39
/ 100
1 month ago
glama

Iron Cannon

An MCP-powered compliance copilot for SaaS stacks, enabling structured audit workflows including stack detection, module wiremapping, implementation directives, code verification, and security/infrastructure/legal readiness gates.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: CLOUDFLARE_API_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 3 credentials: CLOUDFLARE_API_TOKEN, IRON_CANNON_DEV_KEY, IRON_CANNON_REQUIRE_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 medium

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

mediumajv@8.17.1GHSA-2g4f-4pwh-qvx6

ajv has ReDoS when using `$data` option

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCLOUDFLARE_ACCOUNT_ID
🔐 secretCLOUDFLARE_API_TOKEN
configHARVEST_FETCH_LIMIT
configHARVEST_PUBLISH_MAX
configIRON_CANNON_API_KEYS
configIRON_CANNON_COMPLETED
🔐 secretIRON_CANNON_DEV_KEY
configIRON_CANNON_EXPECTED_RPS
configIRON_CANNON_EXPECTED_USERS
configIRON_CANNON_MARKETS
configIRON_CANNON_PROJECT_PATH
configIRON_CANNON_REPO_ROOT
🔐 secretIRON_CANNON_REQUIRE_API_KEY
configIRON_CANNON_SKIP_WIREMAP_GATE
configIRON_CANNON_TIERSet tier: =armor npm run ironcannon -- ...
configIRON_CANNON_URL
configIRON_CANNON_WIREMAP_ATT
configRULESET_VERSION
configVECTORIZE_INDEX_NAME
configVECTORIZE_UPSERT_BATCH
configVECTORIZE_UPSERT_LIMIT
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/dillonrich-iron-cannon-wt48ew)](https://m8ven.ai/mcp/dillonrich-iron-cannon-wt48ew)
commit: 3cd5c5962ca14ee1c0c9964c9e3e28c681805018
code hash: 8067bb22491614239a38d6916e720274e27b15c64099e68e1d97d4c929e49936
verified: 6/11/2026, 11:01:03 AM
view raw JSON →