TailOpsMCP (mdlmarkham/TailOpsMCP) is an MCP server listed on the M8ven Trust Index. It scores 0 out of 100, grade F. It declares 21 tools. No publisher has claimed this listing.

F
Warning
0/100

TailOpsMCP

A control plane gateway for managing distributed infrastructure through MCP, enabling centralized SSH, Docker, and HTTP target management with capability-based authorization and policy enforcement.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

mdlmarkham

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

⏳ This MCP is queued for scoring. Check back in a few minutes.
// key findings
🚨
Reads files from sensitive locations
Touches: ~/.ssh/known_hosts, ~/.ssh/known_hosts
🔐
You'll be asked for 6 credentials: SYSTEMMANAGER_SHARED_SECRET, MCP_AUTH_CLIENT_SECRET, SYSTEMMANAGER_JWT_SECRET, TSIDP_CLIENT_SECRET, PROXMOX_PASSWORD, TAILSCALE_AUTH_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretSYSTEMMANAGER_SHARED_SECRET
configPYTHONIOENCODING
configMCP_AUTH_CLIENT_ID
🔐 secretMCP_AUTH_CLIENT_SECRET
configSYSTEMMANAGER_REQUIRE_AUTH
configSYSTEMMANAGER_ENABLE_APPROVAL
configSYSTEMMANAGER_ENABLE_RATE_LIMITING
configSYSTEMMANAGER_APPROVAL_WEBHOOK
configSYSTEMMANAGER_VALIDATION_MODE
configSYSTEMMANAGER_RATE_LIMIT_MODE
configSYSTEMMANAGER_AUTH_MODE
🔐 secretSYSTEMMANAGER_JWT_SECRET
configTSIDP_URL
configTSIDP_CLIENT_ID
🔐 secretTSIDP_CLIENT_SECRET
configTSIDP_SCOPES
configSYSTEMMANAGER_ALLOWED_BASE_PATHS
configTOON_ENVIRONMENT
configTOON_VERSION
configTOON_FORMAT
configTOON_TOKEN_BUDGET
configTOON_CACHE_SIZE
configSYSTEMMANAGER_INVENTORY
configLOG_LEVEL
configMCP_HOST
configMCP_PORT
configSYSTEMMANAGER_BASE_URL
configACCESS_CONTROL_DEFAULT_DENY
configCONTEXTUAL_PERMISSIONS
configRISK_BASED_ACCESS
configSEPARATION_OF_DUTIES
configCOMPLIANCE_STANDARDS
configAUTOMATED_COMPLIANCE_REPORTING
configAUTOMATED_EVIDENCE_COLLECTION
configDATA_RETENTION_POLICIES
configAUDIT_LOGGING_ENABLED
configACCESS_CONTROL_ENABLED
configMFA_REQUIRED_ROLES
configVULNERABILITY_SCANNING_ENABLED
configAUDIT_LOG_RETENTION_DAYS
configSECURITY_EVENT_RETENTION_DAYS
configSEPARATION_OF_DUTIES_ENABLED
configAPPROVAL_CHAIN_REQUIRED
configSYSTEMMANAGER_DISCOVERY_INTERVAL
configSYSTEMMANAGER_HEALTH_CHECK_INTERVAL
configSYSTEMMANAGER_MAX_CONCURRENT_PROBES
configSYSTEMMANAGER_AUTO_REGISTER
configSYSTEMMANAGER_MAX_FLEET_SIZE
configPROXMOX_HOST
configPROXMOX_USERNAME
🔐 secretPROXMOX_PASSWORD
configPROXMOX_TOKEN_NAME
configPROXMOX_TOKEN_VALUE
configPROXMOX_VERIFY_SSL
configTAILSCALE_ENABLED
configTAILSCALE_TAILNET
🔐 secretTAILSCALE_AUTH_KEY
configTAILSCALE_SSH_USER
configSLACK_WEBHOOK_URL
configTEAMS_WEBHOOK_URL
configALERT_LOG_FILE
configTAILSCALE_OIDC_ENABLED
configTAILSCALE_OIDC_ISSUER
configTAILSCALE_OIDC_AUDIENCE
configSESSION_TIMEOUT_HOURS
configMAX_CONCURRENT_SESSIONS
configSYSTEMMANAGER_POLICY_MODE
configSYSTEMMANAGER_ENABLE_DRY_RUN
configSYSTEMMANAGER_DISABLE_APPROVAL
configSYSTEMMANAGER_SELF_APPROVAL_TIMEOUT
configSSH_STRICT_HOST_KEY_CHECKING
configSYSTEMMANAGER_SNAPSHOT_DIR
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deploySMTP_HOST
deploySMTP_PORT
deploySMTP_USERNAME
deploySMTP_PASSWORD
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

21/21 tools missing one or more hints — my_tool (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_capabilities (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_target_capabilities (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +18 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

17/21 tool handlers declare input schemas (81%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

16/21 tool handlers wrap calls in try/catch (76%)

Wrap each tool handler body in try/catch and return a structured error response.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

No access to sensitive paths

Reads sensitive paths: ~/.ssh/known_hosts, ~/.ssh/known_hosts

Remove reads of sensitive system paths. If you genuinely need them, document why in the README.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/mdlmarkham/tailopsmcp?variant=verified)](https://m8ven.ai/mcp/mdlmarkham/tailopsmcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 23e2fff9d88753fb1201e3eed7e00e89570d7a0b
code hash: bcf8307cc18c13271d899ff1f3775b9af8c270d8e50ad8fe1c50d7a18447e107
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client