embedded-mcp-toolkit (smk-h/embedded-mcp-toolkit) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. No publisher has claimed this listing.
基于MCP协议的嵌入式板卡远程管理工具,提供串口、SSH和本地PowerShell的交互能力,支持会话管理、一键登录等功能。
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
smk-h
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite
BOARD_CONFIG_PATH:主配置文件 config.yaml 的路径,相对于 MCP server 进程的工作目录(即启动 Claude 时的 cwd)。注意:devices/ 目录的查找位置始终是 config.yaml 的同级目录,因此 BOARD_CONFIG_PATH 同时决定了 config.yaml 和 devices/ 的位置BOARD_HOSTBOARD_PASSWORDBOARD_PORTBOARD_USERNAMECHALLENGE_FILEDEVICE这个是MCP的配置文件。env 字段中定义的环境变量会在 Claude 启动 MCP server 时,注入到 MCP server 子进程 的 process.env 中。也就是说,这些变量只在 [src/mcp.ts](src/mcp.ts:102-107) 进程中通过 process.env. 等方式读取,不会 影响 Claude 自身的 shell 环境变量。EMBEDDED_DATA_DIR环境变量可整体覆盖数据目录根(非标准部署时的逃生口,默认 cwd/.embedded)。传输相关的三条链路都收敛到同一落点后,典型流转是:Linux 端 scp 推到 .embedded/tmp/ → 经 serial_upload / ssh_sftp_upload 上载到设备;或反向下载后从该目录 scp 拉走。KEY_FILEKEY_PROVIDERLOGNAMELOG_DIRPowerShell 执行 ipconfig / 用 ps 运行 xxxLOG_SAVE:是否开启业务日志写入文件("1" 表示开启),记录工具调用信息(工具名称、调用参数、会话生命周期等)。需配合 LOG_DIR 使用PSH_CHALLENGE_PATTERNPSH_ERROR_PROMPTPSH_LOCKED_PROMPTPSH_PROFILEPSH_READY_PROMPTPSH_UNLOCKING_PROMPTPSH_UNLOCK_SEQUENCESAVE2FILE_PATH:原始数据日志的存储目录,记录串口、SSH、ADB 等 transport 接收到的原始字节流(每行附到达时间戳,每个会话单独一个文件)。设为 "none" 或留空则关闭。与 LOG_SAVE / LOG_DIR 相互独立SERIAL_BAUDRATESERIAL_PORTSSH_CLIENTSSH_CONNECTIONSSH_TTYShell command execution
4 calls in production code run through a shell (bin/embedded-mcp-toolkit-cli.js:15, src/sdk/transports/adb.ts:101, src/sdk/transports/powershell.ts:61)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 1 high severity in production deps — js-yaml@4.3.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
1/9 production deps stale: zmodem.js@2022-06-29 (4.2y)
Domain consistency
npm scope @smai-kit doesn't match GitHub owner smk-h
Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/smk-h/embedded-mcp-toolkit)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check