QR code generation for AI agents with customizable size, error correction, and format options.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Drizzle ORM has SQL injection via improperly escaped SQL identifiers
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
process.env. You'll be asked to provide them before it can run.ADMIN_SECRET— (none) Secret for admin endpoints (X-Admin-Secret header)API_KEY— "": "your-api-key",BASE_URL— "": "https://api.qrforagent.com"DATABASE_URL— ./data/qr-agent.db SQLite file pathHOST— 0.0.0.0 Bind addressPORT— 3100 HTTP portRESEND_API_KEYRESEND_FROMSHORT_ID_LENGTH— 8 Length of generated short IDsSITE_URLSTRIPE_PRICE_ID— (none) Stripe Price ID for Pro planSTRIPE_SECRET_KEY— (none) Stripe API secret keySTRIPE_WEBHOOK_SECRET— (none) Stripe webhook signing secret[](https://m8ven.ai/mcp/benswel-qr-agent-core-1m71pp)