Orion (Mr-Nobody-Anonymous/Orion) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 102 tools. No publisher has claimed this listing.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Mr-Nobody-Anonymous

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: EVOMAP_VERTEX_ACCESS_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🚨
Code appears obfuscated
1 file are unreadable to a human reviewer. Cannot audit what they do.
🔐
You'll be asked for 31 credentials: ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, EVOMAP_ANTHROPIC_API_KEY, EVOMAP_ANTHROPIC_AUTH_TOKEN, EVOMAP_GEMINI_API_KEY, EVOMAP_OLLAMA_API_KEY, EVOMAP_OPENAI_API_KEY, EVOMAP_VERTEX_ACCESS_TOKEN, GEMINI_API_KEY, GOOGLE_API_KEY, HERMES_DESKTOP_REMOTE_TOKEN, OPENAI_API_KEY, PHOTON_PROJECT_SECRET, PHOTON_SIDECAR_TOKEN, BRIDGE_API_KEY, KYB_API_KEY, KYT_API_KEY, HF_TOKEN, FINNHUB_API_KEY, EVAL_LLM_API_KEY, LLM_API_KEY, API_TOKEN, KEY, XAI_API_KEY, HASS_TOKEN, OPENROUTER_API_KEY, CAMOFOX_API_KEY, CAMOFOX_SESSION_KEY, HERMES_RPC_TOKEN, DISCORD_BOT_TOKEN, HERMES_SESSION_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configA2A_HUB_URL
configA2A_TRANSPORT
configAGENT_NAME
🔐 secretANTHROPIC_API_KEY
🔐 secretANTHROPIC_AUTH_TOKEN
configATP_AUTOBUY_DAILY_CAP_CREDITS
configATP_AUTOBUY_PER_ORDER_CAP_CREDITS
configATP_AUTODELIVER_POLL_MS
configAWS_REGION
configCOMSPEC
configComSpec
configELECTRON_DISABLE_SANDBOX
configEVOLVER_ANTI_ABUSE_TELEMETRY
configEVOLVER_ATP
configEVOLVER_ATP_AUTOBUY
configEVOLVER_ATP_AUTODELIVER
configEVOLVER_CAFFEINATE
configEVOLVER_CURSOR_TRANSCRIPTS_DIR
configEVOLVER_CYCLE_TIMEOUT_ENABLED
configEVOLVER_CYCLE_TIMEOUT_MS
configEVOLVER_DEFAULT_HUB_URL
configEVOLVER_DISABLE_OOM_ADJUST
configEVOLVER_DISABLE_PRIORITY_BOOST
configEVOLVER_HOME
configEVOLVER_IDLE_FETCH_INTERVAL_MS
configEVOLVER_IDLE_THRESHOLD_MS
configEVOLVER_MAX_CYCLES_PER_PROCESS
configEVOLVER_MAX_RSS_MB
configEVOLVER_MAX_SLEEP_MS
configEVOLVER_MIN_SLEEP_MS
configEVOLVER_OUTCOME_REPORT
configEVOLVER_PROGRESS_UPDATE_MS
configEVOLVER_PROXY_SSE_ENABLED
configEVOLVER_PROXY_STORE
configEVOLVER_QUIET_PARENT_GIT
configEVOLVER_REUSE_ATTRIBUTION
configEVOLVER_SESSION_SOURCE
configEVOLVER_SETTINGS_DIR
configEVOLVER_SOLO_MAX_FAILS
configEVOLVER_SUICIDE
configEVOLVER_SUICIDE_WINDOWS
configEVOLVER_VALIDATOR_ENABLED
configEVOLVER_VALIDATOR_FETCH_TIMEOUT_MS
configEVOLVER_VALIDATOR_MAX_TASKS_PER_CYCLE
configEVOLVER_VERBOSE
configEVOLVE_BRIDGE
configEVOLVE_EXEC_BRIDGE
configEVOLVE_LOOP
configEVOLVE_MIN_INTERVAL
configEVOLVE_PENDING_SLEEP_MS
configEVOLVE_RECALL_VERIFY
configEVOLVE_RECALL_VERIFY_SAMPLE_RATE
configEVOLVE_STRATEGY
🔐 secretEVOMAP_ANTHROPIC_API_KEY
🔐 secretEVOMAP_ANTHROPIC_AUTH_TOKEN
configEVOMAP_ANTHROPIC_BASE_URL
configEVOMAP_ASSET_SEARCH_CACHE_MAX
configEVOMAP_ASSET_SEARCH_CACHE_TTL_MS
configEVOMAP_BEDROCK_ENDPOINT
🔐 secretEVOMAP_GEMINI_API_KEY
configEVOMAP_GEMINI_BASE_URL
configEVOMAP_HUB_URL
🔐 secretEVOMAP_OLLAMA_API_KEY
configEVOMAP_OLLAMA_BASE_URL
🔐 secretEVOMAP_OPENAI_API_KEY
configEVOMAP_OPENAI_BASE_URL
configEVOMAP_OPENAI_COMPATIBLE_BASE_URLS
configEVOMAP_PROXY
🔐 secretEVOMAP_VERTEX_ACCESS_TOKEN
🔐 secretGEMINI_API_KEY
🔐 secretGOOGLE_API_KEY
configHERMES_DESKTOP_APP_NAME
configHERMES_DESKTOP_BOOT_FAKE
configHERMES_DESKTOP_BOOT_FAKE_ERROR
configHERMES_DESKTOP_BOOT_FAKE_STEP_MS
configHERMES_DESKTOP_CWD
configHERMES_DESKTOP_DEV_SERVER
configHERMES_DESKTOP_HERMES
configHERMES_DESKTOP_HERMES_ROOT
configHERMES_DESKTOP_IS_PACKAGED
configHERMES_DESKTOP_POOL_IDLE_MS
configHERMES_DESKTOP_POOL_MAX
configHERMES_DESKTOP_PYTHON
🔐 secretHERMES_DESKTOP_REMOTE_TOKEN
configHERMES_DESKTOP_REMOTE_URL
configHERMES_DESKTOP_SHELL
configHERMES_DESKTOP_SKIP_QUIT_CONFIRM
configHERMES_DESKTOP_USER_DATA_DIR
configHERMES_DESKTOP_WEB_DIST
configHERMES_HOME
configHERMES_PORTAL_BASE_URL
configINIT_CWD
configMEMORY_GRAPH_SYNC_HUB
configNOUS_PORTAL_BASE_URL
🔐 secretOPENAI_API_KEY
configPHOTON_MAX_INLINE_ATTACHMENT_BYTES
configPHOTON_PROBE_SPACE_ID
configPHOTON_PROJECT_ID
🔐 secretPHOTON_PROJECT_SECRET
configPHOTON_SIDECAR_BIND
configPHOTON_SIDECAR_PORT
🔐 secretPHOTON_SIDECAR_TOKEN
configPHOTON_STREAM_DEGRADED_RESTART_MS
configPHOTON_STREAM_INTERRUPTED_DEGRADE_COUNT
configPHOTON_STREAM_PROBE_COOLDOWN_MS
configPHOTON_STREAM_PROBE_TIMEOUT_MS
configPHOTON_STREAM_SILENCE_PROBE_MS
configPHOTON_TELEMETRY
configPYTHONPATH
configProgramFiles
configProgramFiles(x86)
configRANDOM_DRIFT
configSHELL
configSystemRoot
configVIBE_TRADING_DESKTOP_LOCALE
configVIBE_TRADING_DESKTOP_PARENT_DEATH_SMOKE_FILE
configVIBE_TRADING_DESKTOP_TEST_USER_DATA
configwindir
🔐 secretBRIDGE_API_KEY
configBRIDGE_API_URL
configMCP_BRIDGE_PORT
🔐 secretKYB_API_KEY
configKYB_API_URL
configMCP_IDENTITY_PORT
🔐 secretKYT_API_KEY
configKYT_API_URL
configMCP_KYT_PORT
configHERMES_SESSION_ID
configSSH_CLIENT
configSSH_TTY
configDISPLAY
configWAYLAND_DISPLAY
configHERMES_TUI_SLASH_TIMEOUT_S
configHERMES_TUI_WS_ORPHAN_REAP_GRACE_S
configHERMES_TUI_RPC_POOL_WORKERS
configHERMES_TUI_SESSION_TTL_S
configTERMINAL_CWD
configHERMES_COMPUTE_HOST_CHILD
configTERMINAL_ENV
configHERMES_GATEWAY_SESSION
configHERMES_EXEC_ASK
configHERMES_INTERACTIVE
configHERMES_MODEL
configHERMES_INFERENCE_MODEL
configHERMES_DESKTOP
configHERMES_DESKTOP_TERMINAL
configHERMES_TUI_PROVIDER
configHERMES_INFERENCE_PROVIDER
configHERMES_TUI_TOOL_PROGRESS
configHERMES_TUI_TOOLSETS
configHERMES_DEV_CREDITS
configHERMES_TUI_MAX_TURNS
configHERMES_TUI_SKILLS
configHERMES_TUI_CHECKPOINTS
configHERMES_TUI_PASS_SESSION_ID
configHERMES_IGNORE_RULES
configHERMES_PET_REFERENCE_MAX_BYTES
configHERMES_YOLO_MODE
configHERMES_VOICE
configHERMES_VOICE_TTS
configBROWSER_CDP_URL
configORION_WEB_HOST
configORION_WEB_PORT
configHERMES_TUI
configHERMES_TUI_NO_EARLY_DISABLE
configPREFIX
configTERMUX_VERSION
configHERMES_TERMUX_DISABLE_FAST_CLI
configSUDO_USER
configHERMES_S6_SUPERVISED_CHILD
configHERMES_REDACT_SECRETS
configHERMES_TERMUX_FORCE_SKILLS_SYNC
configHERMES_TERMUX_PREFETCH_UPDATES
configHERMES_TUI_FORCE_BUILD
configHERMES_SKIP_NODE_BOOTSTRAP
configHERMES_QUIET
configHERMES_NODE
configHERMES_TUI_DIR
configHERMES_KANBAN_BOARD
configHERMES_IGNORE_USER_CONFIG
configHERMES_SESSION_SOURCE
configPROCESSOR_ARCHITEW6432
configelectron_config_cache
configELECTRON_CACHE
configXDG_CACHE_HOME
configCSC_LINK
configAPPLE_SIGNING_IDENTITY
configHERMES_WEB_DIST
configHERMES_SERVE_HEADLESS
configHERMES_SAFE_MODE
configHERMES_DEFER_AGENT_STARTUP
configHERMES_FAST_STARTUP_BANNER
configHERMES_ACCEPT_HOOKS
configATL_FRONTEND_ORIGINS
🔐 secretHF_TOKEN
🔐 secretFINNHUB_API_KEY
configLOCAL_RANK
configEVAL_USE_LITELLM
🔐 secretEVAL_LLM_API_KEY
🔐 secretLLM_API_KEY
configEVAL_LLM_BASE_URL
configSQLITE_PATH
configSQLITE_MAX_ROWS
configROBINHOOD_MCP_TIMEOUT_SECONDS
configALPHA_POOL_MEMORY_URL
configYFINANCE_AGENT_PROMPT
configMCP_ENV_FILE
configAPI_BASE_URL
🔐 secretAPI_TOKEN
configAPI_TIMEOUT_SECONDS
configHERMES_KANBAN_TASK
🔐 secretKEY
configHERMES_CONCURRENT_TOOL_TIMEOUT_S
🔐 secretXAI_API_KEY
configHERMES_CUA_DRIVER_CMD
configCUA_DRIVER_RS_HOME
🔐 secretHASS_TOKEN
🔐 secretOPENROUTER_API_KEY
configTS_BENCH_REPS
configTS_BENCH_MODES
configTS_BENCH_SUMMARY
configTS_UE_MODEL
configTS_UE_LISTING_MAX
configTS_UE_SCALE
configTS_UE_MODES
configTS_UE_SUMMARY
configHERMES_SESSION_PLATFORM
configHERMES_SPINNER_PAUSE
🔐 secretCAMOFOX_API_KEY
configCAMOFOX_URL
configCAMOFOX_USER_ID
🔐 secretCAMOFOX_SESSION_KEY
configCAMOFOX_LOOPBACK_HOST_ALIAS
configAUXILIARY_VISION_MODEL
configAUXILIARY_WEB_EXTRACT_MODEL
configAGENT_BROWSER_ENGINE
configAGENT_BROWSER_HEADED
configPLAYWRIGHT_BROWSERS_PATH
configAGENT_BROWSER_EXECUTABLE_PATH
configHERMES_RPC_SOCKET
🔐 secretHERMES_RPC_TOKEN
configHERMES_RPC_DIR
configHERMES_TIMEZONE
configDELEGATION_MAX_CONCURRENT_CHILDREN
configDELEGATION_CHILD_TIMEOUT_SECONDS
🔐 secretDISCORD_BOT_TOKEN
configHERMES_DISABLE_FILE_STATE_GUARD
configHASS_URL
configFAL_IMAGE_MODEL
configHERMES_DEBUG_INTERRUPT
configHERMES_KANBAN_RUN_ID
configHERMES_KANBAN_CLAIM_LOCK
configHERMES_PROFILE
configHERMES_TENANT
🔐 secretHERMES_SESSION_KEY
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

109/109 tools missing one or more hints — mcpremote (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_skills (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); load_skill (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +106 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Shell command execution

6 calls in production code run through a shell (source_repositories/agents/evolver/index.js:946, source_repositories/agents/evolver/index.js:2256, source_repositories/agents/evolver/index.js:2257)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Readable source code

1 file are minified or bundled, which is usually build output rather than concealment

Ship unminified, readable source.

Domain consistency

npm scope @workspace doesn't match GitHub owner mr-nobody-anonymous

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/mr-nobody-anonymous/orion?variant=verified)](https://m8ven.ai/mcp/mr-nobody-anonymous/orion)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: c512d7915decee6a9668991b3deb201afc1936c4
code hash: 9030f3c868ed7db9fae7e6eca8b0e195ac60f606659db9be0d2eccde15a7e8ce
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client