okf-postal-db (MauricioPerera/okf-postal-db) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 9 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.
DB para agentes: estado materializado en OKF (Markdown+YAML) + bitácora firmada append-only estilo postal, expuesta vía REST (CRUD, paginación/búsqueda, auth, rotación de clave, auditoría). Core escrito por GLM bajo gate CCDD.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Monitored 21 days · every push re-verified
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Fastify's Content-Type header tab character allows body validation bypass
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
API_KEYSi está definida, exige header x-api-key en todas las rutas salvo GET /health; si no, sin authDATA_DIRse hace un commit best-effort en .PORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
9/9 tools missing one or more hints — memory_collections (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); memory_list (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); memory_read (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +6 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
6/9 tools referenced in tests (67%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
0 critical, 1 high severity in production deps — fastify@4.29.1 (high), fastify@4.29.1 (low)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
2/5 production deps stale: gray-matter@2023-07-12 (3.1y), ajv-formats@2024-03-30 (2.4y)
[](https://m8ven.ai/mcp/mauricioperera/okf-postal-db)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check