46
/ 100
1 month ago
glama

Volterra Knowledge Engine

A read-only Model Context Protocol server that exposes a semantic knowledge base to AI agents via 27 tools. It enables querying of documents and data integrated from sources like Notion, SharePoint, HubSpot, and Slack.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
54 flows detected: N8N_API_KEY, SLACK_BOT_TOKEN, SUPABASE_SERVICE_ROLE_KEY. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 4 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 11 credentials: HUBSPOT_API_KEY, LOCAL_DB_PASSWORD, N8N_API_KEY, NOTION_API_KEY, OPENAI_API_KEY, SHAREPOINT_CLIENT_SECRET, SLACK_BOT_TOKEN, SUPABASE_ANON_KEY, SUPABASE_CLOUD_DB_PASSWORD, SUPABASE_CLOUD_SERVICE_KEY, SUPABASE_SERVICE_ROLE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies4 high2 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.25.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.25.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

highxlsx@0.18.5GHSA-4r6h-8v6p-xvw6

Prototype Pollution in sheetJS

highxlsx@0.18.5GHSA-5pgg-2g8v-p4x9

SheetJS Regular Expression Denial of Service (ReDoS)

lowmailparser@3.7.1GHSA-7gmj-h9xc-mcxc

mailparser vulnerable to Cross-site Scripting

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAMPECO_SLACK_CHANNEL_ID
configBATCH_CONCURRENCY
configBATCH_SIZE
configEMBEDDING_MODEL
🔐 secretHUBSPOT_API_KEY
configLOCAL_DB_HOST
configLOCAL_DB_NAME
🔐 secretLOCAL_DB_PASSWORD
configLOCAL_DB_PORT
configLOCAL_DB_USER
configLOG_FORMAT
configLOG_LEVEL
🔐 secretN8N_API_KEY
configN8N_API_URL
🔐 secretNOTION_API_KEY
🔐 secretOPENAI_API_KEY
configPII_DETECTION_ENABLED
configPII_REDACTION_MODE
configSHAREPOINT_CLIENT_ID
🔐 secretSHAREPOINT_CLIENT_SECRET
configSHAREPOINT_SITE_ID
configSHAREPOINT_TENANT_ID
🔐 secretSLACK_BOT_TOKEN
🔐 secretSUPABASE_ANON_KEY
🔐 secretSUPABASE_CLOUD_DB_PASSWORD
🔐 secretSUPABASE_CLOUD_SERVICE_KEY
configSUPABASE_CLOUD_URL
🔐 secretSUPABASE_SERVICE_ROLE_KEY
configSUPABASE_URL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/duhman-volterra-knowledge-engine-jovnbu)](https://m8ven.ai/mcp/duhman-volterra-knowledge-engine-jovnbu)
commit: 7d628f9dd67cd56f12a836db09411ef8f656c2da
code hash: c5f4c1da8b61a013b91bf314effbb02f8c51667c22fbe2b01fdf9970f49ecb26
verified: 6/12/2026, 11:33:01 AM
view raw JSON →