dynamic-mcp-server (scitara-cto/dynamic-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 51 out of 100, grade D. It declares 18 tools. No publisher has claimed this listing.
A flexible and extensible framework for building Model Context Protocol (MCP) servers that conforms to the [Model Context Protocol specification](https://modelcontextprotocol.io/). This framework enables both static and dynamic tool registration, allowing tools to be defined at runtime as well as compile time.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
scitara-cto
Source: mcp.so · also listed on Glama, github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
list-promptsList all available prompts for the current user
add-promptAdd a new prompt to the system
update-promptUpdate an existing prompt's definition or properties
delete-promptDelete a prompt from the system
list-toolsList all tools
delete-toolDelete a tool
update-toolUpdate an existing tool's definition or properties
list-usersList all users
add-userAdd a new user
update-userUpdate an existing user
delete-userDelete a user
share-toolShare a tool with another user (adds to their sharedTools array)
unshare-toolUnshare a tool from a user (removes from their sharedTools array)
remove-userRemove (delete) a user by email. This action is irreversible. You must confirm with the user that they want to remove the user before actually calling this tool.
user-infoRetrieve information about a user. If email is omitted, returns the current user's info. Admins get full info for any user. Non-admins get only existence and name for other users.
hide-toolHide one or more tools for the current user
unhide-toolUnhide one or more tools for the current user (removes from hiddenTools array)
reset-api-keyReset a user's API key and email the new key to the user. Always call this tool first with userConfirmed: false (or omitted). Only set userConfirmed: true after the user has explicitly confirmed. For non-admin users, the email field is ignored and your own API key will be reset.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
LOG_FILE_PATHLOG_LEVELMCP_ADMIN_EMAILMCP_SERVER_NAMEMCP_SERVER_URLMONGODB_DBOMIT_HANDLERSPOSTMARK_API_TOKENSERVER_NAMESERVER_VERSIONMONGODB_URIPORTSMTP_FROMTool test coverage
7/18 tools referenced in tests (39%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
0 critical, 14 high severity in production deps — @modelcontextprotocol/sdk@1.9.0 (high), @modelcontextprotocol/sdk@1.9.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/scitara-cto/dynamic-mcp-server)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check