willow-mcp (rudi193-cmd/willow-mcp) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: there is no public source to read and no endpoint we can reach, so there is nothing for us to inspect. No publisher has claimed this listing.

C
Limited view
71/100
1 month ago

willow-mcp

An agent-neutral MCP server providing SQLite key/value storage, Postgres knowledge base, and Kart task queue functionality. Features SAP/1.0 authorization on every tool call for secure multi-application access.

Limited view. Automated analysis covers part of this stack. Findings reflect what we verified. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

Limited view: static analysis for Python is partially covered.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

rudi193-cmd

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: WILLOW_MCP_EGRESS_PUBLIC_KEY, WILLOW_MCP_EGRESS_SIGNING_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configWILLOW_MCP_ANNOUNCE
configWILLOW_MCP_AUDIT_LEVEL
configWILLOW_SETTINGS_GLOBAL
configWILLOW_PG_DBPoint / WILLOW_STORE_ROOT at your host fleet store when you
configWILLOW_PG_USER$USER Postgres user (Unix socket auth)
configWILLOW_PROJECT_ROOT
configWILLOW_HANDOFF_PROJECT
configWILLOW_IN_KART
🔐 secretWILLOW_MCP_EGRESS_PUBLIC_KEYset to an operator-owned Ed25519 public PEM that
configWILLOW_ENVELOPE_REGISTRY
configWILLOW_SYSCALL_TABLE
configWILLOW_FLEET_ROSTER
configWILLOW_HOMEwillow-mcp-init # scaffold $ (idempotent)
configWILLOW_MCP_APPS_ROOT
configWILLOW_APP_IDwillow-mcp Default app_id if not passed per-call
configWILLOW_MCP_ENFORCE_BINDING
configWILLOW_WORKER_HEARTBEAT_ROOT$WILLOW_HOME/worker_heartbeat Explicit worker heartbeat directory
configWILLOW_HUMAN_ORCHESTRATOR
configWILLOW_MCP_STRICT_TRUST_ROOTand enable =1. The matching private key must remain
configNEST_EMBED_MARGIN
configNEST_EMBED_MARGIN_FLOOR
configNEST_MIN_DATE_YEAR
configOLLAMA_HOST
configNEST_EMBED_MODEL
configNEST_EMBED_TIMEOUT
configNEST_TEXT_MODEL
configNEST_VISION_MODEL
configNEST_LLM_TIMEOUT
configWILLOW_NEST_RULES
configNEST_LEARN_MIN_MARGIN
configNEST_LEARN_MAX_PER_CAT
configNEST_PROMOTE_MIN_SIZE
configNEST_PROMOTE_MAX_MARGIN
configNEST_PROMOTE_MIN_COHESION
configNEST_PROMOTE_MAX_NEW
configNEST_CACHE_DIR
configWILLOW_MCP_FLEET_HOME(unset) The fleet home this install claims to be severed from. Unset = no claim. See [Severance](#severance)
configWILLOW_MCP_FLEET_PG_DB(unset) The fleet database this install claims to be severed from
configWILLOW_STORE_ROOTan Ed25519 private key outside WILLOW_HOME/; no MCP tool or
configWILLOW_PGP_FINGERPRINT
configWILLOW_MCP_RECEIPT_DB
configWILLOW_MCP_SCHEMA_RINGS
configWILLOW_MCP_SCHEMA_RINGS_MAX
configWILLOW_MCP_PORTport/--host take precedence over /WILLOW_MCP_HOST,
configWILLOW_MCP_HOSTport/--host take precedence over WILLOW_MCP_PORT/,
configWILLOW_MCP_URL(derived) Public base URL for OAuth issuer/callbacks in serve mode
🔐 secretWILLOW_MCP_EGRESS_SIGNING_KEY
configWILLOW_MCP_GROVE_RINGS
configXDG_CONFIG_HOME
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

78/78 tools missing one or more hints — store_put (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); store_get (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); store_list (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +75 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool handlers catch errors

Only 18/78 tool handlers wrap calls in try/catch (23%)

Wrap each tool handler body in try/catch and return a structured error response.

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/rudi193-cmd-willow-mcp-49xi67)](https://m8ven.ai/mcp/rudi193-cmd-willow-mcp-49xi67)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: b9c075d98d8a70d8651174393e421b4807e5dfe2
code hash: ce6bb1e0fbe5f7529dac7c21e46889d9c52bb94291e34a79ecdc796615e2393f
verified: 7/19/2026, 8:47:55 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client