY_HOUR
configGORILLA_LOOKBACK_DAYS
configGORILLA_NUDGE_AFTER_DAYS
configGORILLA_DRY_RUN
configTELEGRAM_ALLOWED_USER_ID
configTELEGRAM_TOPIC_PAYMENTS
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

75/75 tools missing one or more hints — list_sites (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_indexing_issues (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_search_analytics (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +72 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

28/75 tools referenced in tests (37%)

Write tests that reference each tool by name so every tool has at least one test.

Domain consistency

npm scope @ateles doesn't match GitHub owner markmhendrickson

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/markmhendrickson/ateles)](https://m8ven.ai/mcp/markmhendrickson/ateles)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 711cb7f154e21ca2018a3cbf504453f4b0ea8bf9
code hash: c96e398f00008ba7efcda86bfb16964ee8ff9641cb75a1aefa12210da6918147
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client