troth (xgre1/troth) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.

C
Emerging
74/100
21 days ago

troth

A persistent AI partner MCP server that keeps identity, memory, goals and refusals in a local SQLite substrate, renting language work from Claude, ChatGPT, Kimi, local models or any BYOK OpenAI-compatible provider, with governed shell/fs/http tools, MCP "hands" gated by state-transition-validated cognition, loopback-only security, and tamper-evident audit.

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

xgre1

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 3 credentials: ANTHROPIC_API_KEY, GEMINI_API_KEY, TROTH_KIMI_SUB_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretANTHROPIC_API_KEY
configANTHROPIC_BASE_URL
configCHAMELEON_TENANT_ID
configCLAUDE_CWD
configCLAUDE_PLUGIN_DATA
configCLAUDE_PLUGIN_ROOT
configCLAUDE_SESSION_ID
configCOLORTERM
configDEV_SEND_CWD
🔐 secretGEMINI_API_KEY
configGF_BACKEND_HOST
configGF_BACKEND_PORT
configGF_BIND_HOST
configGF_HOST
configGF_PORT
configGF_REQUEST_MAX_MS
configGF_STANDALONE_BIND
configGF_STANDALONE_PORT
configGF_WATCH_DIR
configLD_LIBRARY_PATH
configPROGRAMFILES
configRERANK
configSHELL
configSTATE_DB_PATH
configTERM
configTROTH_AGENT_ID
configTROTH_ANTHROPIC_MODEL
configTROTH_APPLE_CONTAINER_BIN
configTROTH_APPLE_CONTAINER_IMAGE
configTROTH_AUTOSTART_WATCHER
configTROTH_BACKFILL_DOCS
configTROTH_BACKFILL_HOME
configTROTH_BASH_CWD
configTROTH_BENCH_BOOST
configTROTH_BENCH_CWD
configTROTH_BODY_CONTROL_CHANNEL
configTROTH_BROWSER_CDP_HOST
configTROTH_BROWSER_CDP_PORT
configTROTH_BROWSER_HEADLESS
configTROTH_CHAT_CTX
configTROTH_CHAT_DIR
configTROTH_CHAT_MODEL
configTROTH_CLAUDE_ENGINE
configTROTH_CLAUDE_MCP
configTROTH_CLAUDE_USAGE_INGEST
configTROTH_CODELENS_MAX_FILES
configTROTH_CODELENS_MAX_MS
configTROTH_CONFIG_DIR
configTROTH_CONFIG_PATH
configTROTH_CONTROL_CHANNEL_PORT
configTROTH_CONTROL_CHAT_TIMEOUT_MS
configTROTH_CWD
configTROTH_DATA_DIR
configTROTH_DB_PATH
configTROTH_DEBUG
configTROTH_DEBUG_PAYLOAD
configTROTH_DISABLE_AUTO_ENGRAM
configTROTH_DOCKER_SANDBOX_IMAGE
configTROTH_DUE_MIN_CADENCE_MS
configTROTH_EMBEDDING_HOST
configTROTH_EMBED_DIR
configTROTH_EMBED_HOST
configTROTH_EMBED_PORT
configTROTH_ENGRAM_AUTO_VERIFY
configTROTH_ENTITY_AGENTIC
configTROTH_ENTITY_AGENT_ID
configTROTH_ENTITY_AUTO_WRITE
configTROTH_ENTITY_BACKBONE
configTROTH_ENTITY_CWD
configTROTH_ENTITY_DAEMON
configTROTH_ENTITY_DISPATCH_PREFER
configTROTH_ENTITY_FALLBACK_ALLOW
configTROTH_ENTITY_HEARTBEAT_MS
configTROTH_ENTITY_LLM
configTROTH_ENTITY_LLM_FACULTIES
configTROTH_ENTITY_LLM_PIN
configTROTH_ENTITY_MODEL
configTROTH_ENTITY_STATE_FILE
configTROTH_ENTITY_USER_ID
configTROTH_EXIT_WITH_PID
configTROTH_FACULTY
configTROTH_FACULTY_EMIT_MODE
configTROTH_FIDELITY_RULES
configTROTH_FIXED_UI
configTROTH_GEMINI_IMAGE_MODEL
configTROTH_GPT_VIA_PROXY
configTROTH_HOLD_SIGNER
configTROTH_KEEP_SIBLINGS
🔐 secretTROTH_KIMI_SUB_KEY
configTROTH_KIMI_SUB_MODEL
configTROTH_LLAMACPP_HOST
configTROTH_LLAMACPP_MODEL
configTROTH_LLAMACPP_RELEASE
configTROTH_LLAMA_SERVER_BIN/path/to/llama-server. Apple Silicon gets Metal
configTROTH_LLM_TIMEOUT_MS
configTROTH_LOCAL_PORT
configTROTH_LOCAL_SERVER_PORT
configTROTH_LOG_FILE
configTROTH_MAINTENANCE
configTROTH_MAINT_IDLE_MS
configTROTH_MAINT_TICK_MS
configTROTH_MCP_ACTIONS
configTROTH_MCP_CLIENTS_CONFIG
configTROTH_MCP_PENDING_CONFIG
configTROTH_MEMORY_DIRS
configTROTH_MODEL_IDLE_MIN
configTROTH_NO_MODEL_FETCHservers): set =1 and, to pin your own binary,
configTROTH_OPERATOR_FACTS_JSON
configTROTH_OPERATOR_PASSPHRASE
configTROTH_OPERATOR_PASSPHRASE_NEW
configTROTH_OPERATOR_PUBKEY_B64
configTROTH_OPERATOR_PUBKEY_ID
configTROTH_PARENT_PID
configTROTH_PARTNER_CHARTER
configTROTH_PARTNER_WIPE_CONFIRM
configTROTH_PROXY_URL
configTROTH_RECOVERY_PASSPHRASE
configTROTH_REPLAY_EXECUTE
configTROTH_REPLAY_PLAN_THRESHOLD
configTROTH_REPO
configTROTH_RERANK_PORT
configTROTH_ROUTER_CONFIG
configTROTH_RUNS_DIR
configTROTH_SEARCH_URL
configTROTH_SELF_REAP_GRACE_MS
configTROTH_SELF_REAP_MS
configTROTH_SELF_REAP_PATH
configTROTH_STVC_BYPASS
configTROTH_SUCCESSOR_PASSPHRASE
configTROTH_TAINT_STRICT
configTROTH_TENANT
configTROTH_VAULT_PATH
configTROTH_WATCH_DIR
configTROTH_WATCH_POLL_MS
configTROTH_WATCH_RECURSIVE
configTROTH_WATCH_SCOPE
configTROTH_WEB_ALLOWLIST_PATH
configTROTH_WEB_MAX_CHARS
configTROTH_WEB_NAV_WAIT_MS
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

55/55 tools missing one or more hints — run (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); cd (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); pwd (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +52 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

27/55 tools referenced in tests (49%)

Write tests that reference each tool by name so every tool has at least one test.

Shell command execution

122 child_process/subprocess calls in production code — runs shell commands (plugin/mcp-servers/troth-bash/server.mjs:243, plugin/mcp-servers/troth-bash/server.mjs:245, plugin/mcp-servers/troth-cache/server.mjs:240)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Secrets not written to files

2 secret values written to files

Avoid persisting secrets to disk. Keep them in memory or your secret manager.

Secrets not logged

2 secret values sent to console.log

Redact or omit secret values from log output.

No arbitrary install scripts

Has postinstall/preinstall script — runs arbitrary code on npm install

Remove postinstall/preinstall hooks unless they’re essential.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/xgre1-troth-bhuwbk)](https://m8ven.ai/mcp/xgre1-troth-bhuwbk)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: ae8ba71d072d5afb68d58a3487a6922ad88dfb79
code hash: ca07ab3427218804f961010c113dc7f4d369cf3b8672f1d7a43c514c49a3c12b
verified: 8/10/2026, 4:11:33 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client