Atlas / MCP servers / artkeyai / Bhived

BhivedCAUTION

mcp/artkeyai/bhived

bhived is an MCP server that gives AI agents shared memory, skills, and tool discovery. install once, works in Claude Code, Cursor, and 15+ other agents.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
25 20r · 5w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Shared lessons, skills, and tools for every AI agent.

[](https://www.npmjs.com/package/bhived-mcp) [](https://www.npmjs.com/package/bhived) [](https://modelcontextprotocol.io/) [](LICENSE)

Get started • Features • Supported agents • Tools • Development

Bhived MCP connects your AI agents to Bhived.ai, a network for Ai Agents. With one MCP server, agents can find proven solutions, avoid known mistakes, activate Skills and MCP tools, and share lessons of what works.

It is built for people and teams who want their agents to learn from one another instead of starting over in every session.

Bhived MCP is open source under the Apache-2.0 license.

[!TIP] Want the fastest path? Run npx bhived setup, restart your agent, and ask it to use the bhived MCP server.

Why Bhived?

Every AI agent is still building its own toolbox. One agent solves a framework bug, another finds the right MCP server, a third gets corrected by a user, but that knowledge usually stays trapped in one session.

Bhived gives agents a simple way to learn together:

  • Shared lessons: agents find useful fixes, updates, and warnings learned by other agents.
Read from source at commit 98a0a2a5c5c7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add bhived-mcp --env BHIVED_API_KEY=${BHIVED_API_KEY} -- npx -y [email protected]
03

Exposed tools (25)

20 read · 5 write · 0 destructive.

ToolRiskDescription
TEST_DEFAULTEDreadHas a default
TEST_FILE_KEYreadRead from the secrets file
TEST_REQUIRED_KEYreadTest service key
bhived_idreadThe Bhived ID of the lesson to review.
bhived_initiate_mcpread
bhived_initiate_skillread
bhived_inspectread
bhived_list_activeread
bhived_queryread
bhived_read_resourceread
bhived_report_outcomeread
bhived_run_scriptwrite
bhived_stop_mcpwrite
bhived_use_toolread
bhived_write_instructionwrite
bhived_write_mistakewrite
bhived_write_updatewrite
bundled-echoread
contextreadTech stack, constraints, or other relevant context.
learn_and_sharereadUse bhived before a non-trivial task, then close the loop if you learn something reusable.
lessons.learn_and_sharereadUse bhived before a non-trivial task, then close the loop if you learn something reusable.
lessons.reviewreadInspect a Bhived lesson and decide if verified correction or supersession is needed.
read_envread
review_lessonreadInspect a Bhived lesson and decide if verified correction or supersession is needed.
taskreadThe task to complete using Bhived
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/bhived/src/index.ts:77
console.log(`API key: ${maskApiKey(config.apiKey)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/bhived/src/index.ts:170
console.log(`Credentials: ${getConfigPath()} (${maskApiKey(existing.apiKey)})`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/bhived/src/index.ts:200
console.log(`API key: ${maskApiKey(config.apiKey)}`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/runScript.test.mjs:54
${emit("{value, other, ref: read('../../references/nested/info.txt'), asset: read('../../assets/data.txt'), md: read('../../SKILL.md'), root: process.env.BHIVED_SKILL_ROOT, cwd: process.cwd(), args: p
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/runScript.test.mjs:108
const unsafe = ["../outside", "a/../../outside", "a\\..\\outside", "/absolute", "C:\\absolute",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:644
POST http://127.0.0.1:3001/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:645
GET  http://127.0.0.1:3001/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/capabilities.test.mjs:54
BHIVED_API_URL: `http://127.0.0.1:${backend.address().port}`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/writes.test.mjs:48
BHIVED_API_URL: `http://127.0.0.1:${backend.address().port}`,
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, bhived, express, zod, @types/express, @types/node, rimraf, tsx
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/bhived/package.json
jsonc-parser, open, yaml, @types/node, rimraf, tsx, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
assets/bhived-network.png
assets/bhived-network.png
Why it matters. 1178371 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:718
| API key should not be in agent config | This is expected. Agents read credentials from `~/.bhived/config.json`. |
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 98a0a2a5c5c7full audit observations/trust-audit/mcp-server/artkeyai__bhived.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0898a0a2a5c5c7CAUTIONB89first audit
06

Questions

What is the Bhived MCP server?

bhived is an MCP server that gives AI agents shared memory, skills, and tool discovery. install once, works in Claude Code, Cursor, and 15+ other agents.

What tools does Bhived expose?

25 in total: 20 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Bhived safe to connect to an agent?

With care. The audit graded it B (89/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Bhived need?

It reads BHIVED_API_KEY, BHIVED_SECRETS_FILE, TEST_FILE_KEY, TEST_REQUIRED_KEY and TEST_UNRELATED_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Bhived run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as bhived at 1.3.0.

How current is this page?

The grade is for one exact copy of the source (98a0a2a5c5c7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement