Enforces authorize-before-execute for any MCP-compatible AI agent. Exposes atlasent_evaluate and atlasent_verify_permit tools so a protected tool call only runs after AtlaSent issues and verifies a signed, single-use permit — fail-closed on any error, timeout, or malformed response.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.ATLASENT_ALLOW_LOCAL_MODE_IN_PRODATLASENT_ANON_KEY— no — Optional x-anon-key headerATLASENT_API_KEY— ask_live_xxx \ATLASENT_BASE_URL— defaults to https://api.atlasent.io/functions/v1. You can omit it unless you are on a self-hosted deployment.ATLASENT_BEHAVIOR_API_KEYATLASENT_BEHAVIOR_BASE_URLATLASENT_MCP_HTTP_BEARERATLASENT_MCP_HTTP_HOSTATLASENT_MCP_HTTP_MAX_BODYATLASENT_MCP_HTTP_PATHATLASENT_MCP_HTTP_PORTATLASENT_MCP_RATE_LIMIT— no 600 Per-tool calls per minute (token bucket)ATLASENT_MCP_READONLY— 1 is recommended for any live-API demo — see [Read-only mode](#read-only-mode-for-live-demos) below.ATLASENT_MCP_TRANSPORTATLASENT_MODE— local =local, or both ATLASENT_API_KEY and ATLASENT_BASE_URL are unset Runs a small in-process rules engine (src/localEngine.ts) — no network, no credentialsATLASENT_SANDBOX_ORG_IDATLASENT_SUPABASE_SERVICE_ROLE_KEYATLASENT_SUPABASE_URLATLASENT_SUPPRESS_BASE_URL_WARNINGATLASENT_SUPPRESS_LOCAL_MODE_WARNING[](https://m8ven.ai/mcp/atlasent-systems-inc-atlasent-mcp-server-13ik4k)