MCP TS Toolkit (thomas92fr/mcp-ts-toolskit) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 55 tools. No publisher has claimed this listing.
A comprehensive MCP server providing secure tools for filesystem operations, Git management, web search, document conversion, npm/.NET project management, and AI generative capabilities (image/video/audio generation and processing) via PiAPI.ai integration.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
thomas92fr
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
analyze_csharp_dependenciesdotnet_toolserialize_csharpcreate_directorydirectory_treeedit_fileExecutes precise text modifications in files by replacing exact text sequences with new content. Features: 1) Preserves indentation and line formatting 2) Supports multi-line replacements 3) Validates file paths for security 4) Generates git-style unified diffs 5) Offers dry-run mode for preview. In…
list_allowed_directoriesmove_fileread_multiple_filessearch_file_contentsearch_fileswrite_filegit_checkoutgit_clonegit_commitgit_diffgit_fetchgit_loggit_pullgit_pushgit_resolve_conflictsgit_statusnpm_buildnpm_installmarkdown_to_documentpiapi_generate_music_for_videoGenerate a music for a video using Qubico MMAudio
piapi_tts_zero_shotZero-shot TTS using Qubico f5-tts
piapi_extend_musicÉtend une musique existante générée par PiAPI.ai en utilisant son ID et un timestamp
piapi_modify_imageModify a image using Qubico Flux, inpaint or outpaint
piapi_derive_imageDerive a image using Qubico Flux, variation
piapi_generate_image_controlnetGenerate a image using Qubico Flux with ControlNet
piapi_gemini_image_generationGenerates images from text descriptions using Google's Gemini 2.5 Flash Image model via PiAPI.ai API. Supports both text-to-image generation and image editing. Can generate 1-4 images in JPEG or PNG format. Cost: $0.03 per image.
piapi_get_task_statusPeriodically checks the status of a PiAPI task until completion or failure
piapi_image_to_3dpiapi_image_faceswapFaceswap an image
piapi_image_rmbgRemove the background of an image
piapi_image_segmentSegment an image
piapi_image_upscaleUpscale an image to a higher resolution
piapi_generate_video_klingGenerate a video using Kling
piapi_generate_video_effect_klingGenerate a video effect using Kling
piapi_midjourney_imagineGenerate a image using Midjourney Imagine
piapi_music_generationpiapi_show_imageShow an image with pixels less than 768*1024 due to Claude limitation
piapi_generate_music_sunoGenerate music using Suno
piapi_generate_video_lumaGenerate a video using Luma
piapi_text_to_imagepiapi_video_generationGénère une vidéo à partir d'un texte descriptif et optionnellement d'images clés via l'API PiAPI.ai
piapi_generate_video_hunyuanGenerate a video using Qubico Hunyuan
piapi_generate_video_skyreelsGenerate a video using Qubico Skyreels
piapi_generate_video_wanGenerate a video using Qubico Wan
piapi_video_faceswapFaceswap a video
piapi_video_upscaleUpscale video resolution to 2x
get_current_datetimeReturns the current date and time in ISO format
brave_web_searchget_web_page_contentRetrieve the complete HTML content of a web page using Puppeteer.' which means navigating to a URL and retrieving the text of the web page.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE
glob CLI: Command injection via -c/--cmd executes matches with shell:true
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
MCP_TOOLSKIT_CONFIG_PATH"": "C:/tmp/config.json"Dependencies
20 dependencies, 1 flagged: puppeteer-core
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
55/55 tools missing one or more hints — analyze_csharp_dependencies (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); dotnet_tool (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); serialize_csharp (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +52 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
1 critical, 6 high severity in production deps — simple-git@3.27.0 (critical), glob@10.4.5 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/thomas92fr/mcp-ts-toolskit)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check