okffs (neturely/okffs) is an MCP server listed on the M8ven Trust Index. It scores 64 out of 100, grade C. It declares 23 tools. No publisher has claimed this listing.
An MCP server that lets Claude Code manage GitHub issues, branches, and pull requests through natural language, automating the full development workflow from planning to closing.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
neturely
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
GITHUB_OWNER1. / GITHUB_REPO in .env.GITHUB_REPO1. GITHUB_OWNER / in .env.GITHUB_TOKENghp_your_token_hereOKFFS_AUTOPILOTOKFFS_AUTO_MERGE_BASEfalse Let merge_pull_request autonomously merge a green, threads-resolved issue PR into the base branch. Never merges OKFFS_PROTECTED_BRANCH.OKFFS_AUTO_PRfalse Open a draft PR when a new issue branch is created.OKFFS_BASE_BRANCHrepo default Branch new issue branches are created from.OKFFS_CLASSIC_PATfalse Set true only with a classic admin:org PAT — enables org-level Issue Field Priority/Effort (broad token; security tradeoff).OKFFS_DEFAULT_ASSIGNEESComma-separated usernames assigned to every new issue.OKFFS_DEFAULT_EFFORTOKFFS_DEFAULT_PRIORITY / — Board Priority/Effort fallback when none is inferred or given.OKFFS_DEFAULT_LABELSComma-separated labels merged with inferred ones.OKFFS_DEFAULT_PRIORITY/ OKFFS_DEFAULT_EFFORT — Board Priority/Effort fallback when none is inferred or given.OKFFS_DEFAULT_TYPENative Issue Type fallback when none is inferred or given (e.g. Task).OKFFS_EXCLUDE_DOCSCLAUDE.md, CONTRIBUTING.md, and README.md are intentionally left for you to maintain. Exclude specific files per repo with (valid: CHANGELOG.md, SECURITY.md).OKFFS_IDENTIFIERPrefix for branch names: {number}-{identifier}-{slug}.OKFFS_INFER_EFFORTOKFFS_INFER_PRIORITY / true Let Claude infer priority/effort from the task.OKFFS_INFER_PRIORITY/ OKFFS_INFER_EFFORT true Let Claude infer priority/effort from the task.OKFFS_INFER_TYPEtrue Let Claude infer the native GitHub Issue Type (Task/Bug/Feature/…) from the task. Org-level; skipped cleanly on user repos.OKFFS_PROJECT_AUTO_ADDAuto-add () is a fallback for boards without GitHub's native "Auto-add to project" workflow — leave it false if your board already auto-adds.OKFFS_PROJECT_ENABLEDupdate_project_status Moves an issue between board columns (Backlog, Ready, In Progress, Review). Needs .OKFFS_PROJECT_IDPVT_kwHO... # the board's GraphQL node IDOKFFS_PROJECT_INITIAL_STATUSColumn a freshly added issue lands in (e.g. Backlog).OKFFS_PROMOTION_AUTO_REVIEWOKFFS_PROMOTION_REVIEWERS — Comma-separated reviewers to request on the gate PR (e.g. copilot-pull-request-reviewer[bot]). Only acted on when =true.OKFFS_PROMOTION_REVIEWERSComma-separated reviewers to request on the gate PR (e.g. copilot-pull-request-reviewer[bot]). Only acted on when OKFFS_PROMOTION_AUTO_REVIEW=true.OKFFS_PROMOTION_STATUSBoard Status column the promotion PR card lands in (e.g. Review). Needs OKFFS_PROJECT_ENABLED.OKFFS_PROMPT_METADATAtrue Set false to hide the assignees/labels tip.OKFFS_PROTECTED_BRANCHOKFFS_AUTO_MERGE_BASE false Let merge_pull_request autonomously merge a green, threads-resolved issue PR into the base branch. Never merges .OKFFS_RESOLVE_THREADSresolve_review_thread Resolves a review thread — only when =true.OKFFS_UPDATE_DOCSWith =true, create_pull_request writes doc updates onto the branch so they land in the PR diff:OKFFS_UPDATE_GUIDANCEfalse Nudge Claude to keep CLAUDE.md in sync at PR time.Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/neturely/okffs)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check