superlog (superloglabs/superlog) is an MCP server listed on the M8ven Trust Index. It scores 64 out of 100, grade C. It declares 49 tools. No publisher has claimed this listing.
Open-source observability tool that uses AI agents to self-heal your software
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
superloglabs
Source: github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
query_logsSearch OpenTelemetry logs. Targets the session's active project unless project_id is given. Error rows include flattened exception_type, exception_message, and exception_stacktrace fields when present.
query_tracesSearch OpenTelemetry spans. Targets the session's active project unless project_id is given. Spans with exception events include flattened exception_type, exception_message, and exception_stacktrace fields when present.
query_metricsFetch recent metric points across gauge, sum, explicit-histogram, exponential-histogram, and summary tables. Targets the session's active project unless project_id is given. Each point includes its data-point `attributes` (the per-series dimensions like route/status/tenant), `resource_attrs`, start …
list_servicesList distinct service.name values emitting telemetry in the given window.
list_projectsList every project the authenticated user can access, across all of their orgs. The active project is marked.
get_active_projectReturn the project that tools default to when project_id is omitted.
set_active_projectChange the default project for subsequent tool calls in this session. Persists for the lifetime of the access token.
list_agent_mcp_serversList the custom MCP servers available to new investigation and Slack-agent sessions for this project. Credentials are always redacted.
add_agent_mcp_serverAdd a trusted HTTPS Streamable HTTP MCP server to this project. Admin only. Authentication accepts none, bearer/API token, arbitrary API-key header, or OAuth. Credential inputs are write-only and never returned.
update_agent_mcp_serverUpdate a project MCP server. Admin only. Omit auth to preserve its credential; supplying auth replaces it. A changed URL must be explicitly trusted.
remove_agent_mcp_serverRemove a custom MCP server from this project. Admin only.
start_agent_mcp_oauthStart OAuth authorization-code authentication with discovery, PKCE, resource binding, and dynamic client registration when needed. Admin only. Open the returned authorizationUrl in a browser.
connect_agent_mcp_client_credentialsExchange the configured OAuth client ID and secret using client_credentials, but only when advertised by the authorization server. Admin only.
disconnect_agent_mcp_oauthErase stored OAuth tokens and disable this custom MCP server. Admin only.
test_agent_mcp_serverConnect to a configured MCP server, initialize the protocol, and list its tools. Admin only. Secrets are never returned.
get_issue_filterRead the project's issue filter: per-kind include/exclude attribute clauses that decide which ERROR events become issues/incidents. Excludes win; a non-empty include list means an event must match at least one clause.
update_issue_filterUpdate the issue filter. Each bucket you provide REPLACES that bucket; omit a bucket to leave it unchanged; pass [] to clear it. Use this to quiet recurring noise (add an exclude clause) or to scope investigations to specific services/routes (add an include clause). Call get_issue_filter first if yo…
preview_issue_filterPreview which recent ERROR events (last 24h) would still become issues under a candidate filter, WITHOUT saving. Buckets you pass are merged over the project's current filter (same semantics as update_issue_filter); omit all buckets to preview the current saved filter. Returns sample matching events…
get_project_contextRead the project's freeform context — the human-written description of the system (architecture, conventions, key services) that the investigation agent reads on every run.
set_project_contextOverwrite the project's freeform context (max 8000 chars; longer input is truncated). This REPLACES the whole field — call get_project_context first and edit the returned text if you want to preserve existing content. Use for durable, system-level facts that apply to every investigation; for narrowe…
list_agent_memoriesList the investigation agent's stored memories for the project — durable learnings (feedback, terminology, infra, project facts) that are injected into future investigations.
create_agent_memoryRecord a durable, reusable learning so future investigations inherit it. Record a memory whenever you discover something worth remembering across investigations — a root-cause pattern, a piece of infra/architecture, a domain term, or a user correction about how to investigate. Keep the title a short…
update_agent_memoryPatch a stored memory. Provide only the fields you want to change. Set status='archived' to retire a memory without deleting it (archived memories stop being injected into investigations).
delete_agent_memoryPermanently delete a stored memory by id. To retire one reversibly, prefer update_agent_memory with status='archived'.
list_alertsList all alerts in the active project (or the project_id you pass).
get_alertFetch a single alert plus its 50 most recent firings.
create_alertCreate an alert. For logs/traces sources aggregation must be 'count'; for metric source it must be 'sum' or 'avg' and metric_name is required.
update_alertPatch an alert. Provide only the fields you want to change. Validation runs on the merged result.
delete_alertDelete an alert by id.
preview_alertEvaluate a draft alert spec against current data without saving. Returns whether it would breach right now.
test_alertRe-evaluate a saved alert against current data and return the result.
soft_failget_homeFetch the active project's shared home command center, including built-ins, data widgets, links, and grid layouts.
set_home_builtinShow or hide one of the built-in home widgets: setup_todos, active_incidents, service_map, incoming_signals, incident_count, or agent_pull_requests.
add_home_widgetAdd a chart, table, or markdown widget directly to the shared project home. Uses the same widget config and 12-column layout as dashboards.
add_home_linkAdd a shared link card to project home. URLs must be absolute and use http or https.
update_home_layoutUpdate positions and sizes for home items on the 12-column grid. Read get_home first and send the items that should move.
remove_home_itemRemove a built-in, data widget, or link from project home. Read get_home first to discover item ids.
list_dashboardsList dashboards in the active project (or project_id).
get_dashboardFetch a dashboard with its widgets.
create_dashboardupdate_dashboardRename a dashboard.
set_dashboard_variablesdelete_dashboardDelete a dashboard and all its widgets.
add_dashboard_widgetupdate_dashboard_widgetdelete_dashboard_widgetRemove a widget from a dashboard.
get_incidentsearch_incidentsDisclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
nanoid: non-secure generators can loop indefinitely with negative size
nanoid: custom generators can loop indefinitely when size is zero
nanoid: Integer Overflow or Wraparound
ADMIN_WEB_ORIGINAGENT_SECRETS_KEYANTHROPIC_API_KEYAPI_BASE_URLAUTUMN_SECRET_KEYBETTER_AUTH_SECRETBETTER_AUTH_URLBILLING_ENFORCEMENT_ENABLEDDEMO_PROJECT_IDFEEDBACK_SLACK_WEBHOOKGATEWAY_PUBLIC_URLGITHUB_APP_CLIENT_IDGITHUB_APP_CLIENT_SECRETGITHUB_APP_IDGITHUB_APP_PRIVATE_KEYGITHUB_APP_PRIVATE_KEY_BASE64GITHUB_APP_SLUGGITHUB_APP_WEBHOOK_SECRETGITHUB_AUTHOR_OAUTH_REDIRECT_URLGITHUB_CLIENT_IDGITHUB_CLIENT_SECRETGITHUB_INSTALL_OAUTH_REDIRECT_URLGITHUB_OAUTH_CLIENT_IDGITHUB_OAUTH_CLIENT_SECRETGOOGLE_CLIENT_IDGOOGLE_CLIENT_SECRETHOSTNAMELINEAR_CLIENT_IDLINEAR_CLIENT_SECRETLINEAR_OAUTH_REDIRECT_URLLINEAR_WEBHOOK_SECRETNOTION_CLIENT_IDNOTION_CLIENT_SECRETNOTION_OAUTH_REDIRECT_URLOTEL_EXPORTER_OTLP_ENDPOINTOTEL_EXPORTER_OTLP_HEADERSOTEL_SDK_DISABLEDOTEL_SERVICE_INSTANCE_IDOTEL_SERVICE_NAMERESEND_API_KEYSTATE_SIGNING_SECRETSUPERLOG_ENVSUPERLOG_ENV_FILESUPERLOG_FROM_EMAILSUPERLOG_HARD_CAPSUPERLOG_REPLY_TO_EMAILWEBHOOK_ALLOW_PRIVATE_DESTINATIONSWEB_ORIGINDATABASE_URLPORTSENTRY_CLIENT_IDSENTRY_CLIENT_SECRETSENTRY_WEBHOOK_FORWARD_URLTool annotations
19/49 tools have annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
49/49 tools missing one or more hints — query_logs (missing: destructiveHint, idempotentHint, openWorldHint); query_traces (missing: destructiveHint, idempotentHint, openWorldHint); query_metrics (missing: destructiveHint, idempotentHint, openWorldHint), +46 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
README present
No README found
Add a README.md describing the server and its tools.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tool test coverage
38/49 tools referenced in tests (78%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
0 critical, 5 high severity in production deps — @hono/node-server@1.13.7 (high), better-auth@1.6.13 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/superloglabs/superlog)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check