Enables authenticated ROAST users to view their dashboard, profiles, photoshoots, and images via MCP tools.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
vite: `server.fs.deny` bypass on Windows alternate paths
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Vite: `server.fs.deny` bypassed with queries
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
process.env. You'll be asked to provide them before it can run.APP_DOMAIN— public domain for rendered views.AUTH0_AUDIENCE— Auth0 API audience used for MCP access tokens.AUTH0_DOMAIN— Auth0 tenant domain.AUTH_REQUIRED_SCOPESROAST_API_BASE_URL— ROAST backend API base URL.ROAST_API_BEARER_TOKEN— backend-to-backend token accepted by ROAST.ROAST_LOGIN_URLROAST_MCP_AUTH_MODE— Use =auth0.ROAST_MCP_DEV_EMAILROAST_MCP_DEV_TOKEN— dev-roast-tokenROAST_MCP_DEV_USER_FIREBASE_ID— existing-roast-user-firebase-id>ROAST_USER_ID_CLAIM— 1. , defaulting toSERVER_URL— public Skybridge server URL.[](https://m8ven.ai/mcp/benoib-roast-mcp-app-18nmej)