VibeServe (ncsound919/VibeServe) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 108 tools. No publisher has claimed this listing.
A production-grade MCP server that turns natural language intent into fully-architected, accessible, production-ready UI code through a 7-step agentic pipeline.
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
ncsound919
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
VIBESERVE_HTTP_PORTVIBESERVE_HTTP_HOSTAGENT_WS_PORTVIBESERVE_GRAPH_DIRDESIGNER_PROVIDERENGINEER_PROVIDERADVOCATE_PROVIDERVIBESERVE_GITHUB_CONFIGVIBESERVE_REPOS_DIRVIBESERVE_MAX_PAYLOAD_BYTESVIBESERVE_WORKSPACEVIBESERVE_INDEX_DIRVIBESERVE_API_SECRETOPENAI_API_KEYOPENAI_BASE_URLOPENAI_MODELDEEPSEEK_API_KEYDEEPSEEK_MODELOPENROUTER_API_KEYOPENROUTER_MODELLOCAL_LLM_URLLOCAL_LLM_MODELOPENCODE_MODELDEFAULT_LLM_PROVIDERVIBESERVE_API_KEYAGENT_WS_HEARTBEAT_SVIBESERVE_BUDGET_MAX_TOKENSVIBESERVE_BUDGET_MAX_COSTVIBESERVE_MUTLY_API_KEYVIBESERVE_REQUIRE_AUTHVIBESERVE_MAX_BODY_BYTESCONTEXT7_API_KEYSUPABASE_KEYSUPABASE_URLGITHUB_TOKENCLOUDFLARE_TOKENCLOUDFLARE_ZONEGOOGLE_API_KEYVIBESERVE_COST_LOGVIBESERVE_LLM_RPMVIBESERVE_MEMORY_PATHBIG_HOMIE_URLBIG_HOMIE_MODELBIG_HOMIE_LLM_PROVIDERGOOGLE_MODELOLLAMA_API_KEYOLLAMA_BASE_URLOLLAMA_MODELOPENCODE_PROJECT_ROOTPYTEST_CURRENT_TESTVIBESERVE_MOCK_INTELLIGENCESENTRY_DSNSENTRY_TRACES_SAMPLE_RATESENTRY_PROFILES_SAMPLE_RATESENTRY_ENVIRONMENTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
108/108 tools missing one or more hints — llm_complete (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); memory_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); memory_store (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +105 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
106/108 tool handlers declare input schemas (98%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool test coverage
55/108 tools referenced in tests (51%)
Write tests that reference each tool by name so every tool has at least one test.
No eval / new Function
1 eval() or new Function() call — dynamic code execution
Replace eval / Function with explicit parsing or safer alternatives.
Readable source code
2 files are minified or bundled, which is usually build output rather than concealment
Ship unminified, readable source.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/ncsound919/vibeserve)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check