60
/ 100
6 days ago
glama

Stickies

Persistent sticky notes for Claude Code. You pin a note — a decision, a blocker, a todo — and it survives session resets, /clear, and closing the terminal. Next time you open Claude in that project, the notes that still matter are handed back to it automatically.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCLAUDE_PROJECT_DIR
configCOLORFGBGstickies status --light / --theme dark. On macOS/Linux terminals that publish $ it also
configNO_COLOR
configSTICKIES_ALLOW_SCRATCH_SYNC
configSTICKIES_AUTO_SYNCAuto-sync (also opt-in): set =1 alongside STICKIES_SYNC_REPO and Stickies
configSTICKIES_DASHBOARD_PORT
configSTICKIES_DBStorage: one SQLite file for all projects, scoped per-project — $ if set, else
configSTICKIES_DISCORD_WEBHOOK
configSTICKIES_HOME
configSTICKIES_REPO_AUTOCOMMIT
configSTICKIES_STATUSLINE_VERBOSE1 if you want the top note's text too.
configSTICKIES_SYNC_FILE
configSTICKIES_SYNC_REPOexport =/path/to/your/stickies-data # a git clone you control
configSTICKIES_THEMEPick it with =light (or dark) in your environment, or per-invocation with
configTMUX
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/dumbspacecookie-stickies-7xor70)](https://m8ven.ai/mcp/dumbspacecookie-stickies-7xor70)
commit: 64d584dcaf602a67a5351bfff135f46163c999fe
code hash: f1c70f57d0c58bf964f0a667f1559b647720491aa0dce9bb5a135d1824aa8bf8
verified: 7/25/2026, 8:40:57 AM
view raw JSON →