50
/ 100
28 days ago
official

Palmyr

Agent infra: email, phone, social, domains, VPS, wallets. Paid per-action via x402, no API key.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: HCLOUD_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🚨
Known vulnerabilities in dependencies: 1 critical, 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 14 credentials: ALLOW_INSECURE_SECRETS_KEY, ANTHROPIC_API_KEY, CAPSOLVER_API_KEY, CDP_API_KEY_SECRET, CLOUDFLARE_API_TOKEN, EXA_API_KEY, HCLOUD_TOKEN, NAMECHEAP_API_KEY, PALMYR_API_KEY, PALMYR_TOKEN, SVM_PRIVATE_KEY, TELNYX_API_KEY, WALLET_SECRET_KEY, X402_FACILITATOR_BEARER
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical2 high2 medium1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

critical@whiskeysockets/baileys@7.0.0-rc.9GHSA-qvv5-jq5g-4cgg

Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload

high@x402/svm@2.3.0GHSA-qr2g-p6q7-w82m

x402 SDK Security Advisory

highhttp-proxy-middleware@3.0.5GHSA-gcq2-9pq2-cxqm

http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`

medium@anthropic-ai/sdk@0.90.0GHSA-p7fg-763f-g4gf

Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool

mediumhttp-proxy-middleware@3.0.5GHSA-64mm-vxmg-q3vj

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretALLOW_INSECURE_SECRETS_KEY
configALLOW_TEST_DEPOSITS
🔐 secretANTHROPIC_API_KEY
🔐 secretCAPSOLVER_API_KEY
configCDP_API_KEY_ID
🔐 secretCDP_API_KEY_SECRET
🔐 secretCLOUDFLARE_API_TOKEN
configDRY_RUN
🔐 secretEXA_API_KEY
🔐 secretHCLOUD_TOKENRequired env vars: TELNYX_API_KEY, , NAMECHEAP_API_KEY, NAMECHEAP_API_USER
configI402_AGENTIC_MARKET_CATALOG_URL
configI402_AGENTIC_MARKET_REFRESH_MINUTES
🔐 secretNAMECHEAP_API_KEYRequired env vars: TELNYX_API_KEY, HCLOUD_TOKEN, , NAMECHEAP_API_USER
configNAMECHEAP_API_USERRequired env vars: TELNYX_API_KEY, HCLOUD_TOKEN, NAMECHEAP_API_KEY,
configNAMECHEAP_CLIENT_IP
configNO_COLOR
configPALMYR_API
🔐 secretPALMYR_API_KEY
configPALMYR_BASE_PROTECTED_RPC
configPALMYR_BASE_RPC
configPALMYR_BROWSER_PATH
configPALMYR_DATA_DIR
configPALMYR_DEFAULT_COUNTRY
configPALMYR_FROM_HOME
configPALMYR_JSONAgents: pipe stdout into jq, branch on $? against the [exit code table](cli/README.md#exit-codes). Force JSON on a TTY with --json or =1.
configPALMYR_KEYFILE
configPALMYR_MAX_USDC
configPALMYR_NO_PREFLIGHT
configPALMYR_PAY_WALLET
configPALMYR_POOL_ADMIN_WALLET
configPALMYR_SELF_HOSTED
configPALMYR_SOCIAL_PATH
🔐 secretPALMYR_TOKEN
configPALMYR_TRADING_KEYSTORE_PASSPHRASE
configPALMYR_TRADING_PATH
configPALMYR_VERSION
configPALMYR_WALLET_PASSPHRASE
configPALMYR_WALLET_PASSPHRASE_CURRENT
configPALMYR_WALLET_PATH
configPOOL_ADMIN_WALLETS
configPORT
configPROGRAMFILES
configPROGRAMFILES(X86)
configSOLANA_RPC_URL
🔐 secretSVM_PRIVATE_KEY
🔐 secretTELNYX_API_KEYRequired env vars: , HCLOUD_TOKEN, NAMECHEAP_API_KEY, NAMECHEAP_API_USER
configWALLET_KEYPAIR_PATH
🔐 secretWALLET_SECRET_KEY
🔐 secretX402_FACILITATOR_BEARER
configX402_FACILITATOR_URL
configX402_FACILITATOR_URL_INTERNAL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/0xartex-palmyr-asl3pb)](https://m8ven.ai/mcp/0xartex-palmyr-asl3pb)
commit: 53b5b9294f64df385887cee848e50032ec6a4ffd
code hash: e473df17937c955560c8e5006a18402ce6cfbfd8c28a8b157b2e00ce04886e95
verified: 7/3/2026, 9:48:35 AM
view raw JSON →