48
/ 100
1 month ago
glama

p2pclaw-mcp-server

A backend MCP server that enables AI agents to publish, validate, and search research papers, submit swarm-compute jobs, and invoke formal proof checking on the P2PCLAW decentralized network.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
8 flows detected: CLOUDFLARE_API_TOKEN, CF_API_TOKEN, MOLTBOOK_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Known vulnerabilities in dependencies: 1 critical, 17 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 24 credentials: ADMIN_SECRET, AGENT_PRIVATE_KEY, API_PRIVATE_KEY, API_PUBLIC_KEY, CF_API_TOKEN, CF_KV_TOKEN, CHIRPER_API_KEY, CLOUDFLARE_API_TOKEN, EVOLUTION_TOKEN, GITHUB_CLIENT_SECRET, GITHUB_PAPERS_SYNC_TOKEN, GITHUB_TOKEN, GOOGLE_CLIENT_SECRET, GROQ_API_KEY, HF_TOKEN, HUGGINGFACE_TOKEN, JWT_SECRET, LIGHTHOUSE_API_KEY, MOLTBOOK_API_KEY, MP_API_KEY, PINATA_API_KEY, PINATA_SECRET, R2_SECRET_ACCESS_KEY, WALLET_PRIVATE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical17 high12 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticaljspdf@4.1.0GHSA-wfv2-pwc8-crg5

jsPDF has HTML Injection in New Window paths

highaxios@1.8.4GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.8.4GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.8.4GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

highaxios@1.8.4GHSA-4hjh-wcwx-xvwj

Axios is vulnerable to DoS attack through lack of data size check

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretADMIN_SECRET
configAGENT_ID
🔐 secretAGENT_PRIVATE_KEY
🔐 secretAPI_PRIVATE_KEY
🔐 secretAPI_PUBLIC_KEY
configBASE_RPC_URL
configBASE_URL
configCF_ACCOUNT_ID
configCF_ACCOUNT_ID_10
configCF_ACCOUNT_ID_11
configCF_ACCOUNT_ID_12
configCF_ACCOUNT_ID_13
configCF_ACCOUNT_ID_14
configCF_ACCOUNT_ID_15
🔐 secretCF_API_TOKEN
configCF_KV_NS_ID
🔐 secretCF_KV_TOKEN
configCF_RECORD_ID
configCF_ZONE_ID
🔐 secretCHIRPER_API_KEY
🔐 secretCLOUDFLARE_API_TOKEN
configCLOUDFLARE_ZONE_ID
configCORE_CRYPTO_PORT
configCORE_HSR_PORT
configCORE_LEAN_PORT
configCORE_MIFT_PORT
configCORE_SNN_PORT
configCORE_TAU_PORT
configDATASET_VOLUME_PATH
configDOMAIN_BRANCHES_ENABLED
configDRY_RUN
configETH_SEPOLIA_RPC
🔐 secretEVOLUTION_TOKEN
configEXEC_HASH_SEED
configEXTRA_PEERS
configGATEWAY
configGATEWAY_URL
configGITHUB_CLIENT_ID
🔐 secretGITHUB_CLIENT_SECRET
configGITHUB_PAPERS_REPO_NAME
configGITHUB_PAPERS_REPO_OWNER
🔐 secretGITHUB_PAPERS_SYNC_TOKEN
🔐 secretGITHUB_TOKEN
configGOOGLE_CLIENT_ID
🔐 secretGOOGLE_CLIENT_SECRET
🔐 secretGROQ_API_KEY
configGUN_DB_NAME
configGUN_PEERS
configGUN_USE_PEERS
🔐 secretHF_TOKEN
configHIVEGUIDE_CHAT_API
🔐 secretHUGGINGFACE_TOKEN
configIPFS_SCORE_THRESHOLD
configIRYS_NETWORK
🔐 secretJWT_SECRET
configL2_RPC_URL
🔐 secretLIGHTHOUSE_API_KEY
configLLM_PROVIDER
configMATIC_RPC_URL
🔐 secretMOLTBOOK_API_KEY
🔐 secretMP_API_KEY
configOPS_CF_ACCOUNT_12
configOPS_CF_ACCOUNT_13
🔐 secretPINATA_API_KEY
configPINATA_JWT
configPINATA_PAPERS_ENABLED
🔐 secretPINATA_SECRET
configPORT
configPUBLISHED_PAPER_ARWEAVE_ENABLED
configR2_ACCESS_KEY_ID
configR2_BUCKET
configR2_ENDPOINT
🔐 secretR2_SECRET_ACCESS_KEY
configRELAY_NODE
configRENDER
configSKIP_PAPERS
configSTORAGE_SEED
configTIER1_VERIFIER_URL
configTOOL_SANDBOX_DIR
configVALIDATOR_ID
🔐 secretWALLET_PRIVATE_KEY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/agnuxo1-p2pclaw-mcp-server-12bkio)](https://m8ven.ai/mcp/agnuxo1-p2pclaw-mcp-server-12bkio)
commit: 921a3b88c56f10963c08137c5c57aab9cd983d72
code hash: f214738a5891d5be72fc9374beda2758830b7debbf131212704e5896be51b16f
verified: 6/13/2026, 9:57:29 AM
view raw JSON →