54
/ 100
6 days ago
glama

crosspad-mcp-server

MCP server that gives Claude Code full control over the CrossPad development workflow — build, test, manage app packages, interact with the simulator, search code across repos — all from natural language.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCROSSPAD_ARDUINO_ROOT$GIT_DIR/ESP32-S3 Arduino platform repo
configCROSSPAD_CORE_ROOT$GIT_DIR/crosspad-core crosspad-core (standalone)
configCROSSPAD_GIT_DIREach repo path is individually configurable via env vars. If not set, falls back to $/<repo-name> (flat layout).
configCROSSPAD_GUI_ROOT$GIT_DIR/crosspad-gui crosspad-gui (standalone)
configCROSSPAD_IDF_ROOTenv =/path/to/platform-idf \
configCROSSPAD_PC_ROOTenv =/path/to/crosspad-pc \
configCROSSPAD_PROBE_SERIAL
configCROSSPAD_REMOTE_HOST127.0.0.1 TCP host for simulator remote control
configCROSSPAD_REMOTE_PORT19840 TCP port for simulator remote control
configCROSSPAD_STM_ELF
configCROSSPAD_STM_ROOT
configCROSSPAD_TRACE_DIR
configCROSSPAD_TRACE_NO_BROWSER
configCROSSPAD_TRACE_OPEN_FALLBACK_MS
configCROSSPAD_TRACE_PYTHON
configCROSSPAD_TRACE_UI_OPEN
configDISPLAY
configIDF_PATHauto-detected (~/esp/esp-idf) ESP-IDF SDK path
configSTM32_PROG
configVCPKG_ROOT~/vcpkg (Linux) / C:/vcpkg (Win) vcpkg installation
configVCVARSALLVS2022 default MSVC vcvarsall.bat (Windows only)
configWAYLAND_DISPLAY
configXDG_CONFIG_HOME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/crosspad-crosspad-mcp-11gso3)](https://m8ven.ai/mcp/crosspad-crosspad-mcp-11gso3)
commit: bd6abbe34de1a2667e3a5901fd45304d082bfc44
code hash: ccbbb04f6db0b1b0a3cdd1edb47f4ce88f8e7ddacb60f28e55a21e11d12e3549
verified: 7/25/2026, 8:40:10 AM
view raw JSON →