73
/ 100
9 hours ago
glama

tar-engine

Audits AI agent skills for safety using static, semantic, adversarial, and supply-chain analysis, providing scores and risk flags. Can be run via CLI, CI, or as an MCP tool from Claude Code, Cursor, and Codex.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 6 credentials: TAR_ENGINE_BYOK_OPENAI_KEY, OPENAI_API_KEY, ANTHROPIC_API_KEY, COCKPIT_TELEGRAM_LLM_API_KEY, COCKPIT_TELEGRAM_BOT_TOKEN, COCKPIT_RAG_EMBED_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configLOG_LEVEL
configPORT
configTAR_ENGINE_URL[self-host](#self-host) and set =http://localhost:8765.
configTAR_ENGINE_TIMEOUT
🔐 secretTAR_ENGINE_BYOK_OPENAI_KEYexplicit opt-in via in the MCP server
configTAR_ENGINE_BYOK_OPENAI_BASE_URL
configTAR_ENGINE_BYOK_OPENAI_MODEL
🔐 secretOPENAI_API_KEY. Semantic + adversarial audit layers require an
configENGINE_HOME
🔐 secretANTHROPIC_API_KEY
configOPENAI_BASE_URL
configOPENAI_MODEL_NAME
configOPENCLAW_SKILLS_PATH
configCLAUDE_SKILLS_PATH
configCOCKPIT_PACKS_DIR
configCOCKPIT_SKILLS_DIR
configTAR_ENGINE_COMMIT_SHA
configOPENAI_MODEL
configCOCKPIT_WORKSPACE_DIR
configCOCKPIT_DB
configCOCKPIT_TELEGRAM_ALLOWED_USERS
configCOCKPIT_TELEGRAM_LLM_BASE_URL
🔐 secretCOCKPIT_TELEGRAM_LLM_API_KEY
configCOCKPIT_TELEGRAM_LLM_MODEL
🔐 secretCOCKPIT_TELEGRAM_BOT_TOKEN
configCOCKPIT_PRICING
configCOCKPIT_MAX_TOKENS_PER_WISH
configCOCKPIT_MAX_COST_PER_WISH
configCOCKPIT_MAX_TOKENS_PER_DAY
configCOCKPIT_MAX_COST_PER_DAY
configL3_INGEST_PRIMARY_PATH
configL3_INGEST_TRANSCRIPTS_PATH
configL3_INGEST_EXPERIMENT_BLOCKLIST
configCOCKPIT_RAG_EMBED_BASE_URL
🔐 secretCOCKPIT_RAG_EMBED_API_KEY
configCOCKPIT_RAG_EMBED_MODEL
configCOCKPIT_RAG_INDEX_DIR
configCOCKPIT_RAG_TOP_K
configCOCKPIT_RAG_SIMILARITY_CUTOFF
configCOCKPIT_RAG_ENABLED
configCOCKPIT_RAG_SOURCES
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/qingxuantang-tar-engine-1v1c9x)](https://m8ven.ai/mcp/qingxuantang-tar-engine-1v1c9x)
commit: 1f86ea45bba9cb8dc7eb1ecdca4b4b1bee291963
code hash: 40fb87e0d587723aac9589dd24aca7ac9a0a8ef818fb67d3b18a16c8740413d0
verified: 7/31/2026, 9:12:14 AM
view raw JSON →