OSU MCP Server (sichengchen/ohio-state-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 62 out of 100, grade C. It declares 98 tools. No publisher has claimed this listing.

C
Caution
62/100

OSU MCP Server

Provides over 50 tools across 14 categories for accessing Ohio State University services including transportation, academics, dining, and events.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

sichengchen

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// tools this server exposes49 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

get_athletics_all

Get information about all OSU athletics programs and schedules

search_sports

Search for specific sports or teams

get_sport_by_gender

Find sports programs by gender

get_upcoming_games

Get upcoming games and events across all sports

get_bus_routes

Get information about all OSU bus routes/lines

get_bus_stops

Get all stops and route information for a specific bus line

get_bus_vehicles

Get real-time vehicle/bus locations for a specific route

get_buildings

Get information about all OSU buildings including addresses, locations, departments, and room details

search_buildings

Search for buildings by name or building number

get_building_details

Get detailed information about a specific building including rooms, departments, and special spaces

find_room_type

Find buildings that contain specific room types (lactation rooms, sanctuaries, wellness spaces, gender inclusive restrooms)

get_academic_calendar

Get the academic calendar with important dates

get_university_holidays

Get university holidays

search_calendar_events

Search for specific events in the academic calendar

get_holidays_by_year

Get holidays for a specific year

search_classes

Search for OSU classes by keyword, subject, instructor, etc.

get_dining_locations

Get all OSU dining locations with basic information

get_dining_locations_with_menus

Get all OSU dining locations with menu section information

get_dining_menu

Get detailed menu items for a specific dining location section

get_university_directory

Get the university directory information

search_people

Search for people in the OSU directory by first and/or last name

get_campus_events

Get information about all campus events

search_campus_events

Search for campus events by title or description

get_events_by_tag

Find events by specific tags or categories

get_events_by_location

Find events at a specific location

get_events_by_date_range

Find events within a specific date range

get_foodtruck_events

Get information about all food truck events on campus

search_foodtrucks

Search for food trucks by name or cuisine type

get_foodtrucks_by_location

Find food trucks at a specific location

get_library_locations

Get information about all OSU library locations including addresses, hours, and contact details

search_library_locations

Search for library locations by name

get_library_rooms

Get information about all available library study rooms for reservation

search_library_rooms

Search for library study rooms by name or location

get_rooms_by_capacity

Find library study rooms that can accommodate a specific number of people

get_rooms_with_amenities

Find library study rooms that have specific amenities

get_buckid_merchants

Get information about all merchants that accept BuckID

search_merchants

Search for merchants by name or category

get_merchants_by_food_type

Find merchants by food/cuisine type

get_merchants_with_meal_plan

Find merchants that accept meal plans

get_parking_availability

Get real-time parking availability for all OSU parking garages

get_recsports_facilities

Get information about all OSU recreation sports facilities including hours, availability, and events

search_recsports_facilities

Search for recreation sports facilities by name or abbreviation

get_facility_details

Get detailed information about a specific recreation sports facility

get_facility_hours

Get current operating hours and open/closed status for all recreation facilities

get_facility_events

Get scheduled events for recreation sports facilities

get_student_organizations

Get information about all student organizations

search_student_orgs

Search for student organizations by name or keywords

get_orgs_by_type

Find student organizations by type or category

get_orgs_by_career_level

Find organizations for specific career levels (undergraduate, graduate, professional)

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.17.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.17.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.17.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

98/98 tools missing one or more hints — get_athletics_all (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_sports (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_sport_by_gender (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +95 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.17.1 (high), @modelcontextprotocol/sdk@1.17.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/sichengchen/ohio-state-mcp-server?variant=verified)](https://m8ven.ai/mcp/sichengchen/ohio-state-mcp-server)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 300e8ea3ad670905765152fda434ab1addabacb7
code hash: 570f204a6fc0af19b200f0e13d304d6ed263d0d3201f1081921f97bc47db4af9
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client