Puppet Enterprise MCP Server (TheDevFactory/puppet-mcp) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 63 tools. No publisher has claimed this listing.

D
Caution
58/100

Puppet Enterprise MCP Server

Exposes the full Puppet Enterprise API to AI assistants, enabling management of Puppet infrastructure through natural language.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

TheDevFactory

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 1 credential: PUPPET_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes63 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

puppet_run

Run Puppet on nodes on demand (enforce or noop mode)

run_task

Run a Puppet task on specified nodes

run_plan

Run a Puppet plan

stop_job

Stop a running orchestrator job

stop_plan

Stop a running plan job

list_jobs

List orchestrator jobs with optional pagination

get_job

Get details of a specific orchestrator job

get_job_nodes

Get nodes involved in a specific job

get_job_report

Get the report/summary for a specific job

get_job_events

Get events that occurred during a job

list_plan_jobs

List plan jobs with optional pagination

get_plan_job

Get details of a specific plan job

get_plan_job_events

Get events from a specific plan job

list_tasks

List available Puppet tasks

get_task

Get details of a specific task

list_plans

List available Puppet plans

get_plan

Get details of a specific plan

list_scheduled_jobs

List all scheduled orchestrator jobs

delete_scheduled_job

Delete a scheduled orchestrator job

check_inventory

Verify the orchestrator can reach specified nodes

get_usage

Get active node deployment usage details

list_node_groups

List all node groups from the classifier

get_node_group

Get a specific node group by ID

create_node_group

Create a new node group in the classifier

update_node_group

Update an existing node group

delete_node_group

Delete a node group from the classifier

classify_node

Get classification data for a specific node

list_classes

List all classes known to the node classifier

list_environments

List environments known to the node classifier

get_node_check_ins

Get check-in history for a node

update_classes

Trigger the classifier to refresh class definitions from the Puppet Server

unpin_nodes

Unpin specified nodes from all node groups

list_users

List all PE users (local and remote)

get_user

Get details of a specific user

get_current_user

Get details of the currently authenticated user

create_user

Create a new local PE user

update_user

Update an existing PE user

delete_user

Delete a PE user

revoke_user

Revoke a user's access to PE

reinstate_user

Reinstate a previously revoked user

list_roles

List all RBAC roles

get_role

Get a specific RBAC role

create_role

Create a new RBAC role

list_user_groups

List all RBAC user groups

list_permissions

List all available RBAC permissions

generate_token

Generate a PE authentication token

deploy_code

Deploy Puppet code to specified environments via Code Manager

get_deploy_status

Get the status of Code Manager deployments

puppetdb_query

Run a PQL (Puppet Query Language) query against PuppetDB

list_nodes

List all nodes known to PuppetDB

get_node

Get PuppetDB details for a specific node

get_node_facts

Get all facts for a specific node from PuppetDB

list_facts

List facts from PuppetDB with optional filter

list_reports

List Puppet reports from PuppetDB

list_catalogs

List catalogs from PuppetDB

get_resources

Query resources from PuppetDB

list_fact_names

List all known fact names in PuppetDB

list_pdb_environments

List environments from PuppetDB

get_inventory

Get inventory data from PuppetDB

get_pe_status

Get status of PE console services (RBAC, Classifier, Activity)

get_orchestrator_status

Get status of the Orchestrator service

get_puppet_server_status

Get status of the Puppet Server

get_puppetdb_status

Get status of PuppetDB

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configPUPPET_CA_CERTNo CA certificate PEM content
configPUPPET_HOSTYes PE primary server hostname
configPUPPET_TLS_VERIFYNo Set true to enforce TLS verification
🔐 secretPUPPET_TOKENYes PE API authentication token
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

63/63 tools missing one or more hints — puppet_run (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); run_task (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); run_plan (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +60 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

46/63 tool handlers declare input schemas (73%)

Declare an inputSchema with zod/joi/yup on every tool definition.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/thedevfactory/puppet-mcp?variant=verified)](https://m8ven.ai/mcp/thedevfactory/puppet-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: ab1c586964d821d93183e9e95caa81488aada610
code hash: 4b8393f0b734b893592b0885dbb9720ff48562fa895f7fab265b94fb30ea4612
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client