33
/ 100
1 month ago
glama

MCP Security Framework

Enables creation of secure-by-default MCP servers with 5-layer validation to protect against injection, path traversal, and other attack vectors.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Tool descriptions don’t match what handlers do
1 tool describes read intent but its handler mutates — list-models (line 20: fs.appendFileSync(logFile, entry))
🚨
Known vulnerabilities in dependencies: 1 critical, 5 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 6 credentials: BFL_API_KEY, GOOGLE_GENAI_API_KEY, IDEOGRAM_API_KEY, KENPOM_PASSWORD, OPENAI_API_KEY, STABILITY_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical5 high1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@3.2.4GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

high@modelcontextprotocol/sdk@1.25.2GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

highminimatch@10.1.1GHSA-23c5-xmqv-rm74

minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions

highminimatch@10.1.1GHSA-3ppc-4f35-3m26

minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

highminimatch@10.1.1GHSA-7r86-cg39-jmmj

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALERT_WEBHOOK_URL
configBASE_DIR
🔐 secretBFL_API_KEY
configGIT_TIMEOUT
🔐 secretGOOGLE_GENAI_API_KEY
🔐 secretIDEOGRAM_API_KEY
configIMAGE_GEN_OUTPUT_DIR
configIMAGE_TIMEOUT
configKENPOM_EMAIL
🔐 secretKENPOM_PASSWORD
configMAX_AUDIT_ENTRIES
configMAX_DIR_ENTRIES
configMAX_FILE_SIZE
configMAX_REPORT_SIZE
configMAX_SEARCH_FILES
configMETRICS_RETENTION_MS
configMOCK_COUNTRY
🔐 secretOPENAI_API_KEY
configPDF_TIMEOUT
configPORT
🔐 secretSTABILITY_API_KEY
configTOOL_POLICIES_PATHCreate a tool-policies.json file in your project root or specify a path via the environment variable.
configVIDEO_TIMEOUT
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 10 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/aself101-mcp-secure-server-9kmf7v)](https://m8ven.ai/mcp/aself101-mcp-secure-server-9kmf7v)
commit: 6090701e8148d75ac9388c48af0cdb5ce57eceac
code hash: ad4238c7c73f191a4ac3616efdeae16f6df44cdb7a64171644675be1438e11dd
verified: 6/22/2026, 1:02:14 PM
view raw JSON →