opensquilla (TokenRhythm/opensquilla) is an MCP server listed on the M8ven Trust Index. It scores 31 out of 100, grade F. It declares 69 tools. No publisher has claimed this listing.

F
Warning
31/100

opensquilla

OpenSquilla — Token-Efficient AI Agent with same budget, higher intelligence density

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

TokenRhythm

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Hardcoded credentials detected
2 live-looking API keys in source: 2 Slack token
🔐
You'll be asked for 4 credentials: ANTHROPIC_API_KEY, OPENROUTER_API_KEY, OPENAI_API_KEY, FIRECRAWL_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes68 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

conversations_list

List OpenSquilla sessions visible to the connected gateway principal.

session_resolve

Resolve a session key or identifier to OpenSquilla session metadata.

messages_read

Read persisted messages for an OpenSquilla session.

messages_send

Send a user message to an existing OpenSquilla session.

events_wait

Wait for live or replayed gateway events for an OpenSquilla session.

transcript_export

Export a session transcript as JSONL with standard tool evidence events.

read_file

Read a file

gateway
audio_config
agents_list

List available agent configurations from the agent registry.

subagents

List, kill, or steer spawned subagent sessions.

create_csv
create_xlsx
create_pptx
create_pdf_report
read_source
read_spreadsheet
write_scratch
create_source
list_dir

List directory contents with type and size.

glob_search

Find files matching a glob pattern.

source_symbols
grep_search

Search file contents for a regex pattern.

git_status

Show the working tree status.

git_diff

Show git diff (staged + unstaged changes).

git_commit

Stage specified files (or all changes) and create a commit.

git_log

Show recent git commit log.

update_goal
image
image_generate
pdf
voice_clone
voice_convert
dubbing_generate

Submit a local audio/video file for ElevenLabs dubbing.

dubbing_status

Check the status of an ElevenLabs dubbing job.

dubbing_download

Download completed ElevenLabs dubbing audio, optionally polling until ready.

music_generate

Generate instrumental music through ElevenLabs.

song_generate

Generate a song with sung vocals through ElevenLabs music generation.

audio_provider_capabilities

Report configured ElevenLabs audio provider capabilities.

voice_search
memory_search
memory_save
memory_get
memory_delete
message
meta_invoke
canvas
nodes
plan_run_checkpoint

CAS one server-authoritative PlanRun transition and publish its snapshot.

router_control
session_search
sessions_send

Send a message to another session (inter-session communication).

sessions_spawn
sessions_list

List active sessions with optional filters.

sessions_history

Retrieve conversation history from a session's transcript.

sessions_yield
session_status
skill_list

List all available skills with name, description, and eligibility.

skill_view
skill_search_community
install_skill_deps
skill_create
skill_edit
skill_delete
tool_search
http_request
web_discover

Lightweight web link discovery that returns titles, URLs, and snippets.

open_workspace_preview
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configOPENSQUILLA_DESKTOP_ENABLE_WIN_INSTALL
configOPENSQUILLA_DESKTOP_GATEWAY_PORT
configOPENSQUILLA_DESKTOP_GATEWAY_URL
configOPENSQUILLA_DESKTOP_REPO_ROOT
configOPENSQUILLA_DESKTOP_SECRET_STORAGE
configOPENSQUILLA_DESKTOP_UPDATE_CHANNEL_ROOT
configOPENSQUILLA_DESKTOP_UPDATE_SOURCE
configOPENSQUILLA_GATEWAY_URL
configOPENSQUILLA_OPENTUI_BUILD_ID
configOPENSQUILLA_OPENTUI_HOST_VERSION
configOPENSQUILLA_PLAYWRIGHT_MANAGE_WEBUI
configOPENSQUILLA_PREVIEW_FORCE_OFFLINE
configOPENSQUILLA_PRODUCT_VERSION
configOPENSQUILLA_TUI_THEME
configOPENSQUILLA_WEBUI_BASE_URL
configPLAYWRIGHT_CHROMIUM_EXECUTABLE_PATH
configPathWhen to use
configProgramFiles
configProgramFiles(x86)
configSystemRoot
configOPENSQUILLA_PROFILE
configOPENSQUILLA_RECOVERY_OFFLINE
configOPENSQUILLA_GATEWAY_CONFIG_PATHConfig load order: →
configDEEPSEEK_MODEL
configDEEPSEEK_BASE_URL
configOPENSQUILLA_TOOL_PROFILE
configOPENSQUILLA_WORKSPACE_WRITE_DENY_GUIDANCE
🔐 secretANTHROPIC_API_KEY
configANTHROPIC_BASE_URL
🔐 secretOPENROUTER_API_KEY
configOPENROUTER_BASE_URL
🔐 secretOPENAI_API_KEY
configOPENAI_BASE_URL
configOPENSQUILLA_LLM_PROXY
configOPENSQUILLA_LLM_PROVIDER
configOPENSQUILLA_LLM_MODEL
configSYSTEMROOT
configOPENSQUILLA_WINDOWS_APPCONTAINER_TEMPFILE_PATCH
configOPENSQUILLA_WINDOWS_APPCONTAINER_SITE_DIR
configOPENSQUILLA_SANDBOX_NETWORK
configCODEX_NETWORK_PROXY_ACTIVE
configHTTPS_PROXY
confighttps_proxy
configHTTP_PROXY
confighttp_proxy
configOPENSQUILLA_SHELL_DENYLIST
configOPENSQUILLA_SAFE_BIN_DENY
configOPENSQUILLA_SAFE_BIN_ALLOW
configOPENSQUILLA_SAFE_BIN_WARN
🔐 secretFIRECRAWL_API_KEY
configOPENSQUILLA_COMPARE_REPORT_DIR
configOPENSQUILLA_STATE_DB
configOPENSQUILLA_GATEWAY_TOKEN_FILE
configOPENCLAW_CONFIG
configOPENSQUILLA_JUDGE_MODEL
configOPENSQUILLA_JUDGE_BASE_URL
configOPENSQUILLA_LIFESTYLE_COMPARE_REPORT_DIR
configOPENCLAW_T3_MODEL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

69/69 tools missing one or more hints — conversations_list (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); session_resolve (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); messages_read (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +66 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Destructive tools are labelled

2 tools perform destructive updates without destructiveHint — memory_delete deletes at line 851 (file_path.unlink()); skill_delete deletes at line 1007 (shutil.rmtree(skill_dir))

Add destructiveHint:true to any tool whose handler calls .delete(), .upsert(), .update(), unlink, rm, DELETE, DROP, REPLACE INTO, or any operation that overwrites existing data.

No hardcoded API keys

2 live-looking API keys in source: 2 Slack token

Move secrets to environment variables (process.env.X) or your secret manager.

Domain consistency

npm scope @opensquilla doesn't match GitHub owner tokenrhythm

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/tokenrhythm/opensquilla?variant=verified)](https://m8ven.ai/mcp/tokenrhythm/opensquilla)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 3d7716f31ec241483309310bfc974d2ae710b72c
code hash: 0fc5a355aa938b1b2937f38271391590977d6fa0e8a255aff37c92660bd86afb
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client