Liara MCP Server (razavioo/liara-mcp) is an MCP server listed on the M8ven Trust Index. It scores 54 out of 100, grade D. It declares 108 tools. No publisher has claimed this listing.
Enables AI assistants to deploy and manage applications, databases, object storage, VMs, DNS, and infrastructure on the Liara cloud platform through natural language commands.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
razavioo
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
liara_list_appsList all apps/projects in your Liara account
liara_get_appGet detailed information about a specific app
liara_create_appCreate a new app
liara_delete_appDelete an app
liara_start_appStart an app (scale up)
liara_stop_appStop an app (scale down)
liara_restart_appRestart an app
liara_resize_appChange app plan (resize resources)
liara_manage_appComprehensive app management: list apps, get details, create, delete, start, stop, restart, or resize apps
liara_manage_env_varsManage environment variables: list, set single/multiple, or delete single/multiple variables
liara_manage_databasesDatabase lifecycle management: list, get details, create, delete, start, stop, restart, or resize databases
liara_manage_database_backupsDatabase backup management: create, list, get download URL, restore, or delete backups
liara_manage_bucketsStorage bucket lifecycle management: list, get details, create, delete, or get credentials
liara_manage_bucket_objectsBucket object operations: list objects, upload, get download URL, or delete objects
liara_get_infrastructure_overviewGet a comprehensive overview of all Liara infrastructure: apps, databases, buckets, networks
liara_manage_deploymentDeployment management: list releases and sources
liara_list_databasesList all databases in your Liara account
liara_get_databaseGet details of a specific database
liara_get_database_connectionGet database connection information (host, port, credentials)
liara_update_databaseUpdate database settings such as plan (resize) or version. At least one of planID or version must be provided.
liara_create_databaseCreate a new database
liara_delete_databaseDelete a database
liara_start_databaseStart a database
liara_stop_databaseStop a database
liara_resize_databaseChange database plan (resize resources)
liara_create_backupCreate a database backup
liara_list_backupsList backups for a database
liara_get_backup_download_urlGet download URL for a database backup
liara_restart_databaseRestart a database
liara_restore_backupRestore a database from a backup
liara_delete_backupDelete a database backup
liara_upload_sourceUpload source code (.tar.gz file) for deployment
liara_deploy_releaseDeploy a release using a source ID
liara_list_releasesList all releases for an app
liara_get_releaseGet details of a specific release
liara_rollback_releaseRollback to a previous release
liara_list_sourcesList all uploaded sources for an app
liara_delete_sourceDelete an uploaded source
liara_list_disksList disks for an app
liara_create_diskCreate a new disk for an app
liara_delete_diskDelete a disk
liara_get_diskGet details of a specific disk
liara_resize_diskResize a disk
liara_create_ftp_accessCreate FTP access for a disk
liara_list_ftp_accessesList FTP accesses for a disk
liara_delete_ftp_accessDelete/revoke FTP access for a disk
liara_list_zonesList all DNS zones
liara_get_zoneGet details of a DNS zone
liara_create_zoneCreate a new DNS zone
liara_delete_zoneDelete a DNS zone
liara_list_dns_recordsList DNS records for a zone
liara_create_dns_recordCreate a DNS record
liara_get_dns_recordGet details of a DNS record
liara_update_dns_recordUpdate a DNS record
liara_delete_dns_recordDelete a DNS record
liara_list_domainsList all domains attached to apps
liara_get_domainGet details of a domain
liara_add_domainAdd a domain to an app
liara_remove_domainRemove a domain from an app
liara_set_env_varsSet or update environment variables for an app
liara_set_env_varSet a single environment variable for an app
liara_get_env_varsGet all environment variables for an app
liara_delete_env_varDelete/unset an environment variable for an app
liara_delete_env_varsDelete/unset multiple environment variables for an app
liara_list_mail_serversList all mail servers
liara_get_mail_serverGet details of a mail server
liara_create_mail_serverCreate a new mail server
liara_delete_mail_serverDelete a mail server
liara_send_emailSend an email via a mail server
liara_start_mail_serverStart a mail server
liara_stop_mail_serverStop a mail server
liara_restart_mail_serverRestart a mail server
liara_list_networksList all networks
liara_get_networkGet details of a network
liara_create_networkCreate a new network
liara_delete_networkDelete a network
liara_get_metricsGet app metrics summary
liara_get_logsGet app logs
liara_list_plansList available plans (apps, databases, or VMs)
liara_get_planGet details of a specific plan
liara_set_zero_downtimeEnable or disable zero-downtime deployment for an app
liara_set_default_subdomainEnable or disable default subdomain for an app
liara_set_fixed_ipEnable or disable static IP for an app (returns IP when enabling)
liara_set_read_onlyEnable or disable read-only mode for an app
liara_list_bucketsList all storage buckets
liara_get_bucketGet details of a specific bucket
liara_create_bucketCreate a new storage bucket
liara_delete_bucketDelete a storage bucket
liara_get_bucket_credentialsGet S3-compatible credentials for a bucket
liara_list_objectsList objects in a bucket
liara_upload_objectUpload an object to a bucket
liara_get_object_download_urlGet download URL for an object
liara_delete_objectDelete an object from a bucket
liara_get_userGet comprehensive user information including plans and teams
liara_list_vmsList all virtual machines
liara_get_vmGet details of a virtual machine
liara_create_vmCreate a new virtual machine
liara_start_vmStart a virtual machine
liara_stop_vmStop a virtual machine
liara_restart_vmRestart a virtual machine
8 further tools are not listed here. The complete surface is in the source.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
LIARA_API_BASE_URLLIARA_API_TOKENyour_api_token_hereLIARA_MCP_CONSOLIDATEDSet =true environment variable to enable consolidated tools. This mode provides fewer, more powerful tools that combine related functionality:LIARA_TEAM_IDoptional_team_idTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
108/108 tools missing one or more hints — liara_list_apps (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); liara_get_app (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); liara_create_app (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +105 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 0/108 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
2 calls in production code run through a shell (bin/setup.js:22, bin/setup.js:74)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 12 high severity in production deps — @modelcontextprotocol/sdk@0.5.0 (high), axios@1.13.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/razavioo/liara-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check