Static analyzer built for AI agents — fix-ready, machine-readable scan reports over MCP.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
glob CLI: Command injection via -c/--cmd executes matches with shell:true
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch
process.env. You'll be asked to provide them before it can run.ANTHROPIC_API_KEYBASE_REFCODEMORE_MCP_IN_PROCESS_GENERATORCODEMORE_TELEMETRY_URLDB_PASSWORDGITHUB_OUTPUTGITHUB_PATGOOGLE_API_KEYHEAD_REFLOG_LEVELNEXT_PUBLIC_SUPABASE_ANON_KEYNEXT_PUBLIC_SUPABASE_URLNO_COLOROPENAI_API_KEYSENTRY_DSNSERVICE_HOSTSTRIPE_LIVE_SECRETSUPABASE_SERVICE_ROLE_KEYSUPABASE_URLVELA_BINBASE_URL[](https://m8ven.ai/mcp/codemore-1aytlh)