zhipu-vision (SoLongAdios/zhipu-vision-mcp) is an MCP server listed on the M8ven Trust Index. It scores 89 out of 100, grade B. It declares 1 tool. The publisher has proved control of what we score (Verified Publisher).
A multi-provider vision model MCP server with automatic failover, providing a single tool analyze_image for image recognition and understanding across multiple models.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Connect your repo and M8ven re-verifies it on the push itself. Without it we re-check verified listings about once a day, so a fix can sit unseen. Read-only, one click, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
GEMINI_API_KEYgemini-2.5-flashGEMINI_BASE_URLGoogle OpenAI 兼容端点 base URLKIMI_API_KEYkimi-k3 / kimi-k2.6KIMI_BASE_URL月之暗面 OpenAI 兼容端点 base URLMIMO_API_KEYglm-4.6v-flash / glm-4.1v-thinking-flash / glm-4v-flash 为智谱免费视觉模型;mimo-v2.5 / mimo-v2-omni 为小米 mimo 多模态模型(需 ),作为收费兜底:智谱免费模型 429 限流/失败时自动切换。MIMO_BASE_URL小米 mimo OpenAI 兼容端点 base URLOPENAI_API_KEYgpt-4o / gpt-4o-miniOPENAI_BASE_URLOpenAI 兼容端点 base URLQWEN_API_KEYqwen-vl-max / qwen3.8-maxQWEN_BASE_URL阿里百炼 OpenAI 兼容端点 base URL(新版百炼空间可覆盖为 maas 端点)SILICONFLOW_API_KEYQwen/Qwen2.5-VL-72B-InstructSILICONFLOW_BASE_URL硅基流动 OpenAI 兼容端点 base URLVISION_MODEL_CHAIN1. 追加到候选链(自动参与故障转移):把条目加到 末尾,如VISION_TIMEOUT_MS单次请求超时毫秒ZHIPU_API_KEY智谱 API key([open.bigmodel.cn](https://open.bigmodel.cn) 控制台获取)ZHIPU_BASE_URL智谱 API base URL,一般无需修改ZHIPU_MODEL逗号分隔的候选模型链,按优先级自动故障转移。条目格式 provider:model,provider 缺省为 zhipu。默认链为智谱免费模型 + mimo 收费兜底;追加其他收费模型(kimi/qwen/gemini/gpt 等)即自动参与故障转移,未配 key 的条目自动跳过。未设置时退化为 ZHIPU_MODELTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
1/1 tools missing one or more hints — analyze_image (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Secrets stay with their owner
1 secret/sensitive value flow into network calls (ZHIPU_API_KEY → open.bigmodel.cn) (1 other flows matched canonical API hosts)
Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.
Secrets not logged
4 secret values sent to log
Redact or omit secret values from log output.
[](https://m8ven.ai/mcp/solongadios/zhipu-vision-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check