0
/ 100
10 hours ago
glama

SassyMCP

SassyMCP is a comprehensive MCP server that replaces 75+ individual servers with one 34MB executable. It provides 274 tools for file operations, shell, desktop automation, GitHub/Git, Android interaction, network/security auditing, SSH, OCR, and Windows system management.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Reads files from sensitive locations
Touches: /Library/Keychains
⚠️
Tool descriptions don’t match what handlers do
1 tool describes read intent but its handler mutates — sassy_edit_block (line 157: p.write_text(new_content, encoding="utf-8"))
🔐
You'll be asked for 12 credentials: SASSYMCP_AUTH_TOKEN, INCEPTION_API_KEY, LEMONSQUEEZY_API_KEY, SSH_KEY, SSH_PASS, LLM_API_KEY, OPENROUTER_API_KEY, SASSYMCP_PANEL_TOKEN, SASSYMCP_LICENSE_SECRET, GITHUB_TOKEN, GITHUB_PERSONAL_ACCESS_TOKEN, SASSYMCP_CROSSLINK_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configSASSYMCP_HOMECrash-survivable control. A pidfile + on-disk registry under $ mean supervise status/stop work even when the bridge is down, so an operator or agent can recover a wedged system.
configSASSYMCP_NO_AUTH
🔐 secretSASSYMCP_AUTH_TOKEN[Environment]::SetEnvironmentVariable("", "<your token>", "User")
configSASSYMCP_ALLOWED_HOSTS
configSASSYMCP_LOAD_ALL1 uv run sassymcp
configSASSYMCP_GROUPScore,github_quick,android,v020 uv run sassymcp
configSASSYMCP_DEV1 Enable live reload (dev mode)
configSASSYMCP_NO_UPDATE_CHECK1 Disable the startup update check (no GitHub API call)
configSASSYMCP_PANELpanel.enabled / =1 to launch it at boot), then open the
🔐 secretINCEPTION_API_KEY
configSASSYMCP_REPO/path/to/repo Override the auto-detected repo root in tools/mercury_audit_sassymcp.py (dev tool only)
configLEMONSQUEEZY_API_BASE
🔐 secretLEMONSQUEEZY_API_KEY
configSSH_HOSTxxx Remote Linux hostname/IP
configSSH_USERxxx Remote Linux username
🔐 secretSSH_KEY
🔐 secretSSH_PASSxxx Remote Linux password
configJOINT_CHANNEL
configHERMES_MODEL
configOLLAMA_URL
configMAX_TURNS
configPOLL_SECONDS
configHERMES_AUTORUN
🔐 secretLLM_API_KEY
🔐 secretOPENROUTER_API_KEY
configNO_COLOR
configTERM
configSASSYMCP_BILLING_BASE
configSASSYMCP_LS_BASE
configSASSYMCP_LS_VARIANT_MAP
configSASSYMCP_ADB
configSHELL
configSASSYMCP_RESOURCE_URL
configSASSYMCP_OAUTH_ISSUER
🔐 secretSASSYMCP_PANEL_TOKEN
configXDG_CONFIG_HOME
🔐 secretSASSYMCP_LICENSE_SECRET
configSASSYMCP_TUNNEL_NAME.\start-tunnel.bat sassymcp # tunnel name as arg, or set
🔐 secretGITHUB_TOKEN"": "ghp_your_token_here"
🔐 secretGITHUB_PERSONAL_ACCESS_TOKEN
🔐 secretSASSYMCP_CROSSLINK_TOKEN
configSSH_SESSION
configSSH_AUTH_SOCK
configPLINK_PATH
configSSH_CLIENT_PATH
configHERMES_NODE_PATH
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 9 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/sassyconsultingllc-sassymcp-8c61cq)](https://m8ven.ai/mcp/sassyconsultingllc-sassymcp-8c61cq)
commit: 4bb5fe895e4d55a306f0dd507b1ea8edd5c44198
code hash: 8db3c280a007cbf9be7cb32cf7ccc8a1594f7ce13b44a861dd39f264b593b058
verified: 7/31/2026, 8:55:47 AM
view raw JSON →