CLI MARKET (Treevu-ai/cli-market-world) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 71 tools. No publisher has claimed this listing.

C
Emerging
74/100
3 days ago

CLI MARKET

Servidor MCP para integrar la plataforma CLI MARKET con asistentes de IA. Permite gestionar productos, pedidos, clientes e inventario de tu tienda marketplace mediante lenguaje natural.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Treevu-ai

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
28 flows detected: MARKET_API_TOKEN, GITHUB_TOKEN, OPENAI_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 30 credentials: HUBSPOT_WEBHOOK_SECRET, CRM_API_KEY, KOMMO_WEBHOOK_SECRET, SIMLA_WEBHOOK_SECRET, SIMLA_API_KEY, ZOHO_WEBHOOK_SECRET, MCP_ALLOW_QUERY_TOKEN, MARKET_API_TOKEN, GITHUB_TOKEN, GH_TOKEN, PEPY_API_KEY, PEPYTECH_API_KEY, OPENAI_API_KEY, CHECKOUT_WEBHOOK_SECRET, PROCURE_MAGIC_SECRET, SLACK_BOT_TOKEN, CLOUDFLARE_API_TOKEN, PAYPAL_E2E_API_KEY, HUBSPOT_ACCESS_TOKEN, MARKET_API_KEY, CLI_MARKET_API_KEY, ORCHESTRATOR_LLM_API_KEY, ANTHROPIC_API_KEY, XAI_API_KEY, GROK_API_KEY, PAYPAL_CLIENT_SECRET, CLI_MARKET_TOKEN, PROCUREMENT_WEBHOOK_SECRET, MARKET_USER_TOKEN, SLACK_SIGNING_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configLOG_LEVEL
🔐 secretHUBSPOT_WEBHOOK_SECRET
🔐 secretCRM_API_KEY
configHUBSPOT_PORTAL_ID
🔐 secretKOMMO_WEBHOOK_SECRET
configLOG_TO_FILE
🔐 secretSIMLA_WEBHOOK_SECRET
🔐 secretSIMLA_API_KEY
🔐 secretZOHO_WEBHOOK_SECRET
🔐 secretMCP_ALLOW_QUERY_TOKEN
configMARKET_MCP_CLIENT_TELEMETRY
configCORS_ORIGINS
configHOST
🔐 secretMARKET_API_TOKEN
configMARKET_PASSWORD_HASH_ITERATIONS
configRATE_LIMIT_MIN
configRATE_LIMIT_DAY
configRATE_LIMIT_WINDOW
configCOLLECT_PARALLEL
configCOLLECT_DELAY
configCOLLECT_INTERVAL_HOURS
configCOLLECT_MAX_QUERIES_PER_LINE
configCOLLECT_CORE_QUERIES
configCOLLECTOR_ADVISORY_LOCK
configCB_FAIL_THRESHOLD
configCB_COOLDOWN
configCB_PERSIST_SKIP
configINDEX_COLLECT_ENABLED
configCOLLECT_EXPANSION
configCOLLECT_FEEDBACK
configCOLLECT_FEEDBACK_DAYS
configCOLLECT_FEEDBACK_MIN
configPG_SSL_MODE
configCOLLECT_CATALOG_INTERVAL
configCOLLECT_GROWTH_REFRESH_INTERVAL
configINDEX_DATABASE_URL
configINDEX_DATA_DIR
configMARKET_DATA_DIR
configINDEX_PERSISTENCE
configINDEX_COLLECT_LIMIT
configINDEX_COLLECT_SINCE_MINUTES
configINDEX_BACKFILL_LIMIT
configADOPTION_GITHUB_REPO
🔐 secretGITHUB_TOKEN
🔐 secretGH_TOKEN
configMARKET_AGENT_ID
configNO_COLOR
configMARKET_MISSIONS
configMARKET_MISSION_TIMEOUT
configMARKET_API_URL
configCURSOR_TRACE_ID
configCURSOR_SESSION
configWINDSURF_SESSION
configCODEIUM_WINDSURF
configTERM_PROGRAM
configPEPY_PRO_TIME_RANGE
configPEPY_DAILY_SERIES_DAYS
configPEPY_CACHE_TTL_S
🔐 secretPEPY_API_KEY
🔐 secretPEPYTECH_API_KEY
configPEPY_PROJECT
configPEPY_PROJECTS
configMARKET_PULSE_LLM
🔐 secretOPENAI_API_KEY
configMARKET_PULSE_LLM_MODEL
configFLY_APP_NAME
configPAYPAL_SANDBOX
configPAYPAL_ALLOW_UNVERIFIED_WEBHOOKS
🔐 secretCHECKOUT_WEBHOOK_SECRET
configPROCURE_PEN_PER_USD
configPRO_PEN_PER_USD
configPROCURE_MAGIC_TTL_SECONDS
🔐 secretPROCURE_MAGIC_SECRET
configSERVER_HOST
configSERVER_PORT
configPRO_PAYMENT_URL
configPRO_PRICE_LABEL
🔐 secretSLACK_BOT_TOKEN
configSLACK_WEBHOOK_CLI_MARKET_PRO
configSLACK_WEBHOOK_FUNNEL
configSLACK_FUNNEL_REALTIME
configSLACK_FUNNEL_VERBOSE
configCONTENT_REPO_PATH
🔐 secretCLOUDFLARE_API_TOKEN
configCLOUDFLARE_ZONE_ID
configCLOUDFLARE_ACCOUNT_ID
configCLOUDFLARE_PAGES_PROJECT
configDASHBOARD_DATA_URL
configCOMMAND_CONTROL_METRICS_DIR
configCLI_MARKET_CONTENT_DIR
configLINKEDIN_CAMPAIGN_START
configLINKEDIN_POST_UTC_HOUR
configGITHUB_SERVER_URL
configCLI_MARKET_CONTENT_GITHUB_REPO
configGITHUB_REF_NAME
configGITHUB_CONTENT_REF
configGITHUB_REPOSITORY
configSLACK_WEBHOOK_BITACORA
configSLACK_WEBHOOK_PUBLICACIONES
configCLI_MARKET_CORE_ROOT
configDOCTOR_MIN_SNAPSHOTS
configDOCTOR_MIN_LINKAGE_PCT
configDOCTOR_MAX_DEAD_SOURCES
🔐 secretPAYPAL_E2E_API_KEY
🔐 secretHUBSPOT_ACCESS_TOKEN
configPIT_API_URL
🔐 secretMARKET_API_KEY
🔐 secretCLI_MARKET_API_KEY
configORCHESTRATOR_LLM_PROVIDER
configORCHESTRATOR_LLM_MODEL
🔐 secretORCHESTRATOR_LLM_API_KEY
🔐 secretANTHROPIC_API_KEY
🔐 secretXAI_API_KEY
🔐 secretGROK_API_KEY
configORCHESTRATOR_LLM_BASE_URL
configORCHESTRATOR_LLM_TEMPERATURE
configORCHESTRATOR_LLM_MAX_TOKENS
configSLACK_WEBHOOK_URL
configGITHUB_ACTIONS
configPRO_PRICE_USD
configPAYPAL_CLIENT_ID
🔐 secretPAYPAL_CLIENT_SECRET
🔐 secretCLI_MARKET_TOKEN
configPRICE_PULSE_POLL_SECS
configGH_PAT
configGITHUB_OUTPUT
🔐 secretPROCUREMENT_WEBHOOK_SECRET
configPROCURE_PUBLIC_URL
configPAM_LANDING_URL
🔐 secretMARKET_USER_TOKEN
configPAM_REPORT_DIR
configLINKEDIN_PERSONAL_DAY_OFFSET
configLINKEDIN_COMPANY_DAY_OFFSET
configSLACK_MIRROR_TWITTER_TO_THREADS
configSLACK_CHANNEL_VENTAS
configSLACK_CHANNEL_FUNNEL
🔐 secretSLACK_SIGNING_SECRET
configSLACK_CHANNEL_CLI_MARKET_PRO
configSLACK_CHANNEL_PUBLICACIONES
configSLACK_CHANNEL_BITACORA
configSLACK_CHANNEL_ALERTAS
configSLACK_CHANNEL_REVENUE
configSLACK_CHANNEL_REVISIONES_CURSOR
configSLACK_CHANNEL_COMMAND_CONTROL
configSLACK_WEBHOOK_ALERTAS
configSLACK_WEBHOOK_REVENUE
configSLACK_WEBHOOK_COMMAND_CONTROL
configSLACK_WEBHOOK_REVISIONES_CURSOR
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployNEXT_PUBLIC_PROCURE_SITE_URL
deployPORT
deployDATABASE_URL
deployPROCURE_APP_URL
deployNEXT_PUBLIC_PROCURE_APP_URL
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

71/71 tools missing one or more hints — market_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); market_compare (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); market_stores (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +68 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Secrets never reach shell commands

1 secret value passed to a subprocess as an argument — no shell is invoked, so there is nothing to inject into

Never pass secrets through shell commands. Use library APIs that accept credentials as arguments.

Secrets not logged

6 secret values sent to print

Redact or omit secret values from log output.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/treevu-ai/cli-market-world)](https://m8ven.ai/mcp/treevu-ai/cli-market-world)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: d70531b1a3ee4afe99626dc00c6d950f4f7c785d
code hash: 875377ca477394e1a0558cf5ed6eb3babfddb6c4e4f39c883358fc16bc200aa0
verified: 9/7/2026, 7:32:11 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client