zulip (windborne/zulipmcp) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 27 tools. No publisher has claimed this listing.

D
Caution
56/100

zulip

Run AI agents in Zulip as @mentionable bots — or wire into any MCP client.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

windborne

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// tools this server exposes27 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

set_context

Initialize the session context for a conversation. Call this once at the start of a session to set where you're chatting.

reply

Reply in the current session context.

listen

Wait for new messages in the current conversation (blocking).

end_session

End the current session gracefully. Writes a clean exit marker so the listener knows this was intentional.

list_streams

List all available Zulip streams/channels (public and private).

get_stream_topics

Get recent topics in a stream.

get_stream_members

Get the members of a stream/channel.

get_messages

Get messages from a stream/topic, or fetch context around a message ID.

get_message_by_id

Get a specific message by its ID.

get_message_link

Get a permalink for a Zulip message.

verify_message

Securely fetch a single message to verify its true sender and content.

send_message

Send a message to a specific stream and topic (fire-and-forget).

send_direct_message

Send a direct message (DM) to one or more users.

add_reaction

Add an emoji reaction to a message.

remove_reaction

Remove an emoji reaction from a message.

edit_message

Edit a message the bot previously sent.

move_messages

Move message(s) to a different topic and/or stream.

resolve_topic

Rename a topic silently to mark it resolved or unresolved.

list_emoji

Search custom emoji available on this Zulip server.

typing

Send a typing indicator in the current conversation. Call this before heavy tool work (code execution, searches, analysis) to let users know you're working. Do NOT call before reply() or listen() — only before stretches of work where you won't be posting for a while. Typing indicator auto-clears whe

stop_typing

Stop the typing indicator in the current conversation. Call this when you've finished working but aren't about to send a message (e.g. before listen(), or if you decided not to reply after all). Note: sending a message (reply/send_message) implicitly clears typing on the client side, so you don't ne

get_user_info

Get information about a Zulip user, including their full profile.

resolve_name

Look up a user's display name by substring before mentioning them.

get_subscribed_streams

Get streams the bot is subscribed to.

fetch_image

Fetch an image from Zulip and save it to a temp file for viewing.

fetch_file

Fetch any file from Zulip and save it locally.

upload_file

Upload a local file to Zulip and return markdown to embed it in messages.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configZULIPMCP_CACHE_DIROverride the disk cache directory (defaults to system temp dir).
configZULIP_MAX_MESSAGE_LENGTHChar limit above which send tools return an error instead of letting Zulip silently truncate. Defaults to 10000 (Zulip's default); set for realms with a custom cap.
configZULIP_RC_PATHAbsolute path to .zuliprc for direct MCP server use. Listener mode sets this for spawned sessions from --zuliprc; it does not read ambient ZULIP_RC_PATH as its own default.
configZULIPMCP_LOG_DIROverride the log directory (defaults to /tmp/zulipmcp_logs).
configSESSION_USER_EMAILEach session gets TRIGGER_MESSAGE_ID and set automatically so set_context() anchors to the @mention and hooks can identify the requester.
configTRIGGER_MESSAGE_IDEach session gets and SESSION_USER_EMAIL set automatically so set_context() anchors to the @mention and hooks can identify the requester.
configWORKSPACE_PATH
configSESSION_STREAMSESSION_TOPIC Topic for auto-init. Requires .
configSESSION_TOPICTopic for auto-init. Requires SESSION_STREAM.
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

27/27 tools missing one or more hints — set_context (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); reply (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); listen (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +24 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Destructive tools are labelled

1 tool perform destructive updates without destructiveHint — listen deletes at line 563 (_interrupt_path.unlink(missing_ok=True))

Add destructiveHint:true to any tool whose handler calls .delete(), .upsert(), .update(), unlink, rm, DELETE, DROP, REPLACE INTO, or any operation that overwrites existing data.

Tool inputs are validated

24/27 tool handlers declare input schemas (89%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 8/27 tool handlers wrap calls in try/catch (30%)

Wrap each tool handler body in try/catch and return a structured error response.

Tests exist

No test files found

Add tests that exercise each declared tool.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/windborne/zulipmcp?variant=verified)](https://m8ven.ai/mcp/windborne/zulipmcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: f8f0d51960bd262743514a2f7e2409538722a5fc
code hash: 9f8e043797277ac6b9578ddeb2dd6cc41a191f5419231273d97bef1eb78133a1
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client