iikoServer MCP Server (simba87/iiko-mcp) is an MCP server listed on the M8ven Trust Index. It scores 50 out of 100, grade D. It declares 47 tools. No publisher has claimed this listing.

D
Caution
50/100

iikoServer MCP Server

MCP server for iiko restaurant management system REST API, providing 39 tools to manage products, employees, entities, documents, payments, reports, and raw API access.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

simba87

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Tool descriptions don’t match what handlers do
1 tool describes read intent but its handler mutates — get_revenue_at_time_handler (line 714: with open("/tmp/revenue_debug.log", "a") as _f:)
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 1 credential: IIKO_PASS
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes47 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

ping_handler
list_endpoints_handler
get_products_handler
get_product_groups_handler
get_product_sizes_handler
get_nomenclature_handler
get_corporate_structure_handler
get_corporate_groups_handler
search_products_handler
get_employees_handler
get_employee_handler
get_employee_roles_handler
get_persons_handler
get_entity_types_handler
get_entities_handler
get_entity_by_id_handler
get_stores_handler
get_contractors_handler
get_incoming_invoices_handler
get_outgoing_invoices_handler
get_incoming_invoice_by_id_handler
get_outgoing_invoice_by_id_handler
get_waste_documents_handler
get_menu_changes_handler
get_menu_change_by_id_handler
get_assembly_charts_handler
get_assembly_chart_by_id_handler
save_assembly_chart_handler
get_payment_types_handler
get_cash_shifts_handler
get_cash_shift_handler
get_payments_handler
get_payment_handler
create_encashment_handler
get_price_categories_handler
get_price_category_handler
get_olap_columns_handler
run_olap_report_handler
get_olap_presets_handler
run_olap_by_preset_handler
run_custom_report_handler
get_venues_revenue_handler
get_staff_meals_handler
get_top_dishes_handler
compare_revenue_handler
get_checks_handler
get_revenue_at_time_handler

Get revenue up to a specific time on a given date.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configIIKO_URLNo https://poidu-poem.iiko.it:443 iikoServer base URL
configIIKO_LOGINYes — Login username
🔐 secretIIKO_PASSYes — Plain password (SHA1 computed internally)
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

47/47 tools missing one or more hints — ping_handler (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_endpoints_handler (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_products_handler (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +44 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Descriptions match behaviour

1 tool describes read intent but its handler mutates — get_revenue_at_time_handler (line 714: with open("/tmp/revenue_debug.log", "a") as _f:)

Rename the tool, rewrite the description, or move the side-effect into a separate clearly-named tool.

Tool inputs are validated

Only 0/47 tool handlers declare input schemas (0%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 0/47 tool handlers wrap calls in try/catch (0%)

Wrap each tool handler body in try/catch and return a structured error response.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Tool description accuracy

get_revenue_at_time_handler: description implies read-only but handler writes/deletes/executes

Update tool descriptions to accurately reflect all capabilities — especially write, delete, or execute operations.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/simba87/iiko-mcp?variant=verified)](https://m8ven.ai/mcp/simba87/iiko-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: ffc88db717cadeea15ddee727b759355bd093a11
code hash: dfc9f4ad8e6e23dd97a856b74028a0e4b39b3b25f6ae6dbdbc5a7ae9661653b0
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client