sugar (roboticforce/sugar) is an MCP server listed on the M8ven Trust Index. It scores 69 out of 100, grade C. It declares 30 tools. No publisher has claimed this listing.

C
Caution
69/100

sugar

Persistent memory for AI coding agents. Local-first, cross-session context, global knowledge, and optional autonomous task execution.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

roboticforce

Source: PulseMCP · also listed on github_topic, Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Tool descriptions don’t match what handlers do
3 tools describe read intent but their handlers mutate — listTasks (line 39: spawn(command, args, {); viewTask (line 39: spawn(command, args, {); getStatus (line 39: spawn(command, args, {)
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 3 credentials: ANTHROPIC_API_KEY, GITHUB_TOKEN, OPENCODE_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes29 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

createTask

Create a new Sugar task for autonomous development

listTasks

List Sugar tasks with optional filtering

viewTask

View detailed information about a specific task

updateTask

Update an existing Sugar task

removeTask

Remove a task from the queue

getStatus

Get Sugar system status and task queue metrics

runOnce

Execute one autonomous development cycle (picks up highest priority task)

initSugar

Initialize Sugar in the current project directory

analyze_issue

Analyze a GitHub issue and return insights

generate_response

Generate a response for a GitHub issue

search_codebase

Search the codebase for relevant code

find_similar_issues

Find issues similar to a given issue

suggest_labels

Suggest labels for an issue based on its content

validate_response

Validate a response before posting

search_memory

Search Sugar memory for relevant context.

store_learning

Store a new learning, decision, or observation in Sugar memory.

get_project_context

Get current project context summary from Sugar memory.

recall

Get memories about a specific topic, formatted as readable context.

list_recent_memories

List recent memories from both project and global stores, optionally filtered by type.

sugar_add_task

Add a new task to the Sugar work queue for autonomous execution.

sugar_list_tasks

List tasks in the Sugar work queue with optional filtering.

sugar_view_task

Get detailed information about a specific task.

sugar_update_task

Update properties of an existing task.

sugar_task_status

Get queue statistics and system health information.

sugar_remove_task

Remove a task from the work queue.

sugar_quality_gate_check

Run quality gate checks

sugar_learning_query

Query the learning system

spawn_subagent

Spawn a single sub-agent to execute a task.

spawn_parallel_subagents

Spawn multiple sub-agents to execute tasks in parallel.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configSUGAR_DEBUG
configSUGAR_PROJECT_ROOT
configSUGAR_MODEL
🔐 secretANTHROPIC_API_KEY
🔐 secretGITHUB_TOKEN
configSUGAR_DEFAULT_REPO
configOPENCODE_CONFIG
configOPENCODE_CONFIG_DIR
configGITHUB_EVENT_PATH
configGITHUB_OUTPUT
configGITHUB_REPOSITORY
configSUGAR_PROJECT_DIR
configSUGAR_SYNC_TURNS
configSUGAR_SEARCH_LIMIT
configOPENCODE_SERVER_URL
🔐 secretOPENCODE_API_KEY
configOPENCODE_TIMEOUT
configSUGAR_OPENCODE_ENABLED
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

30/30 tools missing one or more hints — createTask (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); listTasks (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); viewTask (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +27 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Descriptions match behaviour

3 tools describe read intent but their handlers mutate — listTasks (line 39: spawn(command, args, {); viewTask (line 39: spawn(command, args, {); getStatus (line 39: spawn(command, args, {)

Rename the tool, rewrite the description, or move the side-effect into a separate clearly-named tool.

Tool inputs are validated

23/24 tool handlers declare input schemas (96%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool test coverage

23/30 tools referenced in tests (77%)

Write tests that reference each tool by name so every tool has at least one test.

Tool description accuracy

3 tools have description/behavior mismatches: listTasks: description implies read-only but handler writes/deletes/executes; viewTask: description implies read-only but handler writes/deletes/executes; getStatus: description implies read-only but handler writes/deletes/executes

Update tool descriptions to accurately reflect all capabilities — especially write, delete, or execute operations.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/roboticforce/sugar?variant=verified)](https://m8ven.ai/mcp/roboticforce/sugar)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: eade16940789bc1f927af090f8a3b475e537eddd
code hash: 2af009c0d10a77e34dcabb100e3cbcb532e0841569e9da0c209b471ae2474cc2
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client