MOCO AI Coworker MCP Server (sungjin-ahn-dev/moco-ai-coworker) is an MCP server listed on the M8ven Trust Index. It scores 52 out of 100, grade D. It declares 219 tools. No publisher has claimed this listing.

D
Caution
52/100

MOCO AI Coworker MCP Server

Exposes 219+ tools for Slack, Gmail, Google Workspace, Jira, Confluence, CRM, and phone, enabling a multi-agent AI coworker with memory and proactive suggestions.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

sungjin-ahn-dev

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 8 credentials: SLACK_BOT_TOKEN, CLAWOPS_API_KEY, GOOGLE_API_KEY, GEMINI_API_KEY, SOLAPI_API_KEY, SOLAPI_API_SECRET, NCP_ACCESS_KEY, NCP_SECRET_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes219 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

propose_new_agent
list_my_agents
propose_candidate_agent
list_skills_tool
execute_skill_tool
moco_ask

[자동 호출 규칙] 사용자가 'moco', '모코', 'MOCO'로 호명하거나, acme 회사 업무 관련 요청(일정·회의·이메일·Slack·Confluence·Jira·CRM·병원·처방·계획·메모리·태스크 등)을 하면 즉시 이 도구를 호출하세요. 원본 메시지를 그대로 message 인자에 전달합니다.

moco_chat

MOCO Simple Chat (빠른 답변). 도구 사용 없는 가벼운 대화.

moco_search_memory

MOCO 로컬 메모리에서 query와 관련된 내용 검색.

moco_save_memory

MOCO 메모리에 새 정보 저장.

moco_list_email_tasks

이메일에서 추출된 태스크 조회. status: pending | completed | all

moco_list_jira_tasks

Jira에서 추출된 todo 태스크 조회. status: pending | completed | all

moco_list_pending_answers

답변을 기다리는 질문 목록 (waiting_answer DB).

moco_schedule_message

Slack 채널에 메시지 예약 발송.

moco_status

MOCO 시스템 상태 (활성 체커, 메모리 디렉토리, 모델 설정 등).

clickup_get_me

_auto_set_requester(args)현재 사용자 정보 조회

clickup_get_my_tasks

_auto_set_requester(args)사용자 태스크 목록 조회 (Slack 사용자 매핑 지원)

clickup_list_workspaces

_auto_set_requester(args)워크스페이스 목록 조회

clickup_list_spaces

_auto_set_requester(args)스페이스 목록 조회

clickup_list_folders

_auto_set_requester(args)폴더 목록 조회

clickup_list_lists

_auto_set_requester(args)리스트 목록 조회

clickup_list_tasks

_auto_set_requester(args)태스크 목록 조회

clickup_get_task

_auto_set_requester(args)태스크 상세 조회

clickup_delete_task

_auto_set_requester(args)태스크 삭제

clickup_add_comment

_auto_set_requester(args)코멘트 추가

clickup_get_comments

_auto_set_requester(args)코멘트 목록 조회

clickup_search_tasks

_auto_set_requester(args)태스크 검색

clickup_add_tag
clickup_remove_tag
clickup_set_custom_field
confirm_request_confirmation

사용자에게 confirm 메시지를 보내고 DB에 저장

crm_search_contacts

CRM 연락처 검색

crm_get_contact

CRM 연락처 상세 조회

crm_search_deals

CRM 딜 검색

crm_update_deal_stage

CRM 딜 단계 변경

crm_get_pipeline_summary

CRM 파이프라인 현황 조회

crm_create_task

CRM 태스크 생성

crm_get_my_tasks

사용자의 CRM 태스크 조회

crm_dashboard_summary

CRM 대시보드 요약

crm_enroll_sequence

CRM 시퀀스 등록

crm_list_sequences

CRM 이메일 시퀀스 목록 조회

crm_get_sequence

CRM 이메일 시퀀스 상세 조회

crm_list_automations

CRM 자동화 목록 조회

crm_list_forms

CRM 폼 목록 조회

crm_list_segments

CRM 세그먼트 목록 조회

crm_get_segment_contacts

세그먼트 연락처 조회

crm_list_activities

CRM 활동 이력 조회

crm_get_reports

CRM 리포트 조회

crm_delete_contact
crm_contact_timeline
crm_recalculate_lead_score
crm_list_companies
crm_get_company
crm_create_company
crm_update_company
crm_delete_company
crm_get_company_contacts
crm_get_company_deals
crm_get_deal
crm_update_deal
crm_delete_deal
crm_list_pipelines
crm_create_pipeline
crm_update_pipeline
crm_delete_pipeline
crm_create_sequence
crm_update_sequence
crm_delete_sequence
crm_pause_sequence
crm_sequence_enrollments
crm_sequence_dashboard
crm_bulk_enroll_sequence
crm_get_automation
crm_update_automation
crm_delete_automation
crm_execute_automation
crm_automation_history
crm_list_tasks
crm_get_task
crm_update_task
crm_complete_task
crm_delete_task
crm_create_form
crm_get_form
crm_update_form
crm_delete_form
crm_create_segment
crm_update_segment
crm_delete_segment
crm_refresh_segment
crm_update_activity
crm_delete_activity
crm_get_deals_by_pipeline
crm_deal_forecast
crm_get_pipeline
crm_get_activity
crm_recent_activities
crm_submit_form
crm_list_form_submissions
crm_get_segment
crm_sequence_stats

119 further tools are not listed here. The complete surface is in the source.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretSLACK_BOT_TOKEN
🔐 secretCLAWOPS_API_KEY
🔐 secretGOOGLE_API_KEY
🔐 secretGEMINI_API_KEY
configCLAWOPS_ACCOUNT_ID
🔐 secretSOLAPI_API_KEY
🔐 secretSOLAPI_API_SECRET
🔐 secretNCP_ACCESS_KEY
🔐 secretNCP_SECRET_KEY
configNCP_SMS_SERVICE_ID
configSOLAPI_SENDER
configNCP_FROM_NUMBER
configNCP_BIZ_SERVICE_ID
configNCP_KAKAO_CHANNEL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

219/219 tools missing one or more hints — propose_new_agent (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_my_agents (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); propose_candidate_agent (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +216 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Destructive tools are labelled

1 tool perform destructive updates without destructiveHint — slack_transfer_file deletes at line 987 (temp_file.unlink())

Add destructiveHint:true to any tool whose handler calls .delete(), .upsert(), .update(), unlink, rm, DELETE, DROP, REPLACE INTO, or any operation that overwrites existing data.

Tool inputs are validated

217/219 tool handlers declare input schemas (99%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

206/219 tool handlers wrap calls in try/catch (94%)

Wrap each tool handler body in try/catch and return a structured error response.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/sungjin-ahn-dev/moco-ai-coworker?variant=verified)](https://m8ven.ai/mcp/sungjin-ahn-dev/moco-ai-coworker)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 38245fb18adb41d102566f3ee8994cda5fcce487
code hash: 475627ebacd7c708bf764026ba2dbfde6c67bbe8041fd46efd14c86f4bbd4f08
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client