C
Emerging
74/100
2 days ago

nastech-agent

The agent that grows with you, Nastech - Agent Powered By NOUS RESEARCH.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

nastechresearch

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 13 credentials: PHOTON_PROJECT_SECRET, PHOTON_SIDECAR_TOKEN, API_TOKEN, XAI_API_KEY, OPENROUTER_API_KEY, BROWSER_USE_API_KEY, NASTECH_RPC_TOKEN, NASTECH_SESSION_KEY, TOOL_GATEWAY_USER_TOKEN, OPENAI_API_KEY, SUDO_PASSWORD, TERMINAL_SSH_KEY, MODAL_TOKEN_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configNASTECH_DASHBOARD_URL
configPHOTON_MAX_INLINE_ATTACHMENT_BYTES
configPHOTON_PROBE_SPACE_ID
configPHOTON_PROJECT_ID
🔐 secretPHOTON_PROJECT_SECRET
configPHOTON_SIDECAR_BIND
configPHOTON_SIDECAR_PORT
🔐 secretPHOTON_SIDECAR_TOKEN
configPHOTON_STREAM_DEGRADED_RESTART_MS
configPHOTON_STREAM_INTERRUPTED_DEGRADE_COUNT
configPHOTON_STREAM_PROBE_COOLDOWN_MS
configPHOTON_STREAM_PROBE_TIMEOUT_MS
configPHOTON_STREAM_SILENCE_PROBE_MS
configPHOTON_TELEMETRY
configTAURI_DEV_HOST
configNASTECH_INTERACTIVE
configNASTECH_SESSION_ID
configSSH_CLIENT
configSSH_TTY
configDISPLAY
configWAYLAND_DISPLAY
configNASTECH_TUI_SLASH_TIMEOUT_S
configNASTECH_TUI_WS_ORPHAN_REAP_GRACE_S
configNASTECH_TUI_RPC_POOL_WORKERS
configNASTECH_TUI_SESSION_TTL_S
configTERMINAL_CWD
configNASTECH_COMPUTE_HOST_CHILD
configTERMINAL_ENV
configNASTECH_GATEWAY_SESSION
configNASTECH_EXEC_ASK
configNASTECH_MODEL
configNASTECH_INFERENCE_MODEL
configNASTECH_DESKTOP
configNASTECH_DESKTOP_TERMINAL
configNASTECH_TUI_PROVIDER
configNASTECH_INFERENCE_PROVIDER
configNASTECH_TUI_TOOL_PROGRESS
configNASTECH_TUI_TOOLSETS
configNASTECH_DEV_CREDITS
configNASTECH_TUI_MAX_TURNS
configNASTECH_TUI_SKILLS
configNASTECH_TUI_CHECKPOINTS
configNASTECH_TUI_PASS_SESSION_ID
configNASTECH_IGNORE_RULES
configNASTECH_PET_REFERENCE_MAX_BYTES
configNASTECH_YOLO_MODE
configNASTECH_VOICE
configNASTECH_VOICE_TTS
configBROWSER_CDP_URL
configNASTECH_HOMEfull git checkout it creates at $/nastech-agent (usually
configNASTECH_TUI
configNASTECH_TUI_NO_EARLY_DISABLE
configSUDO_USER
configNASTECH_S6_SUPERVISED_CHILD
configNASTECH_REDACT_SECRETS
configNASTECH_TERMUX_FORCE_SKILLS_SYNC
configNASTECH_TERMUX_PREFETCH_UPDATES
configNASTECH_TUI_FORCE_BUILD
configNASTECH_SKIP_NODE_BOOTSTRAP
configNASTECH_QUIET
configNASTECH_NODE
configNASTECH_TUI_DIR
configNASTECH_KANBAN_BOARD
configNASTECH_IGNORE_USER_CONFIG
configNASTECH_SESSION_SOURCE
configPROCESSOR_ARCHITEW6432
configelectron_config_cache
configELECTRON_CACHE
configXDG_CACHE_HOME
configCSC_LINK
configAPPLE_SIGNING_IDENTITY
configELECTRON_DISABLE_SANDBOX
configKDE_SESSION_VERSION
configKDE_FULL_SESSION
configGNOME_KEYRING_CONTROL
configNASTECH_WEB_DIST
configNASTECH_SERVE_HEADLESS
configNASTECH_SAFE_MODE
configNASTECH_DISABLE_FAST_CHAT_LAUNCH
configNASTECH_TERMUX_DISABLE_FAST_CLI
configNASTECH_DEFER_AGENT_STARTUP
configNASTECH_FAST_STARTUP_BANNER
configNASTECH_ACCEPT_HOOKS
configNASTECH_CUA_DRIVER_CMD
configSQLITE_PATH
configSQLITE_MAX_ROWS
configAPI_BASE_URL
🔐 secretAPI_TOKEN
configAPI_TIMEOUT_SECONDS
configNASTECH_KANBAN_TASK
🔐 secretXAI_API_KEY
configCUA_DRIVER_RS_HOME
🔐 secretOPENROUTER_API_KEY
configTS_BENCH_REPS
configTS_BENCH_MODES
configTS_BENCH_SUMMARY
configTS_UE_MODEL
configTS_UE_LISTING_MAX
configTS_UE_SCALE
configTS_UE_MODES
configTS_UE_SUMMARY
configNASTECH_SESSION_PLATFORM
configNASTECH_SPINNER_PAUSE
configCAMOFOX_LOOPBACK_HOST_ALIAS
configAUXILIARY_VISION_MODEL
configAUXILIARY_WEB_EXTRACT_MODEL
configAGENT_BROWSER_ENGINE
configAGENT_BROWSER_HEADED
configPLAYWRIGHT_BROWSERS_PATH
configAGENT_BROWSER_EXECUTABLE_PATH
configBU_NAME
🔐 secretBROWSER_USE_API_KEY
configBH_AGENT_WORKSPACE
configNASTECH_RPC_SOCKET
🔐 secretNASTECH_RPC_TOKEN
configNASTECH_RPC_DIR
configNASTECH_TIMEZONE
configDELEGATION_MAX_CONCURRENT_CHILDREN
configDELEGATION_CHILD_TIMEOUT_SECONDS
configNASTECH_DISABLE_FILE_STATE_GUARD
configFAL_IMAGE_MODEL
configNASTECH_DEBUG_INTERRUPT
configNASTECH_KANBAN_RUN_ID
configNASTECH_KANBAN_CLAIM_LOCK
configNASTECH_PROFILE
configNASTECH_TENANT
🔐 secretNASTECH_SESSION_KEY
configNASTECH_DISABLE_LAZY_INSTALLS
🔐 secretTOOL_GATEWAY_USER_TOKEN
configTOOL_GATEWAY_SCHEME
configTOOL_GATEWAY_DOMAIN
configOSV_ENDPOINT
configOSV_CHECK_CACHE_TTL
configTERMINAL_LOCAL_MEMORY_MAX_MB
config_NASTECH_GATEWAY
configTERMINAL_TIMEOUT
configWEIXIN_HOME_CHANNEL
configSOME_CONFIG
🔐 secretOPENAI_API_KEY
configNASTECH_SYNC_BASE_URL
configNASTECH_SYNC_DEVICE_NAME
configNASTECH_PLATFORM
🔐 secretSUDO_PASSWORD
configTERMINAL_LIFETIME_SECONDS
configTERMINAL_CONTAINER_PERSISTENT
configTERMINAL_DOCKER_MOUNT_CWD_TO_WORKSPACE
configTERMINAL_DOCKER_SHM_SIZE
configTERMINAL_MODAL_MODE
configTERMINAL_DOCKER_IMAGE
configTERMINAL_SINGULARITY_IMAGE
configTERMINAL_MODAL_IMAGE
configTERMINAL_DAYTONA_IMAGE
configTERMINAL_VERCEL_RUNTIME
configTERMINAL_SSH_HOST
configTERMINAL_SSH_USER
🔐 secretTERMINAL_SSH_KEY
configTERMINAL_PERSISTENT_SHELL
configTERMINAL_LOCAL_PERSISTENT
configTERMINAL_DOCKER_RUN_AS_HOST_USER
configTERMINAL_DOCKER_NETWORK
configTERMINAL_DEGRADED_MODE
configTERMINAL_SANDBOX_DIR
configTIRITH_BIN
configMODAL_TOKEN_ID
🔐 secretMODAL_TOKEN_SECRET
configSTT_OPENAI_MODEL
configSTT_GROQ_MODEL
configSTT_MISTRAL_MODEL
configSTT_ELEVENLABS_MODEL
configGROQ_BASE_URL
configSTT_OPENAI_BASE_URL
configXAI_STT_BASE_URL
configELEVENLABS_STT_BASE_URL
configNASTECH_ALLOW_PRIVATE_URLS
configNASTECH_VISION_DOWNLOAD_TIMEOUT
configNASTECH_VISION_MAX_CONCURRENCY
configAUXILIARY_VIDEO_MODEL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

18/18 tools missing one or more hints — conversations_list (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); conversation_get (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); messages_read (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +15 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

13/18 tools referenced in tests (72%)

Write tests that reference each tool by name so every tool has at least one test.

Shell command execution

3 child_process/subprocess calls in production code — runs shell commands (nastech_cli/main.py:1733, nastech_cli/main.py:9782, nastech_cli/main.py:11175)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets not logged

1 secret value sent to console.log

Redact or omit secret values from log output.

No arbitrary install scripts

Has postinstall/preinstall script — runs arbitrary code on npm install

Remove postinstall/preinstall hooks unless they’re essential.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/nastechresearch-nastech-agent-macx75)](https://m8ven.ai/mcp/nastechresearch-nastech-agent-macx75)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 81c961639c03c4801ac0e2c6603044f232ce004b
code hash: 2ec69586af29edf81438c935ba61f8a1083ee87aa4db48df43f61100263d7b2c
verified: 8/19/2026, 9:17:04 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client