43
/ 100
1 month ago
npm

duckpond-mcp-server

MCP server for multi-tenant DuckDB management with R2/S3 storage

jordanburke/duckpond· npm: duckpond-mcp-server· listed on npm
Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 6 credentials: DUCKPOND_BASIC_AUTH_PASSWORD, DUCKPOND_BEARER_TOKEN, DUCKPOND_JWT_SECRET, DUCKPOND_OAUTH_PASSWORD, DUCKPOND_R2_SECRET_ACCESS_KEY, DUCKPOND_S3_SECRET_ACCESS_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOW_MAJORpnpm release patch # or minor major (major needs )
configDUCKPOND_BASIC_AUTH_EMAIL
🔐 secretDUCKPOND_BASIC_AUTH_PASSWORD
configDUCKPOND_BASIC_AUTH_USERNAME
configDUCKPOND_BASIC_AUTH_USER_ID
🔐 secretDUCKPOND_BEARER_TOKEN
configDUCKPOND_BEARER_TOKEN_USER_ID
configDUCKPOND_CACHE_DIR
configDUCKPOND_CACHE_TYPE
configDUCKPOND_DATA_DIR
configDUCKPOND_DEFAULT_USER
configDUCKPOND_EVICTION_TIMEOUT
configDUCKPOND_JWT_EXPIRES_IN
🔐 secretDUCKPOND_JWT_SECRET
configDUCKPOND_MAX_ACTIVE_USERS
configDUCKPOND_MEMORY_LIMIT
configDUCKPOND_OAUTH_EMAIL
configDUCKPOND_OAUTH_ENABLED
configDUCKPOND_OAUTH_ISSUER
🔐 secretDUCKPOND_OAUTH_PASSWORD
configDUCKPOND_OAUTH_RESOURCE
configDUCKPOND_OAUTH_USERNAME
configDUCKPOND_OAUTH_USER_ID
configDUCKPOND_R2_ACCESS_KEY_ID
configDUCKPOND_R2_ACCOUNT_ID
configDUCKPOND_R2_BUCKET
🔐 secretDUCKPOND_R2_SECRET_ACCESS_KEY
configDUCKPOND_S3_ACCESS_KEY_ID
configDUCKPOND_S3_BUCKET
configDUCKPOND_S3_ENDPOINT
configDUCKPOND_S3_REGION
🔐 secretDUCKPOND_S3_SECRET_ACCESS_KEY
configDUCKPOND_STRATEGY
configDUCKPOND_TEMP_DIR
configDUCKPOND_THREADS
configDUCKPOND_UI_ENABLED
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/duckpond-mcp-server-oq1vjp)](https://m8ven.ai/mcp/duckpond-mcp-server-oq1vjp)
commit: cdca122115089e7556f868388d9ce3aef8a0b41a
code hash: e65024b7fe191a256ed33f78b8686a8962426549a73664eadc5d7e68648f5749
verified: 6/18/2026, 11:10:56 AM
view raw JSON →