MCP TS Toolkit (thomas92fr/mcp-ts-toolskit) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 55 tools. No publisher has claimed this listing.

D
Caution
58/100

MCP TS Toolkit

A comprehensive MCP server providing secure tools for filesystem operations, Git management, web search, document conversion, npm/.NET project management, and AI generative capabilities (image/video/audio generation and processing) via PiAPI.ai integration.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

thomas92fr

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 6 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
// tools this server exposes55 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

analyze_csharp_dependencies
dotnet_tool
serialize_csharp
create_directory
directory_tree
edit_file

Executes precise text modifications in files by replacing exact text sequences with new content. Features: 1) Preserves indentation and line formatting 2) Supports multi-line replacements 3) Validates file paths for security 4) Generates git-style unified diffs 5) Offers dry-run mode for preview. In

list_allowed_directories
move_file
read_multiple_files
search_file_content
search_files
write_file
git_checkout
git_clone
git_commit
git_diff
git_fetch
git_log
git_pull
git_push
git_resolve_conflicts
git_status
npm_build
npm_install
markdown_to_document
piapi_generate_music_for_video

Generate a music for a video using Qubico MMAudio

piapi_tts_zero_shot

Zero-shot TTS using Qubico f5-tts

piapi_extend_music

Étend une musique existante générée par PiAPI.ai en utilisant son ID et un timestamp

piapi_modify_image

Modify a image using Qubico Flux, inpaint or outpaint

piapi_derive_image

Derive a image using Qubico Flux, variation

piapi_generate_image_controlnet

Generate a image using Qubico Flux with ControlNet

piapi_gemini_image_generation

Generates images from text descriptions using Google's Gemini 2.5 Flash Image model via PiAPI.ai API. Supports both text-to-image generation and image editing. Can generate 1-4 images in JPEG or PNG format. Cost: $0.03 per image.

piapi_get_task_status

Periodically checks the status of a PiAPI task until completion or failure

piapi_image_to_3d
piapi_image_faceswap

Faceswap an image

piapi_image_rmbg

Remove the background of an image

piapi_image_segment

Segment an image

piapi_image_upscale

Upscale an image to a higher resolution

piapi_generate_video_kling

Generate a video using Kling

piapi_generate_video_effect_kling

Generate a video effect using Kling

piapi_midjourney_imagine

Generate a image using Midjourney Imagine

piapi_music_generation
piapi_show_image

Show an image with pixels less than 768*1024 due to Claude limitation

piapi_generate_music_suno

Generate music using Suno

piapi_generate_video_luma

Generate a video using Luma

piapi_text_to_image
piapi_video_generation

Génère une vidéo à partir d'un texte descriptif et optionnellement d'images clés via l'API PiAPI.ai

piapi_generate_video_hunyuan

Generate a video using Qubico Hunyuan

piapi_generate_video_skyreels

Generate a video using Qubico Skyreels

piapi_generate_video_wan

Generate a video using Qubico Wan

piapi_video_faceswap

Faceswap a video

piapi_video_upscale

Upscale video resolution to 2x

get_current_datetime

Returns the current date and time in ISO format

brave_web_search
get_web_page_content

Retrieve the complete HTML content of a web page using Puppeteer.' which means navigating to a URL and retrieving the text of the web page.

// known CVEs in dependencies1 critical6 high6 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalsimple-git@3.27.0GHSA-r275-fr43-pm7q

simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE

highglob@10.4.5GHSA-5j98-mcp5-4vw2

glob CLI: Command injection via -c/--cmd executes matches with shell:true

highminimatch@9.0.5GHSA-23c5-xmqv-rm74

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

highminimatch@9.0.5GHSA-3ppc-4f35-3m26

minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

highminimatch@9.0.5GHSA-7r86-cg39-jmmj

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configMCP_TOOLSKIT_CONFIG_PATH"": "C:/tmp/config.json"
// quality suggestions

Dependencies

20 dependencies, 1 flagged: puppeteer-core

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

55/55 tools missing one or more hints — analyze_csharp_dependencies (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); dotnet_tool (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); serialize_csharp (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +52 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

1 critical, 6 high severity in production deps — simple-git@3.27.0 (critical), glob@10.4.5 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/thomas92fr/mcp-ts-toolskit?variant=verified)](https://m8ven.ai/mcp/thomas92fr/mcp-ts-toolskit)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: ee20a31de5c298f67d4308c693bee00e4d566fa5
code hash: 5e14ccd16085cacacfb8e3eea2263053d5b0f83fc29cf3a8e43f374119a8d381
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client