72
/ 100
25 days ago
glama

aion-mcp

An MCP server that provides a set of tools for driving the AION AI assistant stack and managing a home fleet over SSH, including fleet control, Kali security tools, and memory management.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 7 credentials: AION_SERVICE_TOKEN, AION_SESSION_TOKEN, FLEET_DRAYDEV_PASS, FLEET_GATEWAY_TOKEN, KALI_PASS, OPENAI_API_KEY, SONCHAT_ADMIN_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAION_DB_PATH
configAION_HOST/ AION_PORT aion-api 127.0.0.1 / 5000 AION Core Flask API
configAION_MODEL
configAION_PORTAION_HOST / aion-api 127.0.0.1 / 5000 AION Core Flask API
configAION_PUBLIC_API_PORT
🔐 secretAION_SERVICE_TOKENaion_api_chat — X-Aion-Service-Token for /api/service/chat; no user session needed. Required — chat is disabled if unset
🔐 secretAION_SESSION_TOKENsession-scoped aion tools — Value of the aion_token cookie after logging in; required for channels/activity/memory/admin/vast tools
configFLEET_DEPTH
configFLEET_DRAYDEV_HOST/ FLEET_DRAYDEV_USER / FLEET_DRAYDEV_PASS fleet derived / draygen / — draydev SSH; if no password/SSH string is configured the machine is skipped with a clear error
🔐 secretFLEET_DRAYDEV_PASSFLEET_DRAYDEV_HOST / FLEET_DRAYDEV_USER / fleet derived / draygen / — draydev SSH; if no password/SSH string is configured the machine is skipped with a clear error
configFLEET_DRAYDEV_SSH
configFLEET_DRAYDEV_USERFLEET_DRAYDEV_HOST / / FLEET_DRAYDEV_PASS fleet derived / draygen / — draydev SSH; if no password/SSH string is configured the machine is skipped with a clear error
configFLEET_EC2_SSH, FLEET_TIMEOUT_MS, FLEET_MAX_DEPTH fleet — / 180000 / 2 ec2 SSH string; per-run timeout; recursion guard on delegated fleet runs
configFLEET_GATEWAY_HOSTFLEET_GATEWAY_PORT (5100), (127.0.0.1), FLEET_GATEWAY_TTL_MS (120000),
configFLEET_GATEWAY_PORT(5100), FLEET_GATEWAY_HOST (127.0.0.1), FLEET_GATEWAY_TTL_MS (120000),
🔐 secretFLEET_GATEWAY_TOKENWrites are gated: if is set they require a matching x-fleet-token
configFLEET_GATEWAY_TTL_MSFLEET_GATEWAY_PORT (5100), FLEET_GATEWAY_HOST (127.0.0.1), (120000),
configFLEET_GATEWAY_WRITEheader (the status probe stays open); set =off to disable writes
configFLEET_MAX_DEPTHFLEET_EC2_SSH, FLEET_TIMEOUT_MS, fleet — / 180000 / 2 ec2 SSH string; per-run timeout; recursion guard on delegated fleet runs
configFLEET_TIMEOUT_MSFLEET_EC2_SSH, , FLEET_MAX_DEPTH fleet — / 180000 / 2 ec2 SSH string; per-run timeout; recursion guard on delegated fleet runs
configFOOOCUS_URL
configJENN_DB_PATH
configKALI_HOST/ KALI_USER / KALI_PASS / KALI_IMAGE kali 192.168.0.200 / draygen / — / kali-custom:latest KALI_PASS required; kali tools return an error if unset
configKALI_IMAGEKALI_HOST / KALI_USER / KALI_PASS / kali 192.168.0.200 / draygen / — / kali-custom:latest KALI_PASS required; kali tools return an error if unset
🔐 secretKALI_PASSKALI_HOST / KALI_USER / / KALI_IMAGE kali 192.168.0.200 / draygen / — / kali-custom:latest KALI_PASS required; kali tools return an error if unset
configKALI_USERKALI_HOST / / KALI_PASS / KALI_IMAGE kali 192.168.0.200 / draygen / — / kali-custom:latest KALI_PASS required; kali tools return an error if unset
configNEBULA_MODEL
configOLLAMA_HOST
configOLLAMA_PORT
🔐 secretOPENAI_API_KEY
configOPENAI_MODEL
configPORTAL_HOST
configPORTAL_PORT
🔐 secretSONCHAT_ADMIN_KEY
configSONCHAT_HOST
configSONCHAT_PORT
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/draygen-mcpbuilder-1ekhfb)](https://m8ven.ai/mcp/draygen-mcpbuilder-1ekhfb)
commit: 7d5fe76ea846bb945a5e43f6f009efd0eb256ce3
code hash: 772026f71f1e0dc2a3637386971fac952e6ba2eaade3fb89948d9aeece4458f6
verified: 7/6/2026, 10:37:17 AM
view raw JSON →