Nogra MCP (nograai/nogra-mcp) is an MCP server listed on the M8ven Trust Index. It scores 67 out of 100, grade C. It declares 58 tools. No publisher has claimed this listing.

C
Limited view
67/100

Nogra MCP

Provides 32 local tools for managing briefs, dispatch, run events, registry, and redaction in AI-assisted workflows, operating entirely on local markdown/JSON files with no network calls.

Limited view. Automated analysis covers part of this stack. Findings reflect what we verified. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

Limited view: static analysis for Python is partially covered.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

nograai

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configNOGRA_MCP_PLATFORM_OVERRIDE
configNOGRA_PINBOARD_HOST
configNOGRA_PINBOARD_PORT
configNOGRA_WORKSPACE
configNOGRA_ROOT
configY26_ROOT
configCLAUDE_BIN
configCODEX_BIN
configNOGRA_CODEX_DISPATCH_REASONING
configY26_CODEX_DISPATCH_REASONING
configNOGRA_CODEX_MODEL
configY26_CODEX_MODEL
configGEMINI_BIN
configNOGRA_GEMINI_APPROVAL_MODE
configY26_GEMINI_APPROVAL_MODE
configNOGRA_TRANSPORT_RUN_ID
configY26_TRANSPORT_RUN_ID
configNOGRA_TRANSPORT_TARGET
configNOGRA_PRODUCT_NAME
configY26_PRODUCT_NAME
configNOGRA_MCP_NAME
configNOGRA_MCP_PACKAGE_NAME
configNOGRA_MCP_ROOT
configNOGRA_CALLER_LABEL
configY26_CALLER_LABEL
configNOGRA_CLAUDE_PROJECTS_DIR
configY26_CLAUDE_PROJECTS_DIR
configNOGRA_MCP_TRANSCRIPT_LIMIT
configY26_MCP_TRANSCRIPT_LIMIT
configNOGRA_CODEX_MCP_NAME
configY26_CODEX_MCP_NAME
configNOGRA_MCP_BIN
configY26_MCP_BIN
configNOGRA_ROLE_CONFIG
configY26_ROLE_CONFIG
configNOGRA_SETTINGS_PATH
configY26_SETTINGS_PATH
configNOGRA_MANAGER_MODEL
configY26_MANAGER_MODEL
configNOGRA_ORCHESTRATOR_MODEL
configY26_ORCHESTRATOR_MODEL
configNOGRA_GEMINI_MODEL
configY26_GEMINI_MODEL
configNOGRA_PROJECT_MANAGER_ADAPTER
configY26_PROJECT_MANAGER_ADAPTER
configNOGRA_PM_ADAPTER
configY26_PM_ADAPTER
configNOGRA_PROJECT_MANAGER_MODEL
configY26_PROJECT_MANAGER_MODEL
configNOGRA_PM_MODEL
configY26_PM_MODEL
configNOGRA_AGENT_ADAPTER
configY26_AGENT_ADAPTER
configNOGRA_AGENT_MODEL
configY26_AGENT_MODEL
configNOGRA_AGENT_EFFORT
configY26_AGENT_EFFORT
configNOGRA_CLAUDE_PROJECT_DIR
configY26_CLAUDE_PROJECT_DIR
configNOGRA_MCP_INCLUDE_LOCAL_DOCTRINE
configSTINSON_ALLOW_CLAUDE_NATIVE
configNOGRA_TRANSPORT_STALE_SECONDS
configY26_TRANSPORT_STALE_SECONDS
configNOGRA_MCP_LOG_LEVEL
configY26_MCP_LOG_LEVEL
configNOGRA_HOSTED
configNOGRA_HOSTED_WORKSPACE_ID
configNOGRA_WORKSPACE_ID
configNOGRA_PUBLIC_MCP_ROOT
configNOGRA_HOSTED_WORKSPACE
configNOGRA_DEFAULT_TARGET_MODEL
configNOGRA_OWNER
configNOGRA_MCP_HOST
configNOGRA_TRANSPORT_POLL_SECONDS
configY26_TRANSPORT_POLL_SECONDS
configNOGRA_TRANSPORT_HEARTBEAT_SECONDS
configY26_TRANSPORT_HEARTBEAT_SECONDS
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

58/58 tools missing one or more hints — chain_pm_then_agent (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); transport_dispatch (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); agent_exec_packet (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +55 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

48/58 tool handlers declare input schemas (83%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 7/58 tool handlers wrap calls in try/catch (12%)

Wrap each tool handler body in try/catch and return a structured error response.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/nograai/nogra-mcp)](https://m8ven.ai/mcp/nograai/nogra-mcp)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: bf5798ffd4e040cfd941a56143b5554ec133a612
code hash: b5229625aabac604c1533398040e7cc00024bba873413943a8f0e057428a91f8
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client