Determines whether a deliverable meets its contract using deterministic rules, criteria, and signed attestations.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
ajv has ReDoS when using `$data` option
process.env. You'll be asked to provide them before it can run.HOSTNAMEOG_CHAIN_IDOG_PRIVATE_KEY— The 0G anchor key is , used to anchor digests only, neverOKX_API_KEY— The OKX SDK credentials (/SECRET_KEY/PASSPHRASE) are theOKX_BASE_URLOKX_PASSPHRASE— PORT=3100 OKX_API_KEY=… OKX_SECRET_KEY=… =… \OKX_SECRET_KEY— PORT=3100 OKX_API_KEY=… =… OKX_PASSPHRASE=… \OKX_SYNC_SETTLEPORT— 3100 npm startPUBLIC_BASE_URL— the prefix, so the x402 challenge advertises /mcp, neverRUBRIC_ARTIFACT_TTL_MS— Artifact TTL (ms) 600000RUBRIC_MAX_CRITERIA— Maximum criteria 100RUBRIC_MAX_INPUT_BYTES— Maximum input bytes 524288RUBRIC_MAX_SOURCES— Maximum sources 20RUBRIC_SIGNER_PRIVATE_KEY— The signer key is read from and is the ONLYX402_ASSETX402_CHAINX402_DOMAIN_NAMEX402_DOMAIN_VERSIONX402_FACILITATOR_URLX402_NETWORKX402_PAY_TO— 0x2a8efe3093278bb4bd3b2d9c7b5ba992ca4fc9b0 \X402_RPCX402_RPC_URLX402_SETTLE_KEY— The settle key () is the legacy self-hosted settlementX402_USE_FACILITATOR[](https://m8ven.ai/mcp/evidiq-evidiq-rubric-mcp-b2pitx)