HAETSAL-OS (smitmat86-code/HAETSAL-OS) is an MCP server listed on the M8ven Trust Index. It scores 54 out of 100, grade D. It declares 36 tools. No publisher has claimed this listing.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
smitmat86-code
Source: github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
create_automationCreate a recurring automation that runs a task and messages the result
list_automationsList automations with schedules and recent fire events
toggle_automationPause or resume an automation
delete_automationDelete an automation permanently
brain_v1_retainRetain a memory in THE Brain
brain_v1_recallRecall memories from THE Brain
brain_v1_act_send_messageSend SMS or email
brain_v1_act_create_eventCreate calendar event
brain_v1_act_modify_eventModify calendar event
brain_v1_act_draftCreate a draft
brain_v1_act_searchSearch the web
brain_v1_act_browseBrowse a web page
brain_v1_act_remindSet a reminder
brain_v1_act_run_playbookRun a multi-step playbook
prepare_artifact_file_captureUse only after inspecting a directly attached ChatGPT file and capture_artifact_file could not receive a retrievable descriptor. Pass the model-generated extraction; the user will select that existing ChatGPT-hosted file in a private capture card.
capture_artifact_fileartifact_immutable_rollout_statusRead the content-free exact-target digest and completion status for the one-time immutable rollout
repair_artifact_immutable_rolloutExecute only an explicitly approved exact-target immutable promotion; original R2 objects are retained
reserve_artifact_uploadReserve a tenant-scoped managed artifact upload without sending file bytes through MCP
finalize_artifact_captureFinalize searchable extraction and an exact source/derivative artifact manifest
artifact_intake_statusRead a content-free managed artifact intake receipt
brain_v1_bootstrap_startStart bootstrap onboarding
brain_v1_bootstrap_interview_nextAnswer a bootstrap interview question
capture_memoryCapture memory through the canonical memory contract
search_memorySearch canonical memories
trace_relationshipTrace direct graph relationships through the canonical memory surface
get_entity_timelineView graph-backed entity activity over time through the canonical surface
prepare_context_for_agentAssemble a read-only context bundle for a first-party agent
get_recent_memory_tracesList recent brokered memory traces for the current tenant
get_memory_traceRead one brokered memory trace for the current tenant
get_recent_memoriesList recent canonical memories
get_documentGet one canonical document
memory_statusGet canonical memory operation status
memory_statsGet canonical memory stats
memory_searchSearch memories by query
memory_writeWrite an episodic or semantic memory
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
Hono Improper Authorization vulnerability
Hono vulnerable to arbitrary file access via serveStatic vulnerability
BRAIN_JWT_SUBCF_ACCESS_CLIENT_IDCF_ACCESS_CLIENT_SECRETMCP_ENDPOINTMCP_SEARCH_DELAY_MSMCP_TOOL_NAMEDependencies
6 runtime dependencies (10 dev), 1 flagged: @cloudflare/puppeteer
Tool annotations
2/36 tools have annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
36/36 tools missing one or more hints — create_automation (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_automations (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); toggle_automation (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +33 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
Only 9/27 tool handlers declare input schemas (33%)
Declare an inputSchema with zod/joi/yup on every tool definition.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Secrets not logged
4 secret values sent to log
Redact or omit secret values from log output.
Production dependencies are patched
0 critical, 5 high severity in production deps — hono@4.7.0 (high), hono@4.7.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/smitmat86-code/haetsal-os)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check