omnibase_infra (OmniNode-ai/omnibase_infra) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it yet. No publisher has claimed this listing.

C
Emerging
74/100

omnibase_infra

ONEX Infrastructure repository with PostgreSQL adapter and comprehensive testing

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

OmniNode-ai

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
7 flows detected: GH_TOKEN, LINEAR_API_KEY, INFISICAL_CLIENT_SECRET. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 11 credentials: GH_TOKEN, GITHUB_TOKEN, LINEAR_API_KEY, DEPLOY_AGENT_HMAC_SECRET, VALKEY_PASSWORD, SLACK_BOT_TOKEN, INFISICAL_ADMIN_PASSWORD, INFISICAL_CLIENT_SECRET, POSTGRES_PASSWORD, KAFKA_SASL_PASSWORD, KC_ADMIN_PASSWORD
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configCORS_ORIGINS
configBACKFILL_DEBUG
configBACKFILL_CONNECTION_TIMEOUT
configOMNIBASE_INFRA_DB_URL
configOMNI_HOME
🔐 secretGH_TOKEN
🔐 secretGITHUB_TOKEN
configOMNI_GIT_MIRROR_HOST
configOMNI_GIT_MIRROR_PORT
🔐 secretLINEAR_API_KEY
configKAFKA_BOOTSTRAP_SERVERS
configX
configSSM_INSTANCE_ID
configCONSUL_HOST
configCONSUL_PORT
🔐 secretDEPLOY_AGENT_HMAC_SECRET
configKEEP_LIST
configGITHUB_REPO
configMOUNT
configUSED_PCT
configAVAIL_KB
configAVAIL_GB
configSEVERITY
configHALT_REASON
configWARN_PCT
configWARN_FREE_GB
configCRIT_FREE_GB
configHOSTNAME_TAG
configTOPIC
configONEX_GROUP_ID
configLANE_CENSUS_HOST
configLANE
configRUNTIME_TAG
configLANE_CENSUS_DOCKER_SOCKET
configLANE_CENSUS_API_TIMEOUT_S
configLANE_CENSUS_CLI_TIMEOUT_S
configLANE_MANIFEST
configCLAUDE_SCRATCHPAD_DIR
configONEX_STATE_DIR
configMONITOR_WARNING_COOLDOWN
configVALKEY_PORT
configVALKEY_DB
🔐 secretVALKEY_PASSWORD
configONEX_ENVIRONMENT
configMONITOR_RESTART_CONTAINERS
configMONITOR_FILE_LOGS
configMONITOR_JOURNALS
configMONITOR_COOLDOWN
🔐 secretSLACK_BOT_TOKEN
configSLACK_CHANNEL_ID
configMONITOR_PROJECTS
configOMNINODE_CI_PROBE_OWNER
configOMNINODE_CI_ABSENT_GRACE_MINUTES
configOMNINODE_CI_ABSENT_CEILING_MINUTES
configOMNINODE_CI_ZEROJOB_WINDOW_MINUTES
configOMNINODE_CI_PROBE_TIMEOUT_SECONDS
configOMNINODE_CI_PROBE_NOW
configOMNINODE_CI_PROBE_REPOS
configOMNINODE_CI_PROBE_FIXTURE_DIR
configGH_PAT
configONEX_COMPOSE_FILE
configOMNIBASE_DIR
configHOTPATCH_PREFLIGHT_BYPASS
configHOTPATCH_LEDGER_PATH
configOMNIBASE_OPERATOR_ENV_FILE
configINFISICAL_TRUSTED_IPS
🔐 secretINFISICAL_ADMIN_PASSWORD
configINFISICAL_ADDR
configINFISICAL_CLIENT_ID
🔐 secretINFISICAL_CLIENT_SECRET
configINFISICAL_PROJECT_ID
🔐 secretPOSTGRES_PASSWORD
configKAFKA_SASL_USERNAME
🔐 secretKAFKA_SASL_PASSWORD
configGITHUB_EVENT_PATH
configGITHUB_OUTPUT
configKC_URL
configKC_REALM
configKC_ADMIN_USERNAME
🔐 secretKC_ADMIN_PASSWORD
configKC_CONFIG
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployDATABASE_URL
// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/omninode-ai/omnibase_infra)](https://m8ven.ai/mcp/omninode-ai/omnibase_infra)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: d2b9c8690937b16c3aa5ec88f40ac990d4195df3
code hash: 20ae8b78eb97805fa6d2965625d0e4dac77042b5f0964db1e7617939653770be
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client