UMBRAXON/kya-hub (UMBRAXON/kya-hub) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.

C
Caution
72/100
2 months ago

UMBRAXON/kya-hub

Read-only MCP server bridging the public UMBRAXON KYA-Hub HTTP API. Exposes tools to fetch tiers/health, certificates, reputation, CRL metadata, and to verify certificate/delegation-pass payloads.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

UMBRAXON

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
11 flows detected: ADMIN_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Tests do not pass
Either the test suite is broken or the code regressed. Either way the published behaviour can’t be verified by the publisher’s own tests.
🔐
You'll be asked for 12 credentials: ADMIN_API_KEY, ALBY_UNLOCK_PASSWORD, B2_APP_KEY, BACKUP_S3_SECRET_ACCESS_KEY, BITCOIND_RPC_PASSWORD, BTCPAY_API_KEY, BTCPAY_SECRET, DB_PASSWORD, KYAHUB_APP_PASSWORD, KYA_INTEGRATOR_API_KEY, MASTODON_ACCESS_TOKEN, TELEGRAM_BOT_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

ws: Uninitialized memory disclosure

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretADMIN_API_KEY
configALBY_HUB_URL
configALBY_NWC_URI
configALBY_NWC_URI_FILE
🔐 secretALBY_UNLOCK_PASSWORD
configALBY_UNLOCK_PASSWORD_FILE
configANCHOR_FALLBACK_FEERATE_SAT_VB
configANCHOR_FEE_TARGET_BLOCKS
configANCHOR_FUNDING_BACKEND
configANCHOR_MAX_FEERATE_SAT_VB
configANCHOR_REQUIRE_CONFIRMATIONS
configANCHOR_WALLET_AUTOPAUSE_ENABLED
configANCHOR_WALLET_AUTOPAUSE_SATS
configANCHOR_WALLET_CRITICAL_SATS
configANCHOR_WALLET_MONITOR_INTERVAL_MS
configANCHOR_WALLET_WARN_SATS
configANCHOR_WORKER_BACKOFF_MS
configANCHOR_WORKER_BATCH
configANCHOR_WORKER_BROADCAST_ENABLED
configANCHOR_WORKER_CONFIRM_INTERVAL_MS
configANCHOR_WORKER_INTERVAL_MS
configANCHOR_WORKER_MAX_ATTEMPTS
configANCHOR_WORKER_PM2_NAME
configANOMALY_AUTO_SLASH
configANOMALY_TARGET_SPAM
configAPPEAL_SLA_HOURS
configAUTH_CHALLENGE_403_SPIKE_THRESHOLD
configAUTH_CHALLENGE_403_SPIKE_TTL_MULTIPLIER
configAUTH_CHALLENGE_403_SPIKE_WINDOW_MIN
configAUTH_CHALLENGE_EXTEND_OPEN_ON_SPIKE
🔐 secretB2_APP_KEY
configB2_BUCKET
configB2_KEY_ID
configB2_S3_ENDPOINT
configBACKUP_LOCAL_DIR
configBACKUP_PASSPHRASE
configBACKUP_S3_ACCESS_KEY_ID
configBACKUP_S3_BUCKET
configBACKUP_S3_ENDPOINT
configBACKUP_S3_PREFIX
configBACKUP_S3_REGION
🔐 secretBACKUP_S3_SECRET_ACCESS_KEY
configBAD_SIG_AUTO_SLASH
configBAD_SIG_PER_HOUR
configBAN_DAYS_BASIC
configBAN_DAYS_ELITE
configBAN_REPUTATION_DROP
configBITCOIND_ANCHOR_ADDRESS
configBITCOIND_ANCHOR_WALLET
configBITCOIND_RPC_COOKIE_PATH
configBITCOIND_RPC_DOCKER_CONTAINER
configBITCOIND_RPC_DOCKER_COOKIE
🔐 secretBITCOIND_RPC_PASSWORD
configBITCOIND_RPC_TIMEOUT_MS
configBITCOIND_RPC_URL
configBITCOIND_RPC_USER
configBLOCKSTREAM_API_URL
🔐 secretBTCPAY_API_KEY
🔐 secretBTCPAY_SECRET
configBTCPAY_STORE_ID
configBTCPAY_TIMEOUT_MS
configBTCPAY_URL
configCB_FAILURE_THRESHOLD
configCB_OPEN_DURATION_MS
configCB_SUCCESS_THRESHOLD
configCERT_BREAKER_AUTO_RESET_AFTER_MS
configCERT_BREAKER_HALT_PCT
configCERT_BREAKER_MIN_SAMPLES
configCERT_BREAKER_WARN_PCT
configCERT_BREAKER_WINDOW_MS
configCERT_DISCLAIMER
configCERT_ELITE_MULTISIG
configCERT_ELITE_MULTISIG_OPTIONAL
configCERT_ELITE_MULTISIG_ROLES
configCERT_ELITE_MULTISIG_THRESHOLD
configCERT_TERMS_URL
configCOINGECKO_BASE_URL
configCORS_ALLOWED_ORIGINS
configCRL_PUBLIC_BASE_URL
configCRL_PUBLIC_DIR
configCRL_WORKER_BACKOFF_MS
configCRL_WORKER_BATCH_MAX
configCRL_WORKER_BROADCAST_ENABLED
configCRL_WORKER_CONFIRM_INTERVAL_MS
configCRL_WORKER_INTERVAL_MS
configCRL_WORKER_MAX_ATTEMPTS
configCRL_WORKER_MIN_LEAVES
configDAC8_EXPORT_DIR
configDAC8_RATE_CACHE_DIR
configDATA_EXPORT_DIR
configDATA_EXPORT_MAX_PER_DAY
configDATA_EXPORT_PUBLIC_BASE_URL
configDATA_EXPORT_TTL_SECONDS
configDB_HOST
configDB_NAME
🔐 secretDB_PASSWORD
configDB_PORT
configDB_USER
configDECAY_INTERVAL_MS
configDEVKEY_RATE_ENTERPRISE_PER_MIN
configDEVKEY_RATE_FREE_PER_MIN
configDEVKEY_RATE_PRO_PER_MIN
configDEV_WEBHOOK_BATCH_SIZE
configDEV_WEBHOOK_MAX_ATTEMPTS
configDEV_WEBHOOK_POST_TIMEOUT_MS
configDEV_WEBHOOK_QUEUE_ENABLED
configDISCORD_WEBHOOK_URL
configDRY_RUN
configELITE_LISTING_GRACE_DAYS
configELITE_LISTING_HEARTBEAT_DAYS
configELITE_LISTING_HEARTBEAT_SATS
configELITE_LISTING_REACTIVATION_SATS
configESG_FALLBACK_WATTS
configEU_GRID_GCO2_PER_KWH
configFILE_PERM_AUTOFIX
configFILE_PERM_STRICT
configFORK_DETECTOR_AUTOPAUSE
configFORK_DETECTOR_DEPTH
configFORK_DETECTOR_HTTP_TIMEOUT_MS
configFORK_DETECTOR_UA
configGITHUB_ISSUE_WATCH_MAX_NOTIFY
configGITHUB_ISSUE_WATCH_NUMBER
configGITHUB_ISSUE_WATCH_REPO
configGITHUB_ISSUE_WATCH_STATE_PATH
configHUB_ED25519_PRIVKEY_HEX
configHUB_ED25519_PUBKEY_HEX
configHUB_KEY_PASSPHRASE
configHUB_NAME
configHUB_PUBLIC_URL
configHUB_URL
configHUB_VERSION
configINTEGRATOR_KEY_REQUEST_NOTIFY
configINTEGRATOR_KEY_REQ_MAX_PER_IP_DAY
configINTEGRATOR_LSAT_DAY_PASS_SATS
configINTEGRATOR_LSAT_RATE_PER_MIN
configINTEGRATOR_LSAT_TTL_HOURS
configINTEGRATOR_METRICS_ENABLED
configINTEGRATOR_READ_CACHE_MS
configINTEGRATOR_SANDBOX_ON_PRODUCTION
configINVOICE_BTC_RATE_EUR
configINVOICE_CURRENCY
configINVOICE_DOC_TITLE
configINVOICE_FX_PROVIDER
configINVOICE_LEGAL_NOTE
configINVOICE_LOCAL_DIR
configINVOICE_NUMBER_PREFIX
configINVOICE_PUSH_TO_R2
configINVOICE_SELLER_ADDRESS
configINVOICE_SELLER_EMAIL
configINVOICE_SELLER_IBAN
configINVOICE_SELLER_LOGO_PATH
configINVOICE_SELLER_NAME
configINVOICE_SELLER_TAX_ID
configINVOICE_SELLER_VAT_ID
configINVOICE_SELLER_WEBSITE
configINVOICE_VERIFIER_BASE
configIP_BAN_DURATION_HOURS
configIP_BAN_GROSS_10MIN
configIP_BAN_TOTAL_10MIN
configIP_BAN_WHITELIST
🔐 secretKYAHUB_APP_PASSWORD
configKYAHUB_BASE_URL
configKYA_HUB_BASE_URL
configKYA_HUB_LIVE_TEST
configKYA_HUB_REQUEST_TIMEOUT_MS
configKYA_HUB_USER_AGENT
🔐 secretKYA_INTEGRATOR_API_KEY
configLIQUIDITY_CRITICAL_SATS
configLIQUIDITY_HTTP_TIMEOUT_MS
configLIQUIDITY_INBOUND_RATIO_PCT
configLIQUIDITY_LSP_BUY_SATS
configLIQUIDITY_LSP_FEE_SATS
configLIQUIDITY_MIN_INBOUND_SATS
configLIQUIDITY_WARN_SATS
configLOG_LEVEL
configLOG_REDACT_MAX_DEPTH
configLOG_REDACT_MIN_LEN
🔐 secretMASTODON_ACCESS_TOKEN
configMASTODON_BASE_URL
configMASTODON_MAX_PER_RUN
configMASTODON_POSTS_DIR
configMASTODON_STATE_PATH
configMASTODON_TOKEN_FILE
configMEMPOOL_API_URL
configMETRICS_PREFIX
configMETRICS_REFRESH_TTL_MS
configMFR_ATTEST_RATE_BRONZE_PER_HR
configMFR_ATTEST_RATE_DEFAULT_PER_HR
configMFR_ATTEST_RATE_GOLD_PER_HR
configMFR_ATTEST_RATE_SILVER_PER_HR
configMFR_BONUS_BRONZE
configMFR_BONUS_GOLD
configMFR_BONUS_SILVER
configMFR_MAX_MANIFEST_META_BYTES
configMFR_MAX_METADATA_BYTES
configNETDATA_URL
configNOTIF_DEDUPE_MS
configNOTIF_ENABLED
configNOTIF_TIMEOUT_MS
configNWC_PAY_URI
configNWC_PAY_URI_FILE
configOPERATOR_DAILY_REPORT_ENABLED
configOPERATOR_REPORT_ALLOW_KYA_IDS
configOPERATOR_REPORT_HOURS
configPM2_BIN
configPOW_DEFAULT_DIFFICULTY
configPOW_ENABLED
configPOW_REGISTER_DIFFICULTY
configPOW_REGISTER_ELITE_DIFFICULTY
configPOW_REGISTER_MIN_DIFFICULTY
configPOW_REQUIRED_FOR
configPOW_SOLVE_MAX_ITERATIONS
configPOW_TTL_SEC
configPRICING_POLL_MS
configPROTOCOL_VIOLATION_SECOND_DELTA
configPROTOCOL_VIOLATION_THIRD_PLUS_DELTA
configPROTOCOL_VIOLATION_WINDOW_HOURS
configPUBLIC_HUB_URL
configRATE_V1_REGISTER_PER_MIN
configREGISTRATION_ID
configREGISTRATION_MAX_INTENTS_PER_IP_PER_DAY
configREREG_MULTIPLIER_BASE
configREREG_MULTIPLIER_CAP_EXP
configRETENTION_ACTION_LOG_DAYS
configRETENTION_ACTION_LOG_HARDDEL_DAYS
configRETENTION_ANOMALY_FRAC
configRETENTION_ANOMALY_MIN_ROWS
configRETENTION_AUTH_CHALLENGES_DAYS
configRETENTION_BATCH_SIZE
configRETENTION_CERTSIGN_DAYS
configRETENTION_CERTSIGN_HARDDEL_DAYS
configRETENTION_DATA_EXPORTS_DAYS
configRETENTION_HEARTBEAT_DAYS
configRETENTION_INTERVAL_MS
configRETENTION_IP_BANS_DAYS
configRETENTION_POW_CHALLENGES_DAYS
configRETENTION_REG_INTENTS_DAYS
configRETENTION_REJREQ_DAYS
configRETENTION_REJREQ_HARDDEL_DAYS
configRETENTION_REPEVENT_DAYS
configRETENTION_REPEVENT_HARDDEL_DAYS
configRETENTION_REPORTS_DAYS
configRETENTION_REPORTS_HARDDEL_DAYS
configRETENTION_SIGFAIL_DAYS
configRETENTION_VACUUM
configRETENTION_VOLUMETRIC_DAYS
configRETENTION_WEBHOOK_DAYS
configRETENTION_WEBHOOK_HARDDEL_DAYS
configRETENTION_WORKER
configSPONSOR_AGENT_ALLOWLIST
configSPONSOR_AGENT_INVITES_PER_MONTH
configSPONSOR_AGENT_MIN_REPUTATION
configSPONSOR_INVITE_ENABLED
configSPONSOR_INVITE_SUSPEND_DAYS
configSPONSOR_INVITE_TTL_HOURS_DEFAULT
configSPONSOR_INVITE_TTL_HOURS_MAX
configSPONSOR_MAX_VIOLATIONS_PER_30D
configSPONSOR_MFR_ALLOWLIST
configSPONSOR_MFR_INVITES_BRONZE_PER_MONTH
configSPONSOR_MFR_INVITES_GOLD_PER_MONTH
configSPONSOR_MFR_INVITES_SILVER_PER_MONTH
configSPONSOR_PENALTY_REPUTATION
configSYBIL_CIRCLE_LOOKBACK_DAYS
configSYBIL_CIRCLE_MIN_PAIRS
configSYBIL_CIRCLE_PENALTY
configSYBIL_MFR_BONUS
configSYBIL_MIN_ABS_DELTA
configSYBIL_RESISTANCE
configSYBIL_TIER_WEIGHT_BASIC
configSYBIL_TIER_WEIGHT_ELITE
🔐 secretTELEGRAM_BOT_TOKEN
configTELEGRAM_CHAT_ID
configTIER_BASIC_DURATION_MONTHS
configTIER_BASIC_GRADE
configTIER_BASIC_SATS
configTIER_ELITE_GRADE
configTIER_ELITE_REQUIRES_ANCHOR
configTIER_ELITE_SATS
configVOLUMETRIC_LIMITS_CACHE_TTL_MS
configWEB_UPTIME_FAIL_THRESHOLD
configWEB_UPTIME_STATE_PATH
configWEB_UPTIME_TIMEOUT_MS
configWEB_UPTIME_URL
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployNEXT_PUBLIC_HUB_URL
deployNEXT_PUBLIC_OPERATOR_GITHUB
deployNEXT_PUBLIC_OPERATOR_NAME
deployNEXT_PUBLIC_OPERATOR_TELEGRAM
deployNEXT_PUBLIC_OPERATOR_X_URL
deployNEXT_PUBLIC_SITE_URL
deployPORT
deploySENTRY_DSN
deploySENTRY_ENVIRONMENT
deploySENTRY_RELEASE
deploySENTRY_TRACES_SAMPLE_RATE
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

20/20 tools missing one or more hints — kya_health (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); kya_tiers (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); kya_hub_pubkey (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +17 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool handlers catch errors

Only 1/20 tool handlers wrap calls in try/catch (5%)

Wrap each tool handler body in try/catch and return a structured error response.

Tool test coverage

Only 0/20 tools referenced in tests (0%)

Write tests that reference each tool by name so every tool has at least one test.

Tests pass

npm test failed — tests do not pass

Make sure npm test runs cleanly. Common cause: missing build step or missing env vars.

Shell command execution

2 child_process calls — runs shell commands

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets stay with their owner

11 secret/sensitive values flow into network calls (ADMIN_API_KEY → dynamic, ADMIN_API_KEY → dynamic)

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Secrets not logged

3 secret values sent to console.log

Redact or omit secret values from log output.

Dependency freshness

1/25 production deps stale: ajv-formats@2024-03-30 (2.2y)

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/umbraxon-kya-hub-1q5yhd?variant=verified)](https://m8ven.ai/mcp/umbraxon-kya-hub-1q5yhd)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: bab661d370c89686cfd4f5ba8738b2032463ab6c
code hash: 6a230f79b0c747e820934e40f5fc1c2f9f51f259a6cbaa2bd92efa49f3550b9a
verified: 6/14/2026, 10:24:10 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client