Verified Publisher
Free trust score, a verified badge for your README, and your listing on M8ven.
Connect your repo through our read-only GitHub App and we re-verify it automatically on every change — public or private.
Connect with GitHub →Read-only, one click, revoke anytime. What we access →
We scan your repo for a Code Verified score (~2 min) and list it on the M8ven Trust Index. For our deepest verification, connect your repo through our read-only GitHub App: that makes you Live Monitored, re-verified automatically on every change. (Email confirmation alone earns the Claimed mark; repo proof earns Verified Publisher.)
We clone your repo into an isolated sandbox, run static analysis (~30–120s), and delete the clone before the scoring function returns. Source is never stored or used for training — only scoring results, check findings, tool manifest metadata, and the commit SHA we scanned. Full policy at /verified/source-handling.
Connect it through our read-only GitHub App (narrow read access, revocable in one click). That lets us verify private source and re-check it continuously — the same Live Verified badge as public repos.
Yes. Scroll to the "Already submitted this MCP? Manage your listing" section at the bottom of the form — enter the email you submitted with and we'll send an edit link.
No. Earning Verified Publisher requires two proofs: (1) clicking an email confirmation link, and (2) committing a .well-known/m8ven-publisher.txt file to the repo with a token we issue. Step 2 requires push access to the repo, so a non-owner gets stuck — they can submit the listing, but the badge never activates for them.