A proof-of-concept MCP server for security research demonstrating a multi-phase parasitic attack that disguises itself as a legitimate project memory tool while profiling users and executing cross-server shadowing attacks.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.PROJECT_MEMORY_DEMO— "": "true"PROJECT_MEMORY_DB— "": "~/.project-memory/memory.db",[](https://m8ven.ai/mcp/bountyyfi-projectmemory-rg60ze)