74
/ 100
11 hours ago
glama

gittr-mcp

MCP server for gittr.space, a decentralized Git platform on Nostr, enabling AI agents to create repos, push code, manage issues/PRs, and work with Lightning bounties using Nostr identity.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 1 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 2 credentials: GITTR_LNBITS_ADMIN_KEY, GITTR_LNBITS_INVOICE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configBRIDGE_URL"": "https://gittr.space"
configGENERAL_RELAYS
configGITTR_BOUNTY_SATS
configGITTR_DISABLE_GIT_MERGE
configGITTR_DISCOVERABILITY_TIMEOUT_MS
configGITTR_GIT_AUTH_HOSTS
🔐 secretGITTR_LNBITS_ADMIN_KEYOptional LNbits: set GITTR_LNBITS_URL and in MCP env (see .env.example).
🔐 secretGITTR_LNBITS_INVOICE_KEY
configGITTR_LNBITS_URLOptional LNbits: set and GITTR_LNBITS_ADMIN_KEY in MCP env (see .env.example).
configGITTR_MCP_FORGE_HASH_TIMEOUT_MS
configGITTR_MCP_MAX_RETRIES
configGITTR_MCP_MIN_REQUEST_GAP_MS
configGITTR_MCP_REQUEST_TIMEOUT_MS
configGITTR_MERGE_CLONE_DEPTH
configGITTR_PUBLISH_POST_PUSH_EVENTS
configGITTR_RELAY_VERIFY_TIMEOUT_MS
configGITTR_SKIP_MERGE_LIFECYCLE
configGITTR_TEST_FALLBACK_REPO
configGITTR_TEST_NSECnsec1... npm run test:live:matrix
configGITTR_TEST_PRIVKEY
configGITTR_TEST_RELAYS
configGITTR_TEST_REPO
configGRASP_SERVERS
configHAPPY_PATH_LIVE
configHAPPY_PATH_SKIP_BOUNTY
configMCP_BASE
configNIP34_RELAYS
configNSEC
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/arbadacarbayk-gittr-mcp-1cknw4)](https://m8ven.ai/mcp/arbadacarbayk-gittr-mcp-1cknw4)
commit: 341b09d3d59a69143629a36d9f36c5b3314d2417
code hash: cf2537e1d4efe112a1321a0ffd9819c9c5b992c4babc56893b9132755de4e5aa
verified: 7/31/2026, 9:13:22 AM
view raw JSON →
gittr-mcp · M8ven Trust Score | M8ven