VesselAPI MCP Server (vessel-api/vesselapi-mcp) is an MCP server listed on the M8ven Trust Index. It scores 62 out of 100, grade C. It declares 24 tools. No publisher has claimed this listing.
Connect your AI assistant to real-time maritime data. Access vessel tracking, port activity, and maritime safety information through natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
vessel-api
Source: Glama · also listed on mcp.so
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
get_vessels_in_areaFind all vessels within a rectangular bounding box (latitude/longitude)
get_vessels_in_radiusFind all vessels within a radius (in nautical miles) of a point
search_portsSearch for ports by name, country, type, size, region, harbor size, or harbor use
get_portGet detailed information about a specific port by UN/LOCODE
get_port_inboundGet vessels heading to a specific port within an ETA arrival window
get_port_eventsGet port events (arrivals/departures) for a specific port
get_port_events_by_vesselGet port events (arrivals/departures) for a specific vessel
list_port_eventsList port events (arrivals/departures) globally with optional filters for time, country, port, vessel, or event type
search_port_events_by_portSearch port events by port name
search_port_events_by_vesselSearch port events by vessel name
get_vessel_last_port_eventGet the most recent port event (arrival or departure) for a vessel
list_emissionsList global vessel emissions data with optional year filter
get_navtex_messagesGet NAVTEX maritime safety messages (navigational warnings, weather forecasts)
search_vesselsSearch for vessels by name, IMO, MMSI, flag, type, callsign, year built, class society, or owner
get_vesselGet detailed information about a specific vessel
get_vessel_positionGet the current position of a vessel (latitude, longitude, speed, heading)
get_vessel_etaGet the estimated time of arrival for a vessel
get_vessel_classificationGet the classification details for a vessel (class society, surveys, hull info)
get_vessel_ownershipGet the ownership details for a vessel (owner, manager, operator)
get_vessel_emissionsGet emissions data for a vessel (CO2, fuel consumption)
get_vessel_inspectionsGet port state control inspections for a vessel
get_vessel_casualtiesGet marine casualty records for a vessel
get_vessel_inspection_detailGet detailed information about a specific vessel inspection
get_vessel_positions_batchGet positions for multiple vessels at once by MMSI or IMO numbers
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
tsup DOM Clobbering vulnerability
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
24/24 tools missing one or more hints — get_vessels_in_area (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_vessels_in_radius (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_ports (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +21 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/vessel-api/vesselapi-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check