Puppet Enterprise MCP Server (TheDevFactory/puppet-mcp) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 63 tools. No publisher has claimed this listing.
Exposes the full Puppet Enterprise API to AI assistants, enabling management of Puppet infrastructure through natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
TheDevFactory
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
puppet_runRun Puppet on nodes on demand (enforce or noop mode)
run_taskRun a Puppet task on specified nodes
run_planRun a Puppet plan
stop_jobStop a running orchestrator job
stop_planStop a running plan job
list_jobsList orchestrator jobs with optional pagination
get_jobGet details of a specific orchestrator job
get_job_nodesGet nodes involved in a specific job
get_job_reportGet the report/summary for a specific job
get_job_eventsGet events that occurred during a job
list_plan_jobsList plan jobs with optional pagination
get_plan_jobGet details of a specific plan job
get_plan_job_eventsGet events from a specific plan job
list_tasksList available Puppet tasks
get_taskGet details of a specific task
list_plansList available Puppet plans
get_planGet details of a specific plan
list_scheduled_jobsList all scheduled orchestrator jobs
delete_scheduled_jobDelete a scheduled orchestrator job
check_inventoryVerify the orchestrator can reach specified nodes
get_usageGet active node deployment usage details
list_node_groupsList all node groups from the classifier
get_node_groupGet a specific node group by ID
create_node_groupCreate a new node group in the classifier
update_node_groupUpdate an existing node group
delete_node_groupDelete a node group from the classifier
classify_nodeGet classification data for a specific node
list_classesList all classes known to the node classifier
list_environmentsList environments known to the node classifier
get_node_check_insGet check-in history for a node
update_classesTrigger the classifier to refresh class definitions from the Puppet Server
unpin_nodesUnpin specified nodes from all node groups
list_usersList all PE users (local and remote)
get_userGet details of a specific user
get_current_userGet details of the currently authenticated user
create_userCreate a new local PE user
update_userUpdate an existing PE user
delete_userDelete a PE user
revoke_userRevoke a user's access to PE
reinstate_userReinstate a previously revoked user
list_rolesList all RBAC roles
get_roleGet a specific RBAC role
create_roleCreate a new RBAC role
list_user_groupsList all RBAC user groups
list_permissionsList all available RBAC permissions
generate_tokenGenerate a PE authentication token
deploy_codeDeploy Puppet code to specified environments via Code Manager
get_deploy_statusGet the status of Code Manager deployments
puppetdb_queryRun a PQL (Puppet Query Language) query against PuppetDB
list_nodesList all nodes known to PuppetDB
get_nodeGet PuppetDB details for a specific node
get_node_factsGet all facts for a specific node from PuppetDB
list_factsList facts from PuppetDB with optional filter
list_reportsList Puppet reports from PuppetDB
list_catalogsList catalogs from PuppetDB
get_resourcesQuery resources from PuppetDB
list_fact_namesList all known fact names in PuppetDB
list_pdb_environmentsList environments from PuppetDB
get_inventoryGet inventory data from PuppetDB
get_pe_statusGet status of PE console services (RBAC, Classifier, Activity)
get_orchestrator_statusGet status of the Orchestrator service
get_puppet_server_statusGet status of the Puppet Server
get_puppetdb_statusGet status of PuppetDB
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
PUPPET_CA_CERTNo CA certificate PEM contentPUPPET_HOSTYes PE primary server hostnamePUPPET_TLS_VERIFYNo Set true to enforce TLS verificationPUPPET_TOKENYes PE API authentication tokenPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
63/63 tools missing one or more hints — puppet_run (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); run_task (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); run_plan (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +60 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
46/63 tool handlers declare input schemas (73%)
Declare an inputSchema with zod/joi/yup on every tool definition.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/thedevfactory/puppet-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check