Geo MCP Server (rickycambrian/geo_mcp_server) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 44 tools. No publisher has claimed this listing.

D
Caution
58/100

Geo MCP Server

Enables building, querying, and publishing structured knowledge to the decentralized Geo knowledge graph using GRC-20, with tools for graph operations, DAO governance, and file ingestion.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

rickycambrian

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 2 credentials: GEO_PRIVATE_KEY, TEST_WALLET_PRIVATE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes44 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

generate_id

Generate one or more unique Geo knowledge graph IDs (dashless UUID v4)

build_schema

Build a complete schema (properties + types) in one call. Creates all properties first, then creates types that reference those properties by name.

create_knowledge_graph

Create a complete knowledge graph in one call: schema (properties + types), entities with values, and relations between entities. All name-based references are resolved automatically.

read_local_file

Read a local file from an allowed path. Useful for ingesting local research outputs, claim JSON, or markdown before publishing to Geo.

create_knowledge_graph_from_file

Read a local JSON file and create a complete knowledge graph in one call. Accepts either the raw create_knowledge_graph payload or one nested under payload/knowledgeGraph.

add_values_to_entity

Add multiple property values to an existing entity in one call.

create_research_paper_and_claims

Create a Research Paper entity and multiple Research Claim entities using the canonical Geo research schema. Claim entities are always multi-typed with the canonical GeoBrowser Claim type so they show up in standard Claim views.

create_research_ontology_paper_and_claims

Create a Paper entity and Claim entities using the GeoBrowser "Research ontology" (Paper/Claim/Person/Topic/Project). This path is designed for Knowledgebook/GeoBrowser UIs that expect claims to be typed as the canonical Claim type.

get_system_ids

Get well-known system entity IDs from the Geo knowledge graph. Returns commonly used type, property, and data type IDs.

vote_on_proposal

Cast a vote on a DAO proposal (YES, NO, or ABSTAIN)

propose_accept_editor

Propose adding a new editor to a DAO space

propose_remove_editor

Propose removing an editor from a DAO space

propose_accept_subspace

Propose accepting a subspace into a DAO space

propose_remove_subspace

Propose removing a subspace from a DAO space

create_property

Create a property definition in the knowledge graph

create_type

Create a type (schema) that groups properties

create_entity

Create an entity instance in the knowledge graph

create_relation

Create a relation between two entities

create_image

Create an image entity from a URL

update_entity

Update an existing entity

delete_entity

Delete an entity from the knowledge graph

delete_relation

Delete a relation from the knowledge graph

search_entities

Full-text search for entities in the Geo knowledge graph. Returns matching entities with basic metadata.

get_entity

Get full details of a single entity by ID, including values, relations, backlinks, and types.

list_entities

List entities with optional filters for space, type, and name. Supports pagination.

get_space

Get details of a single space by ID, including editor/member counts and recent proposals.

list_spaces

List spaces with optional type filter. Supports pagination.

get_type

Get details of a type definition by ID. Types are entities, so this returns the entity with its values and properties.

list_types

List type definitions in a specific space. Returns type entities with basic metadata.

get_proposals

List proposals for a specific space, ordered by creation time (newest first).

get_proposal

Get full details of a single proposal by ID, including vote breakdown.

get_proposal_votes

List votes for a specific proposal. Returns voter IDs, vote direction, and timestamps.

get_page_content

Get the ordered content blocks of a page entity. Returns text (Markdown) and image blocks in position order.

configure_wallet

Configure wallet to enable write operations. Use walletMode=APPROVAL with walletAddress for transaction-return mode (no private key needed). Without any config, the server runs in read-only mode.

setup_space

Ensure personal space exists and get space ID. Requires configured wallet.

publish_edit

Publish all accumulated ops as an edit to personal space

propose_dao_edit

Propose accumulated ops as a DAO edit

upsert_canvas_workflow

Create/update a canvas workflow entity and publish privately or via DAO proposal

submit_signed_transaction

Submit a signed transaction hash for a pending approval-mode transaction. Handles continuations (auto-vote, auto-execute) automatically.

get_session_status

Get current session state

clear_session

Clear all accumulated ops

resolve_workspace_entities

Resolve workspace entities by kind and optional name search.

upsert_workspace_entity

Create/update a workspace note/task/project and publish privately or as a DAO proposal.

delete_workspace_entity

Delete a workspace entity and publish the change privately or as a DAO proposal.

// known CVEs in dependencies1 critical3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@4.0.18GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

high@modelcontextprotocol/sdk@1.12.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configGEO_CANONICAL_CLAIM_TYPE_ID
configGEO_GRAPHQL_URLoptionally overrides the GraphQL API endpoint (default: https://testnet-api.geobrowser.io/graphql).
configGEO_MCP_ALLOWED_PATHS"": "/Users/me/Documents/research,/tmp"
🔐 secretGEO_PRIVATE_KEY"": "0x...",
configPK
🔐 secretTEST_WALLET_PRIVATE_KEY
// quality suggestions

All four hints declared on every tool

44/44 tools missing one or more hints — generate_id (missing: destructiveHint, idempotentHint, openWorldHint); build_schema (missing: destructiveHint, idempotentHint, openWorldHint); create_knowledge_graph (missing: destructiveHint, idempotentHint, openWorldHint), +41 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

37/44 tool handlers declare input schemas (84%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

39/44 tool handlers wrap calls in try/catch (89%)

Wrap each tool handler body in try/catch and return a structured error response.

Shell command execution

1 child_process call — runs shell commands

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Dev dependencies

1 critical/high in dev-only deps (does not ship to users)

Upgrade dev dependencies when convenient.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/rickycambrian/geo_mcp_server?variant=verified)](https://m8ven.ai/mcp/rickycambrian/geo_mcp_server)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 32d00e664c902eeb58d7bb328b84f1722c61f0eb
code hash: e1d52e15cc6b208cd5ba725a7725b9334db11d638867e344935d5c7102572a8f
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client