okffs (neturely/okffs) is an MCP server listed on the M8ven Trust Index. It scores 64 out of 100, grade C. It declares 23 tools. No publisher has claimed this listing.

C
Caution
64/100

okffs

An MCP server that lets Claude Code manage GitHub issues, branches, and pull requests through natural language, automating the full development workflow from planning to closing.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Sandbox Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

neturely

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

⏳ This MCP is queued for scoring. Check back in a few minutes.
// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: GITHUB_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configGITHUB_OWNER1. / GITHUB_REPO in .env.
configGITHUB_REPO1. GITHUB_OWNER / in .env.
🔐 secretGITHUB_TOKENghp_your_token_here
configOKFFS_AUTOPILOT
configOKFFS_AUTO_MERGE_BASEfalse Let merge_pull_request autonomously merge a green, threads-resolved issue PR into the base branch. Never merges OKFFS_PROTECTED_BRANCH.
configOKFFS_AUTO_PRfalse Open a draft PR when a new issue branch is created.
configOKFFS_BASE_BRANCHrepo default Branch new issue branches are created from.
configOKFFS_CLASSIC_PATfalse Set true only with a classic admin:org PAT — enables org-level Issue Field Priority/Effort (broad token; security tradeoff).
configOKFFS_DEFAULT_ASSIGNEESComma-separated usernames assigned to every new issue.
configOKFFS_DEFAULT_EFFORTOKFFS_DEFAULT_PRIORITY / — Board Priority/Effort fallback when none is inferred or given.
configOKFFS_DEFAULT_LABELSComma-separated labels merged with inferred ones.
configOKFFS_DEFAULT_PRIORITY/ OKFFS_DEFAULT_EFFORT — Board Priority/Effort fallback when none is inferred or given.
configOKFFS_DEFAULT_TYPENative Issue Type fallback when none is inferred or given (e.g. Task).
configOKFFS_EXCLUDE_DOCSCLAUDE.md, CONTRIBUTING.md, and README.md are intentionally left for you to maintain. Exclude specific files per repo with (valid: CHANGELOG.md, SECURITY.md).
configOKFFS_IDENTIFIERPrefix for branch names: {number}-{identifier}-{slug}.
configOKFFS_INFER_EFFORTOKFFS_INFER_PRIORITY / true Let Claude infer priority/effort from the task.
configOKFFS_INFER_PRIORITY/ OKFFS_INFER_EFFORT true Let Claude infer priority/effort from the task.
configOKFFS_INFER_TYPEtrue Let Claude infer the native GitHub Issue Type (Task/Bug/Feature/…) from the task. Org-level; skipped cleanly on user repos.
configOKFFS_PROJECT_AUTO_ADDAuto-add () is a fallback for boards without GitHub's native "Auto-add to project" workflow — leave it false if your board already auto-adds.
configOKFFS_PROJECT_ENABLEDupdate_project_status Moves an issue between board columns (Backlog, Ready, In Progress, Review). Needs .
configOKFFS_PROJECT_IDPVT_kwHO... # the board's GraphQL node ID
configOKFFS_PROJECT_INITIAL_STATUSColumn a freshly added issue lands in (e.g. Backlog).
configOKFFS_PROMOTION_AUTO_REVIEWOKFFS_PROMOTION_REVIEWERS — Comma-separated reviewers to request on the gate PR (e.g. copilot-pull-request-reviewer[bot]). Only acted on when =true.
configOKFFS_PROMOTION_REVIEWERSComma-separated reviewers to request on the gate PR (e.g. copilot-pull-request-reviewer[bot]). Only acted on when OKFFS_PROMOTION_AUTO_REVIEW=true.
configOKFFS_PROMOTION_STATUSBoard Status column the promotion PR card lands in (e.g. Review). Needs OKFFS_PROJECT_ENABLED.
configOKFFS_PROMPT_METADATAtrue Set false to hide the assignees/labels tip.
configOKFFS_PROTECTED_BRANCHOKFFS_AUTO_MERGE_BASE false Let merge_pull_request autonomously merge a green, threads-resolved issue PR into the base branch. Never merges .
configOKFFS_RESOLVE_THREADSresolve_review_thread Resolves a review thread — only when =true.
configOKFFS_UPDATE_DOCSWith =true, create_pull_request writes doc updates onto the branch so they land in the PR diff:
configOKFFS_UPDATE_GUIDANCEfalse Nudge Claude to keep CLAUDE.md in sync at PR time.
// quality suggestions

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/neturely/okffs?variant=verified)](https://m8ven.ai/mcp/neturely/okffs)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 45be5859768e88a3172da5ba8b17e2da05651e3f
code hash: 756672b8c43e704e651298f9b3e38fdda592b3d3bed9e89921a0aa79de312ff6
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client