36
/ 100
1 month ago
glama

Agentic Control Framework (ACF)

AI-native orchestration layer with 80+ tools for task management, code editing, browser automation, terminal control, and persistent memory across CLI, local MCP, and cloud deployments.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
3 flows detected: GEMINI_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 17 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 4 credentials: GEMINI_API_KEY, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, SUPABASE_ANON_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies17 high13 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.7.2GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.7.2GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.7.2GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configACF_ENABLE_APPLESCRIPT1: enable AppleScript tests (macOS only)
configACF_ENABLE_BROWSER_TOOLS1: enable Playwright browser tests (macOS default)
configACF_INSTALL_ALLACF_INSTALL_SHARP=1 or =1: install optional sharp
configACF_INSTALL_SHARP1 or ACF_INSTALL_ALL=1: install optional sharp
configACF_PATHproject root override for bins
configACF_SKIP_PLAYWRIGHT1: skip heavy Playwright browser downloads
configACF_SKIP_POSTINSTALL1: skip all postinstall steps
configALLOWED_DIRSadditional allowed directories (path-delimited)
configAUTH_PORT
configBASE_URL
configBLOCKED_COMMANDS
configBROWSER_HEADLESS"": "false",
configBROWSER_TIMEOUT
configBROWSER_USER_DATA_DIR
configCOMMAND_TIMEOUT
configDEFAULT_SHELL"": "/bin/bash"
configFILE_WRITE_LINE_LIMIT
configGEMINI_API_ENDPOINT
🔐 secretGEMINI_API_KEYenable AI-backed tools (parsePrd, expandTask, reviseTasks)
configMCP_PROXY_URL
configREADONLY_MODEset to true to disable write operations
configSTRIPE_ENTERPRISE_PRICE_ID
configSTRIPE_PRO_PRICE_ID
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
🔐 secretSUPABASE_ANON_KEY
configSUPABASE_URL
configWORKSPACE_ROOTdefault workspace path used by CLI/MCP
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/futureatoms-agentic-control-framework-1t61g4)](https://m8ven.ai/mcp/futureatoms-agentic-control-framework-1t61g4)
commit: 25ad754a06fb6b62d318e976651a637db5b4939b
code hash: 75933dba782f4922d8bbcc4c115ada3eab4ec674c04fa6b893fd6608628d59fa
verified: 6/18/2026, 11:50:56 AM
view raw JSON →