72
/ 100
17 days ago
glama

VoiceLayer

VoiceLayer MCP server enables AI coding assistants to speak and hear via local, on-device speech-to-text and text-to-speech, with no cloud dependencies.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: QA_VOICE_WISPR_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configBRAINLAYER_DB
configQA_VOICE_CHUNKED_STT
configQA_VOICE_RECORDINGS_DIR
configQA_VOICE_SOCKET_PATH
configQA_VOICE_STT_BACKENDAuto-detected. Override with =whisperwisprauto.
configQA_VOICE_THINK_FILE
configQA_VOICE_TTS_RATE+0% Base speech rate
configQA_VOICE_TTS_VOICEen-US-JennyNeural edge-tts voice ID
configQA_VOICE_WHISPER_ACCELERATION
configQA_VOICE_WHISPER_COREML
configQA_VOICE_WHISPER_COREML_MODEL
configQA_VOICE_WHISPER_LANG
configQA_VOICE_WHISPER_MODELauto-detected Path to whisper.cpp GGML model
configQA_VOICE_WHISPER_SERVER_PORT
configQA_VOICE_WISPR_DB_PATH
🔐 secretQA_VOICE_WISPR_KEYWispr Flow Cloud (fallback) ~500ms + network Set env var
configSHELL
configVOICELAYER_CONTROL_LAYER_BASE
configVOICELAYER_DISABLE_CONTROL_LAYER_JOURNAL
configVOICELAYER_TTS_AUTH_TOKEN_FILE~/.voicelayer/daemon.secret Backward-compatible override for the shared Qwen3 daemon bearer secret file
configVOICELAYER_TTS_DAEMON_SECRET_FILE~/.voicelayer/daemon.secret Preferred override for the shared Qwen3 daemon bearer secret file
configVOICE_REVIEW_BATCH
configVOICE_REVIEW_BRAINLAYER_WT
configVOICE_REVIEW_CATEGORY
configVOICE_REVIEW_DECISIONS
configVOICE_REVIEW_DEEP_LITERT_MODEL
configVOICE_REVIEW_FFMPEG
configVOICE_REVIEW_FINISH_CMD
configVOICE_REVIEW_LITERT_MODEL
configVOICE_REVIEW_LITERT_URL
configVOICE_REVIEW_STT_VOCAB
configVOICE_REVIEW_TEMP_DIR
configVOICE_REVIEW_TIMEOUT_MS
configVOICE_REVIEW_TTS_RATE
configVOICE_REVIEW_TTS_VOICE
configVOICE_REVIEW_WEB_HOST
configVOICE_REVIEW_WEB_PORT
configVOICE_REVIEW_WHISPER_CLI
configVOICE_REVIEW_WHISPER_MODEL
configVOICELAYER_BAKEOFF_TTS_KOKORO_CMD
configVOICELAYER_BAKEOFF_TTS_QWEN3_CMD
configVOICE_COACH_WHISPER_CLI
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/etanhey-voicelayer-16pfbt)](https://m8ven.ai/mcp/etanhey-voicelayer-16pfbt)
commit: fe5a2965054949e61ec0aeb0ae7d3f11aad32557
code hash: e9487ee47e727fe0e6f80e91846fa510eb62b6027c4185577395aca38ecb5c4d
verified: 6/17/2026, 11:41:57 AM
view raw JSON →