Multi-platform notification delivery supporting WeChat, Telegram, DingTalk, Bark, Lark, Feishu, and more
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
aahl
Source: PulseMCP · also listed on modelscope
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
TRANSPORTHASS_BASE_URLHome Assistant 地址,默认: http://homeassistant.local:8123HASS_ACCESS_TOKENHome Assistant 长效令牌HASS_MOBILE_KEYHome Assistant 移动设备key (如: mobile_app_your_iphone),也可在提示词指定DINGTALK_BOT_KEY钉钉群机器人access_tokenDINGTALK_BASE_URL钉钉API地址,默认: https://oapi.dingtalk.comLARK_BOT_KEYLark群机器人key,也可以在提示词指定LARK_BASE_URLLark API地址,默认: https://open.larksuite.comFEISHU_BASE_URL飞书API地址,默认: https://open.feishu.cnBARK_DEVICE_KEY默认Bark设备key,也可以在提示词指定BARK_BASE_URLBark API地址,默认: https://api.day.appNTFY_BASE_URLNtfy API地址,默认: https://ntfy.shNTFY_DEFAULT_TOPIC默认Ntfy订阅主题,也可以在提示词指定PUSH_PLUS_TOKEN默认PushPlus令牌,也可以在提示词指定PUSH_PLUS_BASE_URLPushPlus API地址,默认: http://www.pushplus.plusTELEGRAM_DEFAULT_CHATTelegram 默认会话ID,也可以在提示词指定TELEGRAM_BOT_TOKENTelegram 机器人令牌TELEGRAM_BASE_URLTelegram API反代理地址,默认: https://api.telegram.orgWEWORK_BOT_KEY"": "your-wework-bot-key"WEWORK_APP_AGENTID企业微信应用的ID,默认: 1000002WEWORK_APP_CORPID企业微信所属的企业IDWEWORK_APP_SECRET企业微信应用的凭证密钥WEWORK_APP_TOUSER企业微信默认接收人ID,也可以在提示词指定,默认: @allWEWORK_BASE_URL企业微信API反代理地址,用于可信IP,默认: https://qyapi.weixin.qq.comPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
21/21 tools missing one or more hints — ha_send_mobile (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); ding_send_text (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); lark_send_text (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +18 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Secrets stay with their owner
4 secret/sensitive values flow into network calls (WEWORK_BOT_KEY → dynamic, WEWORK_BOT_KEY → dynamic) (4 other flows matched canonical API hosts)
Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/mcp-notify-1fx806)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check