C

npm:@akari-os/keymaster-mcp

https://www.npmjs.com/package/@akari-os/keymaster-mcp
74/100 · MCP Trust Grade · checked 5h ago · MCP 1.0.3

What it offers — 5 tools · Developer Tools

get_secret

Retrieve an API key from Vault via Keymaster. Returns the secret value for the given service and key name.

healthcheck

Check Keymaster connectivity and validate all known API keys against their service endpoints. Returns a full status report.

list_services

List all known services and their key names that can be used with get_secret.

list_secrets

List all available secret paths (service + key_name combinations) that can be retrieved via get_secret. Returns whether each key is verifiable against

rotate_secret

Rotate (replace) a secret in Vault. For security, this operation is not available through the read-only Keymaster proxy.

Spec / packaging20%100
Security (OWASP MCP)30%25
Maintenance / popularity20%92
Tool hygiene15%95
Transparency / provenance15%90

Findings

WARNMCP08 References sensitive file paths / environment secrets.
INFO Static analysis of npm package @akari-os/keymaster-mcp@1.0.3 (stdio server — no remote endpoint). Reliability/behavioral signals require running it; not measured.
Grade another server

We re-grade npm:@akari-os/keymaster-mcp on a schedule and alert your Slack/webhook the moment its tools change or its grade drops — rug-pull insurance for the connection.

Share this report card

A 1200×630 card with the grade + audit — drop it in a post, Slack, or your repo.

MCP Trust report card — npm:@akari-os/keymaster-mcp grade C
Share on X Open card image

Embed this grade

A live badge — it re-verifies itself and shows current stability. Static scorecards can't. Paste it in your README or site to show users you're independently audited.

MCP Trust Grade C · wmcp.sh
[![MCP Trust Grade C](https://wmcp.sh/mcp/grade/npm%3A%40akari-os%2Fkeymaster-mcp/badge.svg)](https://wmcp.sh/mcp/grade/npm%3A%40akari-os%2Fkeymaster-mcp)
<a href="https://wmcp.sh/mcp/grade/npm%3A%40akari-os%2Fkeymaster-mcp"><img src="https://wmcp.sh/mcp/grade/npm%3A%40akari-os%2Fkeymaster-mcp/badge.svg" alt="MCP Trust Grade C · wmcp.sh"></a>

Agents: check this before connecting

Add the wmcp.sh trust oracle as an MCP server and call grade_mcp_server / check_mcp_drift in your agent's pre-connection gate:

https://wmcp.sh/mcp/trust
How this grade is computed. An open, independent rubric — Spec conformance (20%), Security mapped to the OWASP MCP Top 10 (30%), Reliability (20%), Tool hygiene (15%), Transparency (15%) — run by connecting to the server and inspecting its real MCP surface. The grade is free and identical whether or not the operator pays. v1 uses static + spec signals from a single connection; continuous uptime, real latency, and annotation-truthing (declared readOnly vs observed behavior) layer on via the wmcp.sh proxy.