41
/ 100
10 days ago
glama

MS-MCP

Enables MCP clients to execute Materials Studio modeling and computation tasks via MaterialsScript runtime, with a local Dashboard for monitoring.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Tool descriptions don’t match what handlers do
2 tools describe read intent but their handlers mutate — ms_queue_status (line 1021: fs.mkdirSync(dir, { recursive: true })); ms_gui_find_cif_import_current (line 217: fs.mkdirSync(path.dirname(cifPath), { recursive: true }))
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: MS_MCP_DASHBOARD_TOKEN, MS_MCP_REMOTE_SSH_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.17.5GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.17.5GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.17.5GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configComSpec
configMS_INSTALL_ROOT
configMS_MCP_ALLOWED_CIF_HOSTS
configMS_MCP_ALLOW_ARBITRARY_SCRIPT
configMS_MCP_ALLOW_EXTERNAL_INPUTS
configMS_MCP_ALLOW_GUI_QUEUE
configMS_MCP_DASHBOARD_AUTOSTART
configMS_MCP_DASHBOARD_AUTO_OPEN
configMS_MCP_DASHBOARD_PORT
🔐 secretMS_MCP_DASHBOARD_TOKENThe Dashboard listens on loopback. Writes are disabled unless MS_MCP_DASHBOARD_WRITE=1; write mode also requires with at least 24 characters. Do not commit this token.
configMS_MCP_DASHBOARD_WRITEThe Dashboard listens on loopback. Writes are disabled unless =1; write mode also requires MS_MCP_DASHBOARD_TOKEN with at least 24 characters. Do not commit this token.
configMS_MCP_GUI_HEARTBEAT_STALE_MS
configMS_MCP_MAX_CIF_BYTES
configMS_MCP_MAX_OUTPUT_BYTES
configMS_MCP_MODEL_ROOT
configMS_MCP_MODEL_STAGING_ROOT
configMS_MCP_PROJECT_FOLDER
configMS_MCP_PROJECT_ROOT
configMS_MCP_REMOTE_JOBS_ROOT/absolute/path/to/Gateway/jobs
🔐 secretMS_MCP_REMOTE_SSH_KEYC:\path\to\private_key
configMS_MCP_REMOTE_SSH_TARGET
configMS_MCP_REMOTE_SSH_TIMEOUT_MS
configMS_MCP_STRUCTURE_SOURCE_POLICY
configMS_MCP_TIMEOUT_MS
configMS_MCP_WORK_ROOT
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/drye1109-ms-mcp-1rztip)](https://m8ven.ai/mcp/drye1109-ms-mcp-1rztip)
commit: 991a1b3ab2ad985529fb645dc82f47528a2a1297
code hash: 383a155446301ef0bbe0fee2a6a9ff32b693fd575a3089d89e53b591c82d9c8c
verified: 7/21/2026, 9:31:58 AM
view raw JSON →