59
/ 100
1 month ago
glama

Defense MCP

This is a Linux OS hardening tool. Take a fresh install and immediately harden the heck out of it using just your favourite LLM agent and natural language prompts. "Make my system secure" or "Do a full security audit of my system."

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Tool descriptions don’t match what handlers do
2 tools describe read intent but their handlers mutate — dns_security (line 203: dnsQueryRe.exec(line)); sudo_session (line 909: fs.writeFileSync(scriptPath, scriptLines.join("\n") + "\n", { mode: 0o700 }))
🚨
Known vulnerabilities in dependencies: 1 critical
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 1 credential: MCP_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@4.0.18GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configDEFENSE_MCP_ALLOWED_DIRS"": "/tmp,/home,/var/log"
configDEFENSE_MCP_ALLOWED_TOOLS
configDEFENSE_MCP_AUTO_INSTALLfalse node build/index.js
configDEFENSE_MCP_BACKUP_DIR
configDEFENSE_MCP_BACKUP_ENABLEDtrue Auto-backup before system changes
configDEFENSE_MCP_CHANGELOG_PATH
configDEFENSE_MCP_COMMAND_TIMEOUT
configDEFENSE_MCP_DRY_RUN"": "true",
configDEFENSE_MCP_LOG_FILE
configDEFENSE_MCP_LOG_LEVELinfo Log verbosity (debug/info/warn/error)
configDEFENSE_MCP_LOG_MAX_FILES
configDEFENSE_MCP_LOG_MAX_SIZE
configDEFENSE_MCP_MAX_OUTPUT_SIZE
configDEFENSE_MCP_NETWORK_TIMEOUT
configDEFENSE_MCP_POLICY_DIR
configDEFENSE_MCP_PREFLIGHTtrue Enable pre-flight dependency checks
configDEFENSE_MCP_PREFLIGHT_BANNERStrue Show pre-flight status in tool output
configDEFENSE_MCP_PROTECTED_PATHS
configDEFENSE_MCP_QUARANTINE_DIR
configDEFENSE_MCP_RATE_LIMIT_GLOBAL
configDEFENSE_MCP_RATE_LIMIT_PER_TOOL
configDEFENSE_MCP_RATE_LIMIT_WINDOW
configDEFENSE_MCP_READ_ONLY
configDEFENSE_MCP_REDACT_OUTPUT
configDEFENSE_MCP_REQUIRE_CONFIRMATIONtrue Require confirmation for destructive actions
configDEFENSE_MCP_RUNTIME_PATH_VERIFY
configDEFENSE_MCP_SUDO_TIMEOUT
configDEFENSE_MCP_THIRD_PARTY_INSTALLRequires explicit =true to enable
configDEFENSE_MCP_TIMEOUT_DEFAULT
configDEFENSE_MCP_TIMEOUT_LYNIS
configDEFENSE_MCP_TIMEOUT_NMAP
configDISPLAY
configLOGNAME
🔐 secretMCP_API_KEY
configMCP_PORT3100 HTTP server port (when MCP_TRANSPORT=http)
configMCP_TRANSPORTstdio Transport mode: stdio or http
configSSH_CONNECTION
configSSH_TTY
configSUDO_ASKPASS
configWAYLAND_DISPLAY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 9 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/bottobot-defense-mcp-server-odpyzn)](https://m8ven.ai/mcp/bottobot-defense-mcp-server-odpyzn)
commit: ccdc3f3be66fc9c964850f5eb0e9f33c7efe8580
code hash: 7a48c2d60f09a8e4e075c9d2ac82c77015e7e723a0bcb25649c7ce2b30c24d4f
verified: 6/12/2026, 10:57:55 AM
view raw JSON →