swarm-mcp (Volpestyle/swarm-mcp) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.
MCP server that lets multiple coding-agent sessions on the same machine discover each other and collaborate through a shared SQLite database.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
Volpestyle
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
ajv has ReDoS when using `$data` option
esbuild enables any website to send any requests to the development server and read the response
AGENT_IDENTITYHERDR_FAKE_COMMANDHERDR_FAKE_LOGHERDR_FAKE_RUN_PANEHERDR_PANEHERDR_PANE_IDHERMES_HOST_HOMEHERMES_PROFILE_HOMEMERMAID_BACKGROUNDMERMAID_SCALEMERMAID_WIDTHSWARM_CC_AGENT_ROLESWARM_CC_IDENTITYSWARM_CODEX_AGENT_ROLESWARM_CODEX_IDENTITYSWARM_DB_PATHSWARM_DISPATCH_HARNESSSWARM_DISPATCH_SPAWNERSWARM_HARNESS_CLAUDESWARM_HARNESS_CODEXSWARM_HARNESS_HERMESSWARM_HARNESS_OPENCODESWARM_HERDR_BINSWARM_HERDR_MAX_PANES_PER_TABSWARM_HERDR_PARENT_PANESWARM_HERDR_SPLIT_DIRECTIONSWARM_HERMES_IDENTITYSWARM_HERMES_ROLESWARM_IDENTITYSWARM_MCP_ALLOW_CROSS_IDENTITYSWARM_MCP_ALLOW_UNLABELEDSWARM_MCP_BINLauncher-managed sessions may set to a real command such asSWARM_MCP_DEFAULT_ROOTSSWARM_MCP_DIRECTORYSWARM_MCP_FILE_ROOTSWARM_MCP_INSTANCE_IDWrites (require identity — pass --as <uuid prefix unique-label-substring> or set ; falls back to the sole live instance in scope):SWARM_MCP_LABELSWARM_MCP_LAUNCH_DIRSWARM_MCP_PERSONAL_ROOTSSWARM_MCP_PROFILE_DIRSWARM_MCP_SCOPEconst scope = process.env.;SWARM_OPENCODE_AGENT_ROLESWARM_PROTOCOL_STATE_RSSWARM_SPAWNERSWARM_WORKER_HARNESSTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
3/3 tools missing one or more hints — register (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); remove_instance (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); deregister (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint). OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
Only 1/3 tool handlers declare input schemas (33%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool test coverage
2/3 tools referenced in tests (67%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
68 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 1 high severity in production deps — @modelcontextprotocol/sdk@1.25.2 (high), ajv@8.17.1 (medium)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dev dependencies
1 critical/high in dev-only deps (does not ship to users)
Upgrade dev dependencies when convenient.
Dependency freshness
1/6 production deps stale: ajv-formats@2024-03-30 (2.2y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/volpestyle-swarm-mcp-12vhyt)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check