Bridge that lets stdio-only MCP clients connect to remote MCP servers with OAuth and other auth support, enabling local clients to use remote, authorized MCP servers.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
undici WebSocket client vulnerable to denial of service via fragment count bypass
process.env. You'll be asked to provide them before it can run.MCP_REMOTE_CONFIG_DIR— mcp-remote stores all the credential information inside ~/.mcp-auth (or wherever your points to). If you're having persistent issues, try running:[](https://m8ven.ai/mcp/abluva-mcp-remote-1yy0dg)