m365-copilot-companion-mcp (MasayukiTa/m365-copilot-companion-mcp) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it yet. No publisher has claimed this listing.

C
Emerging
74/100

m365-copilot-companion-mcp

Personal-use MCP server that gives Microsoft 365 Copilot real hands on your own laptop: files, Python, Office, SQL, Web. 100+ tools, autonomous relay, easily extensible, no extra licences.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

MasayukiTa

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: MCP_API_KEY, MCP_REQUIRE_UNLOCK_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configMCP_EXECUTION_PROFILESの全文を末尾へ貼り、「保存」を押します。これは=1で使う
🔐 secretMCP_API_KEYBearer <MCP_API_KEY の値> (STEP 2 で表示された値)
configMCP_TOOL_MAP
configMCP_TOOL_MAP_MAX
configMCP_TOOL_MAP_EXEC_DIRECT
configMCP_TOOL_MAP_INCLUDE
configMCP_FAULTHANDLER_MAX_BYTES
configMCP_NO_PPTX_AUTOSTAMP
configTASK_JOB_APPROVAL_MODE
configPYTEST_CURRENT_TEST
configMCP_GREP_MAX_FILE_MB
configMCP_DATA_MEMORY_AUTO
configMCP_DATA_MEMORY_TABLE_TOKENS_MAX
configVIRTUAL_ENV
configMCP_ALLOWED_BASEでファイル範囲制限 — エージェントが触れるフォルダの上限を設定でき、それ以外はブロックします。
configMCP_GATE_DIR
configMCP_JOB_MAX_RUNTIME_S
configMCP_LOCAL_JOB_DB
configMCP_UNLOCK_TTL_DAYS
configMCP_SUPPRESS_GUI
configMCP_FLEET_RUN_ID
configMCP_TRUSTED_PROXY_HOPS
configMCP_UNLOCK_MAX_SESSIONS
configMCP_UNLOCK_SESSION_AUTH
configMCP_UNLOCK_SESSION_TTL_S
🔐 secretMCP_REQUIRE_UNLOCK_TOKEN
configMCP_SKILLS_PROJECT_ROOT
configMCP_SEARCH_INCLUDE_ALL
configMCP_COMPANION_REPO
configMCP_SESSION_STORE_DIR
configMCP_FLEET_AGENT_URL
configMCP_IMPL_AGENT_URL
configMCP_LOCAL_CONTROLLER_MAX_RESTARTS
configMCP_LOCAL_ROTATE_AFTER_TURNS
configMCP_LOCAL_TURN_TIMEOUT
configMCP_LOCAL_UI_IDLE_TIMEOUT
configMCP_LOCAL_EDGE_MB_LIMIT
configSWE_CYCLE_FLOOR_GB
configSWE_CYCLE_BATCH_TIMEOUT_S
configSWE_CYCLE_GRADE_TIMEOUT_S
configSWE_RUN_TAG
configSWE_MAX_ATTEMPTS
configSWE_SLICE_FILE
configSWE_EFFORT
configEVAL_SSH_HOST
configSWE_EVAL_HOST
configSystemRoot
configSWE_NET
configREVIEW_MAX_CONCURRENT_CEILING
configMCP_DEEP_REVIEW_TRANSPORT
configSWE_BROKER
configSWE_STRONG_SELFTEST
configSWE_FIX_RADIUS
configSWE_MINIMALITY
configSWE_MISS85_DISCIPLINE
configSWE_CACHE_LEVEL
configSWE_HTTPBIN_URL
configSWE_HTTPBIN_CERT
configSWE_EVAL_TIMEOUT_S
configSWE_EVAL_RETRIES
configSWE_NO_REGRESSION_FEEDBACK
configSWE_KEEP_IMAGES
configSWE_KEEP_ENV
configSWE_KEEP_ENV_FLOOR_GB
configEVAL_HOST_WSL_DISTRO
configEVAL_HOST_POLL_SECONDS
configEVAL_HOST_POLL_MAX
// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/masayukita/m365-copilot-companion-mcp)](https://m8ven.ai/mcp/masayukita/m365-copilot-companion-mcp)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: d4b534542edbf98fe0268e97b52f152c3474a0ac
code hash: b02e3506e6aa9561bac6262b747ca072692062c443bbeb281fe4e33027b8bf51
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client