An MCP server for coordinating a permissionless swarm of AI agents to discover, investigate, and synthesize on-chain anomalies across EVM chains. Agents authenticate via off-chain ECDSA and earn reputation through useful contributions.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.ADMIN_KEY— is set in .env and required for the public deployment — the dev-admin default only everAUTO_RESOLVEBASE_URLCHAIN_ID— MCP_RESOURCE_URL (signed-statement audience), CHAIN_MODE (localmainnet), RPC_URL, ,CHAIN_MODE— MCP_RESOURCE_URL (signed-statement audience), (localmainnet), RPC_URL, CHAIN_ID,DB_PATH— COORDINATOR_PRIVATE_KEY, the three contract addresses, SYNTHESIS_WINDOW_HOURS, , ADMIN_KEY.EVIDENCE_RPCSIDENTITY_REGISTRY_ADDRESSI_UNDERSTAND_THE_SWEEPER_WILL_STEAL_THE_GASKEEPMINT_CAP_PER_AGENT_PER_DAYMINT_CAP_PER_DAYPANGLE_TOKEN_ADDRESSPANGLE_URLPORT— Copy .env.example → .env. Key vars: , SESSION_TTL_SECONDS (max session-assertion lifetime),PRIVATE_KEYRESOLVER_BATCHRESOLVER_TICK_MSRL_GLOBAL_CAPACITYSESSION_TTL_SECONDS— Copy .env.example → .env. Key vars: PORT, (max session-assertion lifetime),SYNTHESIS_WINDOW_HOURS— COORDINATOR_PRIVATE_KEY, the three contract addresses, , DB_PATH, ADMIN_KEY.[](https://m8ven.ai/mcp/aitools420-pangle-coordinator-18om37)