SureM SMS MCP (suremapp/surem-sms-mcp) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 3 tools. No publisher has claimed this listing.

D
Caution
58/100

SureM SMS MCP

Enables Claude to send SMS/LMS messages via the SureM platform using natural language commands. It automatically handles message type selection, scheduled sending, and token management for seamless text message delivery.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

suremapp

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 9 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: SUREM_SECRET_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes4 tools · 1 behind config

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

send_message
send_tts

텍스트를 음성으로 변환해 전화 통화로 발송하는 TTS(Text-to-Speech) 도구입니다. 수신자의 휴대폰으로 전화가 걸리며 입력된 텍스트가 음성 안내로 재생됩니다. 메시지는 최대 90 글자. ⚠️ 발신번호(reqPhone)를 사용자가 명시하지 않았다면 절대 추측하지 말고 반드시 사용자에게 '슈어비즈에 사전 등록된 발신번호'를 직접 물어본 뒤 호출하세요.

send_international_message

한국이 아닌 국가로 국제 SMS 메시지를 발송합니다. 국가 코드(country)와 함께 호출. ⚠️ 한국(82) 은 이 도구를 사용하지 말고 send_message 로 발송하세요. 텍스트 길이는 최대 500 글자. ASCII 만 포함된 경우 160 byte / SMS, 유니코드 포함 시 70자 / SMS 기준으로 초과 시 서버에서 자동 concat(LMS) 처리. 중국(86) 은 슈어엠 정책상 항상 유니코드 모드로 계산됨. 국제 발송의 발신번호는 슈어비즈 사전 등록 여부와 무관하게 사용 가능 (국내 send_message 와 다름)

upload_mms_imagebehind config

MMS 발송에 사용할 이미지 1~3장을 슈어엠 서버에 업로드하고 단일 imageKey 를 반환합니다. 받은 imageKey 를 send_message 의 imageKey 파라미터에 전달해 MMS 로 발송. ⚠️ 이미지 규격: 확장자 jpg, 한 장 500KB 이하, 가로/세로 1000px 이하, 합산 1MB 미만. 입력은 서버 프로세스가 접근 가능한 로컬 jpg 파일 경로(path).

// known CVEs in dependencies9 high8 medium2 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highaxios@1.15.1GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.15.1GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.15.1GHSA-777c-7fjr-54vf

Allocation of Resources Without Limits or Throttling in Axios

highaxios@1.15.1GHSA-hfxv-24rg-xrqf

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

highaxios@1.15.1GHSA-j5f8-grm9-p9fc

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretSUREM_SECRET_KEY
configSUREM_USER_CODE가 실제 슈어엠 아이디 인지
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

4/4 tools missing one or more hints — send_message (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); upload_mms_image (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); send_tts (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +1 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 9 high severity in production deps — axios@1.15.1 (high), axios@1.15.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/suremapp/surem-sms-mcp?variant=verified)](https://m8ven.ai/mcp/suremapp/surem-sms-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 936a9291e5b9a4689f4db3ac241c395dd13435c7
code hash: f78bc158ae1223e83da7e85414375b86cbac7c10315aec9d2b026b2f18e54a6f
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client