safe-audit-fix (pasindudilshan1/safe-audit-fix) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 4 tools. The publisher has proved control of what we score (Verified Publisher). It is connected through the M8ven GitHub App, so the listing is re-checked on every push.

B
Emerging
89/100
6 days ago

safe-audit-fix

MCP server that safely fixes npm audit vulnerabilities by planning, applying fixes one at a time, running tests after each, and auto-reverting failures to prevent breaking changes.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored

Monitored 18 days · every push re-verified

Who stands behind it

gmail.com (@pasindudilshan1) · Verified Publisher

Source: Glama

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
4 tools verified — handlers match their declared behaviour
2 read-only tools verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
Are you the publisher? Confirm or correct these findings.
// quality suggestions

Shell command execution

2 calls in production code run through a shell (src/engine/exec.js:34, src/engine/exec.js:49)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/pasindudilshan1/safe-audit-fix)](https://m8ven.ai/mcp/pasindudilshan1/safe-audit-fix)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: e226784d8221a75c14cd11b0ab12a6153f58810b
code hash: 99fd6214e22acab02b1e275f9f98ee5092842f692fe3814730dd04666291445e
verified: 9/4/2026, 4:53:59 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client