0
/ 100
1 month ago
glama

Accessibility MCP Server

Provides conversational, actionable accessibility testing for AI agents, including auditing, prioritization, and code-level fixes.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Code appears obfuscated
1 file are unreadable to a human reviewer. Cannot audit what they do.
⚠️
Known vulnerabilities in dependencies: 5 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
// known CVEs in dependencies5 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@0.5.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@0.5.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highplaywright@1.40.0GHSA-7mvr-c777-76hp

Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate

highxlsx@0.18.5GHSA-4r6h-8v6p-xvw6

Prototype Pollution in sheetJS

highxlsx@0.18.5GHSA-5pgg-2g8v-p4x9

SheetJS Regular Expression Denial of Service (ReDoS)

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configA11Y_ENGINEaxe, ace axe Testing engine: axe-core (Deque) or IBM Equal Access (ACE).
configBEST_PRACTICEStrue, false true Include best-practice rules (adds best-practice tag when no tags are provided).
configHEADLESS_BROWSERtrue, false true Run the browser in headless mode; set to false to show the browser window.
configSCREEN_SIZESComma-separated WIDTHxHEIGHT 1280x1024 Viewport size(s) for the browser (e.g. 1280x1024,320x640). The first size is used for audits.
configWCAG_LEVEL2.0_A, 2.0_AA, 2.0_AAA, 2.1_A, 2.1_AA, 2.1_AAA, 2.2_A, 2.2_AA, 2.2_AAA 2.1_AA WCAG version and level used when the tool does not specify tags.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/dallask-a11y-mcp-srv-b3tsuj)](https://m8ven.ai/mcp/dallask-a11y-mcp-srv-b3tsuj)
commit: 24197445b8954fc80dea5dac09de2f0f313537a9
code hash: ae66732653a3c91fef718bf77745efa8288e9eba9279fef0304804e64228fcca
verified: 6/11/2026, 11:53:30 AM
view raw JSON →