tex (MattNardizzi/tex) is an MCP server listed on the M8ven Trust Index. It scores 60 out of 100, grade C. No publisher has claimed this listing.

C
Caution
60/100

tex

Runtime governance for AI agents — PERMIT / ABSTAIN / FORBID enforced in-path, sealed with tamper-evident receipts that verify offline.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

MattNardizzi

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 10 credentials: TEX_CONDUIT_ENTRA_CLIENT_SECRET, ANTHROPIC_API_KEY, TEX_DISCOVERY_ENTRA_CLIENT_SECRET, TEX_DISCOVERY_OPENAI_API_KEY, TEX_DISCOVERY_SLACK_TOKEN, TEX_WEBHOOK_KEY, TEX_PDP_API_KEY, TEX_LOCAL_PEP_SECRET, TEX_AUTHORITY_SIGNING_SECRET, TEX_TAINT_LABEL_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configTEX_EVIDENCE_KEY_DIR
configTEX_DISCOVERY_PRESENCE_THRESHOLD
configTEX_DORMANCY_IDLE_DAYS
configTEX_DEFER_RUNTIME
configTEX_CONDUIT_ENTRA_CLIENT_ID
🔐 secretTEX_CONDUIT_ENTRA_CLIENT_SECRET
configTEX_CONDUIT_ORIGIN
configTEX_LOCAL_PEP
configTEX_PRESENCE_BRAIN
🔐 secretANTHROPIC_API_KEY
configTEX_PRESENCE_MODEL
configTEX_PRESENCE_PLANNER
configTEX_PRESENCE_PLANNER_MODEL
configTEX_SANDBOX
configTEX_DISCOVERY_ENTRA_TENANT_ID
configTEX_DISCOVERY_ENTRA_CLIENT_ID
🔐 secretTEX_DISCOVERY_ENTRA_CLIENT_SECRET
configTEX_DISCOVERY_AUDIT_QUERY
🔐 secretTEX_DISCOVERY_OPENAI_API_KEY
configTEX_DISCOVERY_OPENAI_ORG
configTEX_DISCOVERY_OPENAI_PROJECT
🔐 secretTEX_DISCOVERY_SLACK_TOKEN
configTEX_DISCOVERY_SLACK_TEAM_ID
configTEX_PROXY_IMAGE
configTEX_INIT_IMAGE
configTEX_PROXY_PORT
configTEX_PEP_ENV
configTEX_APPROVED_RUNTIME_CLASSES
configTEX_OPERATOR_HOST
configTEX_OPERATOR_PORT
configTEX_WEBHOOK_CERT
🔐 secretTEX_WEBHOOK_KEY
configTEX_PDP_MODE
configTEX_PEP_TENANT
configTEX_AGENT_ID
configTEX_AGENT
configTEX_PEP_AUDIENCE
configTEX_PEP_BROKER_TTL
configTEX_PEP_BROKER_AUDIENCE
configTEX_PEP_BROKER_HEADER
configTEX_PEP_BROKER_STRIP_HEADERS
configTEX_ORIGDST_SOCK
configTEX_PDP_BASE
🔐 secretTEX_PDP_API_KEY
configTEX_PEP_BROKER_TRUSTED_ISSUERS
configTEX_PEP_BROKER_TRUSTED_AUDIENCES
configTEX_PEP_ANCHOR_TSA_URL
configTEX_PEP_ANCHOR_AUTHORITY
configTEX_PEP_HOST
configTEX_PEP_PORT
configTEX_SIM_ENABLED
configTEX_EVIDENCE_ANCHOR_AUTHORITY
configTEX_EVIDENCE_ANCHOR_OUT_DIR
configTEX_SEAL_DECISIONS
configTEX_GIX_WITNESS
configTEX_ZKPDP_ALLOW_SHIM
configTEX_TALUS_ALLOW_INSECURE_TEE
configTEX_APP_ENV
configTEX_CONDUIT_ENTRA_REDIRECT_URI
configTEX_CONDUIT_UI_ORIGIN
configTEX_DISCOVERY_SCAN_RATE_LIMIT_PER_MIN
configTEX_SEAL_PLANE
configTEX_SANDBOX_TENANT
🔐 secretTEX_LOCAL_PEP_SECRET
configTEX_PLANE_STATUS
configTEX_GOVERN_MINT
configTEX_TAINT_GATED_MINT
configTEX_FRONTIER_NANOZK
configTEX_TEE_ATTESTATION_MODE
configTEX_TEE_MODE
configTEX_VOICE_GATEWAY_URL
🔐 secretTEX_AUTHORITY_SIGNING_SECRET
configTEX_TGPCC
configTEX_TGPCC_ED25519_SK
🔐 secretTEX_TAINT_LABEL_SECRET
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployDATABASE_URL
// quality suggestions

Tools detected

No tools extracted — insufficient content to verify at Tier 2

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 0 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/mattnardizzi/tex?variant=verified)](https://m8ven.ai/mcp/mattnardizzi/tex)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 59754fdc1f8158778dbe343c00a4221725f789ff
code hash: b816dd87c1d54f186f6c22278a5c84e3df707faa8c2498ba8f9f6a21eb91efca
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client