74
/ 100
6 days ago
glama

codex-tencent-connectors

A MCP server plugin that integrates WeCom, QQ Mail, and Tencent Docs with OpenAI Codex, enabling operations like messaging, email management, and document editing through natural language.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 7 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
// known CVEs in dependencies1 critical7 high1 medium3 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticaltar@7.4.3GHSA-23hp-3jrh-7fpw

node-tar: Decompression/parse DoS via unlimited input

hightar@7.4.3GHSA-34x7-hfp2-rc4v

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

hightar@7.4.3GHSA-83g3-92jg-28cx

Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction

hightar@7.4.3GHSA-8qq5-rm4j-mr97

node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

hightar@7.4.3GHSA-8x88-c5mf-7j5w

node-tar: Negative tar entry size causes infinite loop in archive replace

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configWECOM_CLI_CONFIG_DIR可通过 WECOM_CLI_PATH 指定其他 wecom-cli。可通过 和 WECOM_CLI_TMP_DIR 修改其配置目录和临时目录。
configWECOM_CLI_PATH可通过 指定其他 wecom-cli。可通过 WECOM_CLI_CONFIG_DIR 和 WECOM_CLI_TMP_DIR 修改其配置目录和临时目录。
configWECOM_CLI_TMP_DIR可通过 WECOM_CLI_PATH 指定其他 wecom-cli。可通过 WECOM_CLI_CONFIG_DIR 和 修改其配置目录和临时目录。
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/fortytwoo-codex-tencent-connectors-z0oitq)](https://m8ven.ai/mcp/fortytwoo-codex-tencent-connectors-z0oitq)
commit: 998c26161d8229fe7ad78de04588b242945c3826
code hash: c9e5fb2228d99d189b4cc0ea7ade6ead4f6f5f0963d9fc8f8b06a44fca0d4ea1
verified: 7/25/2026, 8:41:28 AM
view raw JSON →