Universal-MCP-Ecosystem (robertsn808/Universal-MCP-Ecosystem) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 477 tools. No publisher has claimed this listing.
Model Context Protocol
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
robertsn808
Source: github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
aws_queryQuery AWS services and resources
database_queryExecute database queries across all applications
process_paymentProcess payments through UPP
trigger_workflowTrigger N8N automation workflows
generate_reportGenerate business analytics reports
dynamodb_data_modelingRetrieves the complete DynamoDB Data Modeling Expert prompt.
put_resource_policyAttaches a resource-based policy document (max 20 KB) to a DynamoDB table or stream. You can control permissions for both tables and their indexes through the policy.
get_resource_policyReturns the resource-based policy document attached to a DynamoDB table or stream in JSON format.
scanReturns items and attributes by scanning a table or secondary index. Reads up to Limit items or 1 MB of data, with optional FilterExpression to reduce results.
queryReturns items from a table or index matching a partition key value, with optional sort key filtering.
update_itemEdits an existing item's attributes, or adds a new item to the table if it does not already exist.
get_itemReturns attributes for an item with the given primary key. Uses eventually consistent reads by default, or set ConsistentRead=true for strongly consistent reads.
put_itemCreates a new item or replaces an existing item in a table. Use condition expressions to control whether to create new items or update existing ones.
delete_itemDeletes a single item in a table by primary key. You can perform a conditional delete operation that deletes the item if it exists, or if it has an expected attribute value.
update_time_to_liveEnables or disables Time to Live (TTL) for the specified table. Note: The epoch time format is the number of seconds elapsed since 12:00:00 AM January 1, 1970 UTC.
update_tableModifies table settings including provisioned throughput, global secondary indexes, and DynamoDB Streams configuration. This is an asynchronous operation.
list_tablesReturns a paginated list of table names in your account.
create_tableCreates a new DynamoDB table with optional secondary indexes. This is an asynchronous operation.
describe_tableReturns table information including status, creation time, key schema and indexes.
create_backupCreates a backup of a DynamoDB table.
describe_backupDescribes an existing backup of a table.
list_backupsReturns a list of table backups.
restore_table_from_backupCreates a new table from a backup.
describe_limitsReturns the current provisioned-capacity quotas for your AWS account and tables in a Region.
describe_time_to_liveReturns the Time to Live (TTL) settings for a table.
describe_endpointsReturns DynamoDB endpoints for the current region.
describe_exportReturns information about a table export.
list_exportsReturns a list of table exports.
describe_continuous_backupsReturns continuous backup and point in time recovery status for a table.
untag_resourceRemoves tags from a DynamoDB resource.
tag_resourceAdds tags to a DynamoDB resource.
list_tags_of_resourceReturns tags for a DynamoDB resource.
delete_tableThe DeleteTable operation deletes a table and all of its items. This is an asynchronous operation that puts the table into DELETING state until DynamoDB completes the deletion.
update_continuous_backupsEnables or disables point in time recovery for the specified table.
list_importsLists imports completed within the past 90 days.
lambda_functionTool for invoking a specific AWS Lambda function with parameters.
run_queryRun a SQL query using boto3 execute_statement
get_table_schemaFetch table columns and comments from Postgres using RDS Data API
KendraListIndexesToolList all Amazon Kendra indexes in the specified region.
KendraQueryToolQuery Amazon Kendra and retrieve content from the response.
listKeyspacesLists all keyspaces in the Cassandra/Keyspaces database - args: none
listTablesLists all tables in a specified keyspace - args: keyspace
describeKeyspaceGets detailed information about a keyspace - args: keyspace
describeTableGets detailed information about a table - args: keyspace, table
executeQueryExecutes a read-only SELECT query against the database - args: keyspace, query
analyzeQueryPerformanceAnalyzes the performance characteristics of a CQL query - args: keyspace, query
create_brokerCreate a ActiveMQ or RabbitMQ broker on AmazonMQ.
create_configurationCreate configuration for AmazonMQ broker.
get_graph_statusGet the status of the currently configured Amazon Neptune graph.
get_graph_schemaGet the schema for the graph including the vertex and edge labels as well as the (vertex)-[edge]->(vertex) combinations.
run_opencypher_queryExecutes the provided openCypher against the graph.
run_gremlin_queryExecutes the provided Tinkerpop Gremlin against the graph.
QBusinessQueryToolMCP tool to query Amazon Q Business and return a formatted response.
AuthorizeQIndexGenerate the OIDC authorization URL for Q index authentication.
CreateTokenWithIAMGet a token using the authorization code through IAM.
AssumeRoleWithIdentityContextAssume an IAM role using the identity context from the token.
SearchRelevantContentSearch for relevant content in an Amazon Q Business application.
list_collectionsReturns a list of collection IDs in your AWS account.
index_facesDetects faces in an image and adds them to the specified collection.
search_faces_by_imageSearches for faces in a collection that match a face in the supplied image.
detect_labelsDetects objects, scenes, concepts, and activities in an image.
detect_moderation_labelsDetects unsafe or inappropriate content in an image.
recognize_celebritiesRecognizes celebrities in an image.
compare_facesCompares a face in the source image with faces in the target image.
detect_textDetects text in an image.
readonly_queryRun a read-only SQL query against the configured Aurora DSQL cluster. Aurora DSQL is distributed SQL database with Postgres compatibility. The following table summarizes `SELECT` functionality that is expected to work. Items not in this table may also be supported, as this is a point in time snapsh…
transactWrite or modify data using SQL, in a transaction against the configured Aurora DSQL cluster. Aurora DSQL is a distributed SQL database with Postgres compatibility. This tool will automatically insert `BEGIN` and `COMMIT` statements; you only need to provide the statements to run within the transact…
get_schemaGet the schema of the given table
call_awsCall AWS with the given CLI command and return the result as a dictionary.
getprojectsGet a list of data automation projects.
getprojectdetailsGet details of a data automation project.
analyzeassetAnalyze an asset using a data automation project.
generate_diagramget_diagram_examplesGet example code for different types of diagrams.
list_iconsList available icons from the diagrams package, with optional filtering.
list_workflowsList available HealthOmics workflows.
create_workflowCreate a new HealthOmics workflow.
get_workflowGet details about a specific workflow.
create_workflow_versionCreate a new version of an existing workflow.
list_workflow_versionsList versions of a workflow.
start_runlist_runsList workflow runs.
get_runGet details about a specific run.
list_run_tasksList tasks for a specific run.
get_run_taskGet details about a specific task.
get_run_logsRetrieve high-level run logs that show workflow execution events.
get_run_manifest_logsRetrieve run manifest logs produced when a workflow completes or fails.
get_run_engine_logsRetrieve engine logs containing STDOUT and STDERR from the workflow engine process.
get_task_logsRetrieve logs for a specific workflow task containing STDOUT and STDERR.
analyze_run_performanceAnalyze AWS HealthOmics workflow run performance and provide optimization recommendations.
diagnose_run_failureProvides comprehensive diagnostic information for a failed workflow run.
package_workflowPackage workflow definition files into a base64-encoded ZIP.
get_supported_regionsGet the list of AWS regions where HealthOmics is available.
search_placesSearch for places using Amazon Location Service geo-places search_text API. Geocode the query using the geocode API to get BiasPosition. If no results, try a bounding box filter. Includes contact info and opening hours if present. Output is standardized and includes all fields, even if empty or not …
get_placeGet details for a place using Amazon Location Service geo-places get_place API. Output is standardized and includes all fields, even if empty or not available.
reverse_geocodeReverse geocode coordinates to an address using Amazon Location Service geo-places reverse_geocode API.
search_nearbySearch for places near a location using Amazon Location Service geo-places search_nearby API. If no results, expand the radius up to max_radius. Output is standardized and includes all fields, even if empty or not available.
search_places_open_nowSearch for places that are open now using Amazon Location Service geo-places search_text API and filter by opening hours. If no open places, expand the search radius up to max_radius. Uses BiasPosition from geocode.
calculate_routeCalculate a route and return summary info and turn-by-turn directions.
optimize_waypointsOptimize the order of waypoints using Amazon Location Service geo-routes optimize_waypoints API (V2).
320 further tools are not listed here. The complete surface is in the source.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
CORS_ORIGINSENABLE_ANALYTICSENABLE_AUTOMATIONENABLE_AWS_INTEGRATIONENABLE_PAYMENT_PROCESSINGLOG_LEVELAWS_REGIONAWS_PROFILEFUNCTION_PREFIXFUNCTION_LISTFUNCTION_TAG_KEYFUNCTION_TAG_VALUEFUNCTION_INPUT_SCHEMA_ARN_TAG_KEYKENDRA_INDEX_IDNEPTUNE_ENDPOINTNEPTUNE_USE_HTTPSFASTMCP_LOG_LEVELAWS_DOCUMENTATION_PARTITIONAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYAWS_SESSION_TOKENAWS_EXECUTION_ENVKB_INCLUSION_TAG_KEYBEDROCK_KB_RERANKING_ENABLEDMCP_CLOUDWATCH_APPSIGNALS_LOG_LEVELGITHUB_TOKENPROMETHEUS_URLLOG_FILEPYTEST_CURRENT_TESTMCP_SERVER_DISABLE_LOGGINGSTATE_MACHINE_PREFIXSTATE_MACHINE_LISTSTATE_MACHINE_TAG_KEYSTATE_MACHINE_TAG_VALUESTATE_MACHINE_INPUT_SCHEMA_ARN_TAG_KEYFASTMCP_LOG_FILEPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
477/477 tools missing one or more hints — aws_query (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); database_query (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); process_payment (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +474 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Secrets not logged
9 secret values sent to logger.info
Redact or omit secret values from log output.
Production dependencies are patched
0 critical, 16 high severity in production deps — @modelcontextprotocol/sdk@1.17.3 (high), @modelcontextprotocol/sdk@1.17.3 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/robertsn808/universal-mcp-ecosystem)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check