losbeto (rmartins1451/losbeto) is an MCP server listed on the M8ven Trust Index. It scores 48 out of 100, grade D. No publisher has claimed this listing.

D
Caution
48/100

losbeto

Provides point-in-time Brazilian market data and official statistics, enabling accurate backtesting and AI agent access to vintage, unrevised data, as well as Brazilian financial primitives like PIX code generation and business day calculations.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

rmartins1451

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
22 flows detected: GEMINI_API_KEY, GROQ_API_KEY, DEEPSEEK_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 24 credentials: DASH_TOKEN, PARTNER_KEY, JWT_SECRET, HELIUS_API_KEY, CDP_API_KEY_SECRET, TON_API_KEY, GROQ_API_KEY, GEMINI_API_KEY, FINNHUB_API_KEY, TWELVEDATA_API_KEY, ALPHAVANTAGE_API_KEY, SERPER_API_KEY, DEEPSEEK_API_KEY, CLAUDE_API_KEY, ANTHROPIC_API_KEY, JUPITER_API_KEY, COINGECKO_API_KEY, TWITTER_API_KEY, TWITTER_API_SECRET, TWITTER_ACCESS_TOKEN, TWITTER_ACCESS_TOKEN_SECRET, TELEGRAM_BOT_TOKEN, X402LIST_TOKEN, BASE_OPERATOR_PRIVATE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configDATA_DIR
configOMEGA_X402_PORT
configOMEGA_GOSSIP_PORT
configOMEGA_MCAST_PORT
configFLY_APP_NAME
configPUBLIC_URL
🔐 secretDASH_TOKEN
🔐 secretPARTNER_KEY
🔐 secretJWT_SECRET
configJWT_TTL_SECONDS
configSOLANA_RPC
🔐 secretHELIUS_API_KEY
configBASE_RPC
configBASE_PAYTO_EVM
configPREFER_BASE
configALGORAND_WALLET_ADDRESS
configGOPLAUSIBLE_FACILITATOR
configOPERATOR_WALLETS
configCDP_API_KEY_ID
🔐 secretCDP_API_KEY_SECRET
configX402_FACILITATOR
🔐 secretTON_API_KEY
🔐 secretGROQ_API_KEY
🔐 secretGEMINI_API_KEY
🔐 secretFINNHUB_API_KEY
🔐 secretTWELVEDATA_API_KEY
🔐 secretALPHAVANTAGE_API_KEY
🔐 secretSERPER_API_KEY
🔐 secretDEEPSEEK_API_KEY
🔐 secretCLAUDE_API_KEY
🔐 secretANTHROPIC_API_KEY
configOLLAMA_URL
configOLLAMA_ENABLED
configOLLAMA_MODEL
configLLM_FORCE_ENGLISH
configCDP_SEND_RESOURCE
configCDP_FALLBACK_PAYAI
configMPP_CHALLENGE
configUCP_PROFILE
🔐 secretJUPITER_API_KEY
🔐 secretCOINGECKO_API_KEY
🔐 secretTWITTER_API_KEY
🔐 secretTWITTER_API_SECRET
🔐 secretTWITTER_ACCESS_TOKEN
🔐 secretTWITTER_ACCESS_TOKEN_SECRET
🔐 secretTELEGRAM_BOT_TOKEN
configTELEGRAM_CHAT_ID
configBINANCE_SOLANA_ADDRESS
configBINANCE_WALLET_ADDRESS
configSWEEP_THRESHOLD_USDC
configSWEEP_INTERVAL_S
configOMEGA_SEEDS
configDYNAMIC_PRICING
configPREDICTIVE_PRICING
configGEOIP_ENABLED
configGEO_BLOCKED
configREVENUE_TARGET_DAILY
configSOLANA_WALLET_ADDRESS
configRECEIVE_ADDRESS
configWALLET_SECRET_B58
configTON_MNEMONIC
configFAC_VERIFY_TIMEOUT
configFAC_SETTLE_TIMEOUT
configCDP_BREAKER_THRESHOLD
configCDP_BREAKER_COOLDOWN
configDEEPSEEK_MODEL
configCLAUDE_MODEL
configGROQ_MODEL
configGEMINI_MODEL
configLLM_CACHE_TTL
configLLM_COOLDOWN
configLLM_BILLING_COOLDOWN
configLLM_DAILY_COOLDOWN
configGEMINI_DISCOVERY_TTL
configGROQ_DISCOVERY_TTL
configLLM_SMALL_TOKENS
configLLM_ORDER
configBASE_RPC_URL
configOMEGA_QUIET
configOMEGA_RL_RPM
configOMEGA_RL_RPM_WALLET
configINLINE_SAMPLE_MAX_CHARS
configSERVICE_NAME
configCHALLENGE_TTL
configUPSELL_WINDOW
configSVM_FEE_PAYER_OVERRIDE
configPREVIEW_MAX_AGE_SECS
configPREVIEW_MIN_AGE_SECS
configFEEDBACK_SLACK
configCONTACT_EMAIL
configPREVIEW_GEN_COOLDOWN
configWELCOME_FREE_CALL
configWELCOME_DAILY_CAP
configWELCOME_TTL_S
configPROMO_FIRST_BUYER_FRACTION
configPROMO_MIN_402_VIEWS
configYAHOO_SERIES_TTL
configYAHOO_FAIL_LIMIT
configYAHOO_COOLDOWN
configAI_PROBE_TTL
🔐 secretX402LIST_TOKENUseful env vars: AI_WARMER=1, LLM_DAILY_GLOBAL_CAP, LLM_DAILY_KEY_CAP, PIT_INTERVAL_S, ALGO_ANCHOR_MNEMONIC, .
configMCP_LEGACY_TOOLS
configLLM_DAILY_GLOBAL_CAPUseful env vars: AI_WARMER=1, , LLM_DAILY_KEY_CAP, PIT_INTERVAL_S, ALGO_ANCHOR_MNEMONIC, X402LIST_TOKEN.
configLLM_DAILY_KEY_CAPUseful env vars: AI_WARMER=1, LLM_DAILY_GLOBAL_CAP, , PIT_INTERVAL_S, ALGO_ANCHOR_MNEMONIC, X402LIST_TOKEN.
configLLM_FREE_PER_DAY
configLLM_FREE_GLOBAL_PER_DAY
configDEMAND_ALERT_IPS
configCDP_API_BASE
configCHAT_RETENTION_DAYS
configCHAT_RATE_MAX
configERC8004_AGENT_ID
configSPEC_CACHE_TTL
configAUTOPILOT_WARM_SECS
configAUTOPILOT_WARM_AI_SECS
configAI_WARMERUseful env vars: =1, LLM_DAILY_GLOBAL_CAP, LLM_DAILY_KEY_CAP, PIT_INTERVAL_S, ALGO_ANCHOR_MNEMONIC, X402LIST_TOKEN.
configACP_AGENT_ID
configACP_SELLER
configGUNICORN_WORKERS
configGUNICORN_THREADS
configPROOF_OF_REVENUE
🔐 secretBASE_OPERATOR_PRIVATE_KEY
configDISCOVERY_PING
configBUYER_WALLETS
configSWEEP_MIN_ENDPOINTS
configSWEEP_WINDOW_S
configFUNNEL_REF_TS
configSAMPLE_STALE_S
configLLM_DAILY_BUDGET
configLLM_PAID_RESERVE
configPIT_INTERVAL_SUseful env vars: AI_WARMER=1, LLM_DAILY_GLOBAL_CAP, LLM_DAILY_KEY_CAP, , ALGO_ANCHOR_MNEMONIC, X402LIST_TOKEN.
configPRICE_BR_ASOF
configPRICE_BR_REVISIONS
configALGO_ANCHOR_MNEMONICUseful env vars: AI_WARMER=1, LLM_DAILY_GLOBAL_CAP, LLM_DAILY_KEY_CAP, PIT_INTERVAL_S, , X402LIST_TOKEN.
configALGOD_URL
configAUTOPILOT
configSCORECARD_TTL
configCHALLENGE_CACHE_TTL
configPRICE_BR_MACRO_SNAPSHOT
configRADAR_AUTO_IPS
configRADAR_MAX_ALIASES
configANVITA_VERIFICATION
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tools detected

No tools extracted — insufficient content to verify at Tier 2

Tests exist

No test files found

Add tests that exercise each declared tool.

Secrets stay with their owner

2 secret/sensitive values flow into network calls (GEMINI_API_KEY → https://generativelanguage.googleapis.com/v1beta/models, GEMINI_API_KEY → https://generativelanguage.googleapis.com/v1beta/models/) (18 other flows matched canonical API hosts)

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Secrets not logged

1 secret value sent to log.info

Redact or omit secret values from log output.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/rmartins1451/losbeto?variant=verified)](https://m8ven.ai/mcp/rmartins1451/losbeto)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 70920ad680d1a0d0937e2642fd1e9c3c2b075295
code hash: 84e59dc45353cf4a819b59cc15ed22c09727bb10bb240e78905907d4b5af13d4
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client