A local MCP server that turns AI clients into power users of local git repositories, enabling clone, browse, search, and inspect code without burning API tokens.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
simple-git is vulnerable to Remote Code Execution
simple-git Affected by Command Execution via Option-Parsing Bypass
process.env. You'll be asked to provide them before it can run.GITHUB_TOKEN— MCP_GITHUB_TOKEN / unset Token injected into HTTPS GitHub URLs at clone time (never stored in settings.json)MCP_CLONE_DEPTH— 0 (full history) Default shallow-clone depth applied when add_repo doesn't pass an explicit depthMCP_DEBUG— unset When 1 / true / yes, logs each tool call + duration to stderrMCP_GITHUB_TOKEN— / GITHUB_TOKEN unset Token injected into HTTPS GitHub URLs at clone time (never stored in settings.json)MCP_MAX_REPO_BYTES— 2 GB Warn threshold after add_repo; informational only, doesn't fail[](https://m8ven.ai/mcp/az-ka-my-local-mcp-n4ai0g)