photon (portel-dev/photon) is an MCP server listed on the M8ven Trust Index. It scores 85 out of 100, grade B. It declares 1 tool. No publisher has claimed this listing.
Define intent once. Photon turns a single TypeScript file into CLI tools, MCP servers, and web interfaces.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
portel-dev
Source: Glama · also listed on github_topic
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
ws: Memory exhaustion DoS from tiny fragments and data chunks
esbuild allows arbitrary file read when running the development server on Windows
ws: Uninitialized memory disclosure
BEAM_BIND_ADDRESSBEAM_PORTCLOUDFLARE_API_TOKENDOCS_HOSTNAMEGITHUB_TOKENPHOTON_A2A_AUTHPHOTON_ALLOW_HTTP_MARKETPLACEPHOTON_BASES_REGISTRYPHOTON_DAEMON_DISABLE_EAGER_LOADPHOTON_DAEMON_IDLE_TIMEOUT_MSPHOTON_DAEMON_READY_TIMEOUT_MSPHOTON_DAEMON_WATCHDOG_PIDPHOTON_DEBUG_EMITPHOTON_DEBUG_EVENTSPHOTON_DEBUG_EXTRACTPHOTON_DIRphoton ps --base ~/Projects/kith # filter to onePHOTON_EVENT_LOG_MAX_SIZEPHOTON_HOMEPHOTON_HOT_RELOAD_DEBOUNCE_MSPHOTON_INSTANCE_ALIASESPHOTON_LIGHT_DAEMONPHOTON_MAX_SSE_SESSIONS_PER_CLIENTPHOTON_MCP_AUTHORIZATION_SERVERPHOTON_MCP_AUTH_MODEPHOTON_MCP_BEARERPHOTON_MCP_JWT_AUDIENCEPHOTON_MCP_JWT_ISSUERPHOTON_MCP_JWT_JWKSPHOTON_MCP_JWT_PROFILEPHOTON_MCP_MAX_SUBSCRIPTIONSPHOTON_MCP_MAX_SUBSCRIPTIONS_PER_PRINCIPALPHOTON_MCP_RATE_LIMITPHOTON_MCP_RATE_WINDOW_MSPHOTON_MCP_RESOURCE_METADATA_URLPHOTON_NAMEPHOTON_PUBLIC_URLPHOTON_SCHEDULES_DIRPHOTON_SESSION_IDPHOTON_STALE_CHECK_INTERVAL_MSPHOTON_TRANSPORTPHOTON_WEBHOOK_ALLOWED_IPSPHOTON_WEBHOOK_ALLOW_UNAUTHENTICATEDPHOTON_WEBHOOK_PORTPHOTON_WEBHOOK_RATE_LIMITPHOTON_WEBHOOK_RATE_WINDOW_MSPHOTON_WEBHOOK_SECRETSHELLDependencies
50 dependencies, 2 flagged: @playwright/test, playwright
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
1/1 tools missing one or more hints — setup (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
No eval / new Function
1 eval() or new Function() call — dynamic code execution
Replace eval / Function with explicit parsing or safer alternatives.
Shell command execution
37 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 1 high severity in production deps — ws@8.18.0 (high), esbuild@0.28.0 (low)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
4/20 production deps abandoned (no release in 2+ years): fast-json-patch@2022-06-17 (4.1y), cli-highlight@2023-04-12 (3.3y), cli-table3@2024-05-12 (2.2y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/portel-dev/photon)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check