openagents (openagents-org/openagents) is an MCP server listed on the M8ven Trust Index. It scores 40 out of 100, grade D. It declares 29 tools. No publisher has claimed this listing.

D
Warning
40/100

openagents

OpenAgents - The collaboration OS for AI agents

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

openagents-org

Source: github_code

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: BROWSERFABRIC_API_KEY, BROWSERFABRIC_PROVISION_SECRET. We can’t prove the destination matches the brand the credential belongs to.
🚨
Hardcoded credentials detected
2 live-looking API keys in source: 2 Google API key
🔐
You'll be asked for 24 credentials: OA_WORKSPACE_TOKEN, OPENAGENTS_WORKSPACE_TOKEN, BRAVE_API_KEY, EXA_API_KEY, BROWSERFABRIC_API_KEY, BROWSERFABRIC_PROVISION_SECRET, APNS_AUTH_KEY, ROUTER_LLM_API_KEY, ANTHROPIC_API_KEY, YUMI_API_KEY, GOOGLE_OAUTH_CLIENT_SECRET, RESEND_API_KEY, SLACK_CLIENT_SECRET, SLACK_SIGNING_SECRET, CAMPAIGN_GATEWAY_MASTER_KEY, OPENAI_API_KEY, KIMI_API_KEY, MOONSHOT_API_KEY, LLM_API_KEY, AZURE_OPENAI_API_KEY, OPENAGENTS_API_KEY, DEFAULT_LLM_API_KEY, GOOGLE_API_KEY, MINIMAX_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configAMP_HOME
configASDF_DATA_DIR
configBUN_INSTALL
configChocolateyInstall
configComSpec
configDENO_INSTALL
configELECTRON_RENDERER_URL
configFNM_DIR
configNPM_CONFIG_PREFIX
configNVM_BIN
configNVM_DIR
configNVM_HOME
configNVM_SYMLINK
🔐 secretOA_WORKSPACE_TOKEN
configOPENAGENTS_AGENT_NAME
configOPENAGENTS_CHANNEL_NAME
configOPENAGENTS_DEVTOOLS_PORT
configOPENAGENTS_DOWNLOAD_REGION
configOPENAGENTS_ENDPOINT
configOPENAGENTS_INSTALL_STALL_MS
configOPENAGENTS_SKIP_UPDATE_CHECK
configOPENAGENTS_WORKSPACE_ID
🔐 secretOPENAGENTS_WORKSPACE_TOKEN
configOPENCODE_INSTALL_DIR
configPNPM_HOME
configProgramFiles
configSCOOP
configSHELL
configSystemRoot
configUV_TOOL_DIR
configVOLTA_HOME
configXDG_BIN_HOMEuses uv tool install, which places aider in $ →
configXDG_DATA_HOME$/../bin → ~/.local/bin (and always in the uv tools venv).
configTHREADPOOL_TOKENS
🔐 secretBRAVE_API_KEY
🔐 secretEXA_API_KEY
configMAX_BROWSER_TABS
🔐 secretBROWSERFABRIC_API_KEY
configBROWSERFABRIC_URL
🔐 secretBROWSERFABRIC_PROVISION_SECRET
configBROWSER_SANDBOX
configBROWSER_TAB_IDLE_MINUTES
configBROWSER_CLOSE_RETRY_WINDOW_HOURS
configBROWSER_CLOSING_STALE_MINUTES
configBROWSER_SWEEP_MAX_ACTIONS
configAUTH_MODE
configFIREBASE_PROJECT_ID
configFIREBASE_CREDENTIALS_JSON
configAPPLE_CLIENT_IDS
🔐 secretAPNS_AUTH_KEY
configAPNS_AUTH_KEY_PATH
configAPNS_KEY_ID
configAPNS_TEAM_ID
configAPNS_BUNDLE_ID
configAPNS_ENVIRONMENT
configIDENTITY_MODE
configAGENT_TIMEOUT_SECONDS
configENFORCE_AGENT_LIFECYCLE_AUTH
configCORS_ORIGINS
configFILE_STORAGE_BACKEND
configFILE_STORAGE_PATH
configS3_BUCKET
configS3_REGION
configMAX_FILE_SIZE
configAPP_ANDROID_LATEST_VERSION
configAPP_ANDROID_LATEST_BUILD
configAPP_ANDROID_MIN_BUILD
configAPP_ANDROID_UPDATE_URL
configAPP_ANDROID_RELEASE_NOTES
configAPP_IOS_LATEST_VERSION
configAPP_IOS_LATEST_BUILD
configAPP_IOS_MIN_BUILD
configAPP_IOS_UPDATE_URL
configAPP_IOS_RELEASE_NOTES
configROUTER_LLM_ENABLED
configROUTER_LLM_PROVIDER
configROUTER_LLM_MODEL
🔐 secretROUTER_LLM_API_KEY
configROUTER_LLM_BASE_URL
🔐 secretANTHROPIC_API_KEYe.g. AIDER_MODEL=sonnet / opus / claude-3-5-sonnet-20241022
configCLOUD_AGENT_MAX_CONTEXT_MESSAGES
configCLOUD_AGENT_MAX_CONTEXT_CHARS
configCLOUD_AGENT_MAX_DEPTH
configYUMI_ENABLED
🔐 secretYUMI_API_KEY
configYUMI_BASE_URL
configYUMI_MODEL
configYUMI_MAX_TOOL_ITERATIONS
configGOOGLE_OAUTH_CLIENT_ID
🔐 secretGOOGLE_OAUTH_CLIENT_SECRET
configFRONTEND_BASE_URL
🔐 secretRESEND_API_KEY
configEMAIL_FROM
configINVITE_TTL_DAYS
configSLACK_CLIENT_ID
🔐 secretSLACK_CLIENT_SECRET
🔐 secretSLACK_SIGNING_SECRET
configCAMPAIGN_ENABLED
configCAMPAIGN_GATEWAY_URL
🔐 secretCAMPAIGN_GATEWAY_MASTER_KEY
configCAMPAIGN_TOTAL_CAP_USD
configCAMPAIGN_DAILY_GRANT_USD
configFEEDBACK_EMAIL_TO
configHOST
configVERCEL
configAWS_LAMBDA_FUNCTION_NAME
configDB_PGBOUNCER
configOUTBOUND_ALLOWED_PORTS
configSOURCE_API
configDRY_RUN_CHANNEL
🔐 secretOPENAI_API_KEYe.g. AIDER_MODEL=gpt-4o
configOPENAI_BASE_URL
configCODEX_MODEL
configOPENCLAW_MODEL
configCURSOR_MODEL
configGOOSE_MAX_TURNSoverride ) and --max-tool-repetitions (default 12,
🔐 secretKIMI_API_KEY
🔐 secretMOONSHOT_API_KEY
🔐 secretLLM_API_KEYvariable your is injected into. It accepts auto (default),
configKIMI_BASE_URL
configLLM_BASE_URLrequires LLM_BASE_URL; the model is normalized to openai/<model>
configKIMI_MODEL
configLLM_MODEL
configOPENCLAW_DIRECT_API
configOPENCLAW_WORKSPACE_DIR
🔐 secretAZURE_OPENAI_API_KEY
configOPENAI_API_VERSION
🔐 secretOPENAGENTS_API_KEY
configPYTHONIOENCODING
configDEFAULT_LLM_PROVIDER
configDEFAULT_LLM_MODEL_NAME
🔐 secretDEFAULT_LLM_API_KEY
configDEFAULT_LLM_BASE_URL
configAWS_DEFAULT_REGION
configAWS_BEARER_TOKEN_BEDROCK
🔐 secretGOOGLE_API_KEY
🔐 secretMINIMAX_API_KEY
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployNEXT_PUBLIC_API_URL
deployNEXT_PUBLIC_GA_ID
deployNEXT_PUBLIC_POSTHOG_HOST
deployNEXT_PUBLIC_POSTHOG_KEY
deployDATABASE_URL
deployREDIS_URL
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

29/29 tools missing one or more hints — workspace_get_history (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); workspace_get_agents (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); workspace_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +26 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

No hardcoded API keys

2 live-looking API keys in source: 2 Google API key

Move secrets to environment variables (process.env.X) or your secret manager.

Tool test coverage

17/29 tools referenced in tests (59%)

Write tests that reference each tool by name so every tool has at least one test.

Shell command execution

36 calls in production code run through a shell (packages/agent-connector/src/mcp-server.js:834, packages/launcher/src/main/index.ts:2267, packages/agent-connector/src/autostart.js:59)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets not written to files

1 secret value written to files

Avoid persisting secrets to disk. Keep them in memory or your secret manager.

Secrets not logged

1 secret value sent to logger.info

Redact or omit secret values from log output.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/openagents-org/openagents?variant=verified)](https://m8ven.ai/mcp/openagents-org/openagents)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: df8327ca94d1a969241f205ea7b0ce2a4326ed62
code hash: 143f4796499024a45998483f735655b0c54cc81a8da8143193e18953fd466a5e
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client