An MCP server that acts as an AI collections agent for Australian tradies and SMEs, enabling automated chasing of overdue invoices, payment plans, and payments through a secure permissions engine.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Wrangler affected by OS Command Injection in `wrangler pages deploy`
process.env. You'll be asked to provide them before it can run.ADMIN_KEY— H "Authorization: Bearer <your from .dev.vars>"ANTHROPIC_API_KEY— your key> ADMIN_KEY=<your ADMIN_KEY> npm run a2aBASE_URL— "$PROD_URL" ADMIN_KEY="$ADMIN_KEY" npm run smokePINCH_API_BASEPINCH_AUTH_URLPINCH_PUBLISHABLE_KEY— wrangler secret put # paste the Application ID (app_test_...)PINCH_SECRET_KEY— wrangler secret put # paste sk_test_...PINCH_VERSION[](https://m8ven.ai/mcp/bytestudiosaus-settlemate-dmo315)