Enables multiple Claude Code sessions to communicate and share results automatically, with optional orchestration for hands-off workflow coordination.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.BRIDGE_ADMIN— with =1 (your "control" session). Auto-driven sessions don't haveBRIDGE_AUTOSEND— no off 1 enables the Stop auto-send hookBRIDGE_BLOCK_GIT— Or narrow what's blocked with (a regex; e.g. allow commitBRIDGE_BLOCK_GIT_ALLBRIDGE_HOP— no 0 Loop-guard hop (set by the spawn driver)BRIDGE_PROJECT— the room name shopBRIDGE_ROLE— this session's nickname backendBRIDGE_ROOT— change the list, edit defaultOffRoles in <>/spawner.config.json.BRIDGE_SEND_TO— no Default recipient for auto-sendBRIDGE_SESSIONCLAUDE_CONFIG_DIR— $/settings.json when that env var is set (common for aCLAUDE_SESSION_IDTMUX_PANE[](https://m8ven.ai/mcp/devpark435-claude-session-bridge-1rj3xr)