Conductor By Thealxlabs (useconductor/conductor) is an MCP server listed on the M8ven Trust Index. It scores 52 out of 100, grade D. It declares 271 tools. No publisher has claimed this listing.
Local-first AI agent that unifies 25+ plugins (Spotify, Gmail, GitHub, Notion, Telegram, Vercel, and more) into a single orchestration framework. AES-256-GCM encrypted credentials, zero telemetry, supports Claude, GPT-4o, Gemini, and Ollama.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
useconductor
Source: mcp.so
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, as the running server reported them. We print them as written. Our assessment is the findings above, not this list.
conductor_statusGet the current status of Conductor
conductor_recent_activityGet recent activity from Conductor
json_formatFormat, validate, and minify JSON
text_statsGet text statistics — word count, character count, sentence count, reading time
regex_testTest a regex pattern against text
text_transformTransform text: uppercase, lowercase, title case, camelCase, snake_case, slug, reverse
url_expandExpand a shortened URL to its final destination
url_statusCheck if a URL is accessible and get response details
url_headersGet all HTTP response headers for a URL
aws_ec2_listList EC2 instances
aws_ec2_startStart an EC2 instance
aws_ec2_stopStop an EC2 instance
aws_s3_listList S3 buckets
aws_s3_putUpload file to S3
aws_lambda_listList Lambda functions
aws_lambda_invokeInvoke a Lambda function
calc_mathEvaluate a math expression. Supports +, -, *, /, **, %, sqrt(), abs(), sin(), cos(), tan(), log(), ceil(), floor(), round(), PI, E
calc_convertConvert between units. Supports: km/mi/m/ft/in/cm, kg/lb/oz/g, °C/°F/K, L/gal/ml, GB/MB/KB/TB
calc_dateCalculate days between dates, or add/subtract days from a date
color_convertConvert a color between hex, RGB, and HSL formats
color_contrastCheck WCAG contrast ratio between two colors
color_paletteGenerate a color palette (complementary, analogous, triadic, or random)
cron_schedulecron_listList all scheduled tasks
cron_cancelCancel and delete a scheduled task
cron_pausePause or resume a scheduled task without deleting it
cron_historyGet the run history for a scheduled task
cron_run_nowImmediately trigger a scheduled task without waiting for its next run time
crypto_priceGet current price of a cryptocurrency
crypto_trendingGet trending cryptocurrencies
crypto_searchSearch for a cryptocurrency by name or symbol
db_postgres_queryExecute a read-only SQL query on PostgreSQL. SELECT only — no writes allowed.
db_mysql_queryExecute a read-only SQL query on MySQL. SELECT only — no writes allowed.
db_mongo_findQuery a MongoDB collection
db_redis_commandExecute a Redis command
db_list_connectionsList configured database connections (without exposing credentials)
docker_containersList Docker containers. Use --all to include stopped containers.
docker_container_logsGet logs from a Docker container
docker_container_actionStart, stop, restart, pause, unpause, or kill a Docker container
docker_imagesList Docker images
docker_pullPull a Docker image
docker_runRun a Docker container. Requires approval for security.
docker_volumesList Docker volumes
docker_networksList Docker networks
docker_statsGet resource usage stats for running containers
docker_buildBuild a Docker image from a Dockerfile
docker_pushPush a Docker image to a registry
docker_network_lsList Docker networks
docker_volume_lsList Docker volumes
docker_compose_upStart services defined in a docker-compose file
docker_compose_downStop and remove services defined in a docker-compose file
docker_execExecute a command inside a running container
fun_jokeGet a random joke
fun_cat_factGet a random cat fact
fun_triviaGet a random trivia question
fun_random_numberGenerate a random number in a range
fun_quoteGet an inspirational quote
gcal_list_calendarsList all Google Calendars accessible to the user
gcal_list_eventsList upcoming calendar events
gcal_get_eventGet full details of a specific calendar event
gcal_create_eventCreate a new Google Calendar event
gcal_update_eventUpdate an existing Google Calendar event
gcal_delete_eventDelete a Google Calendar event
gcp_compute_listList GCP Compute Engine instances
gcp_compute_startStart a Compute Engine instance
gcp_compute_stopStop a Compute Engine instance
gcp_storage_listList Cloud Storage buckets
gcp_storage_uploadUpload file to Cloud Storage
gcp_functions_listList Cloud Functions
gcp_functions_deployDeploy a Cloud Function
gdrive_listList files and folders in Google Drive
gdrive_searchSearch Google Drive files by name or content. Supports Drive query syntax e.g. name contains "budget" mimeType="application/vnd.google-apps.spreadsheet"
gdrive_getGet metadata about a specific Drive file
gdrive_readgdrive_create_folderCreate a new folder in Google Drive
gdrive_upload_textUpload a text file to Google Drive
gdrive_deletePermanently delete a file from Google Drive
gh_my_reposList the authenticated user's own repositories
gh_workflow_runsList recent workflow runs for a repository
gh_run_statusGet the status and jobs of a specific workflow run
gh_trigger_workflowManually trigger a GitHub Actions workflow (workflow_dispatch)
gh_cancel_runCancel a running GitHub Actions workflow run
gh_list_prsList pull requests for a repository
gh_create_prCreate a new pull request
gh_merge_prMerge a pull request
gh_list_issuesList issues for a repository
gh_create_issueCreate a new GitHub issue
gh_commentAdd a comment to a GitHub issue or pull request
gh_releasesList releases for a repository
gh_create_releaseCreate a new GitHub release
gh_notificationsGet unread GitHub notifications (mentions, CI failures, reviews needed)
gh_code_searchSearch code across GitHub repositories
github_userGet GitHub user profile info
github_repoGet repository details
github_reposList repositories for a user
github_trendingSearch trending/popular repositories by query and optional language filter
github_issuesList issues for a repository with optional filters
github_issueGet a single issue by number
github_create_issueCreate a new issue in a repository
github_close_issueClose an open issue
171 further tools are not listed here. The complete surface is in the source.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Unsafe object property setter in mathjs
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
CONDUCTOR_GOOGLE_CLIENT_IDCONDUCTOR_GOOGLE_CLIENT_SECRETCONDUCTOR_GOOGLE_REDIRECT_URIGOOGLE_CLIENT_SECRETHOSTNAMELOG_LEVELTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
271/271 tools missing one or more hints — conductor_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); conductor_recent_activity (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); json_format (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +268 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
90/271 tools referenced in tests (33%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
4 calls in production code run through a shell (src/dashboard/cli.ts:25, src/security/keychain.ts:57, src/security/keychain.ts:72)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 4 high severity in production deps — mathjs@15.1.1 (high), mathjs@15.1.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
1/22 production deps stale: spotify-web-api-node@2022-06-26 (4.2y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/useconductor/conductor)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check