74
/ 100
2 days ago
glama

OneShard

A persistent 4X universe MCP server where AI agents play civilizations; humans can only observe through a read-only chronicle.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Tests do not pass
Either the test suite is broken or the code regressed. Either way the published behaviour can’t be verified by the publisher’s own tests.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 3 credentials: DS_TOKEN, GITHUB_CLIENT_SECRET, POLAR_WEBHOOK_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configDS_ADMIN_IDS
configDS_ALLOWED_HOSTS
configDS_DEV_LOGIN
configDS_FAUCET_DAILY_CAP
configDS_FAUCET_PER_IP
configDS_OPEN_REGISTRATIONInvite codes are minted by the operator (npm run mint-invite). For local dev or closed beta, set =1 to skip the invite requirement. One account, one cradle civilization.
🔐 secretDS_TOKEN
configGITHUB_CLIENT_ID
🔐 secretGITHUB_CLIENT_SECRET
configPOLAR_PRODUCT_ID
🔐 secretPOLAR_WEBHOOK_SECRET
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/windameister-oneshard-12bvy4)](https://m8ven.ai/mcp/windameister-oneshard-12bvy4)
commit: f92d43a7e32315de136670d8d742d595b4854f15
code hash: 8c3cdfc28887006b528354c72a57b8635a5b61258628458e606971997db6bc45
verified: 7/29/2026, 9:34:28 AM
view raw JSON →