26
/ 100
3 days ago
pulsemcp

BearingBrain

Bearing lookup, fitment analysis, and quote review for industrial parts sourcing.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Tool annotations don’t match behaviour
9 read-only tools perform write/delete/exec — bearingbrain (line 104: fs.mkdirSync(dir, { recursive: true })); recommend_buy_option (line 104: fs.mkdirSync(dir, { recursive: true })); about_bearingbrain (line 104: fs.mkdirSync(dir, { recursive: true }))
⚠️
Tool descriptions don’t match what handlers do
1 tool describes read intent but its handler mutates — bearingbrain (line 104: fs.mkdirSync(dir, { recursive: true }))
⚠️
Known vulnerabilities in dependencies: 7 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 4 credentials: GOOGLE_GEMINI_API_KEY, JWT_SECRET, SKF_API_KEY, STRIPE_SECRET_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAMAZON_ASSOCIATE_TAG
configAPP_URL
configCJ_DEEP_LINK_BASE
configCJ_PUBLISHER_ID
configDATABASE_URLOptional: PostgreSQL-compatible for catalog-backed search tools
configFAILURE_DIAG_MODEL
configGEMINI_MODEL
🔐 secretGOOGLE_GEMINI_API_KEYOptional: , SKF_API_KEY, Stripe/CJ settings for integration paths copied from the private app
🔐 secretJWT_SECRET
configNEXT_PUBLIC_BASE_URL
configPARTS_AGENT_PLANNER_THINKING
configPARTS_CHAT_MODEL
configPARTS_CHAT_THINKING
configPARTS_CHAT_TIMEOUT_MS
configPARTS_EXTRACT_THINKING
configPARTS_HELPER_MODEL
configPARTS_PARAMS_MODEL
configPARTS_PLANNER_MODEL
configPARTS_REWRITE_MODEL
configPARTS_REWRITE_THINKING
configPI_AGENT_BIN
configPI_AGENT_CWD
configPI_AGENT_MODEL
configPI_AGENT_THINKING
configPI_AGENT_TIMEOUT_MS
configPI_PARSE_MODEL
configSITE_AGENT_PROVIDER
configSKF_API_BASE
🔐 secretSKF_API_KEYOptional: GOOGLE_GEMINI_API_KEY, , Stripe/CJ settings for integration paths copied from the private app
🔐 secretSTRIPE_SECRET_KEY
configZORO_CJ_ADVERTISER_ID
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/optimizedwf-bearingbrain-mcp-1egwzx)](https://m8ven.ai/mcp/optimizedwf-bearingbrain-mcp-1egwzx)
commit: 821fee15cce545a07de9714a4108cf3304441a14
code hash: 183ad59b5d81bf0d6f0ae138f9524da27080133a2b92bd791c570df359c633bc
verified: 6/1/2026, 1:17:27 PM
view raw JSON →