39
/ 100
12 days ago
github_topic

JanuScope

Local-first MCP policy proxy. Tool-block, SQL-mutation gate, PII redact, audit, rate-limit, OpenTelemetry, vault secrets, first-use quarantine, schema pre-inject. No hosted gateway. One YAML Lens wraps any MCP, 20 included (Postgres, MySQL, MongoDB, GitHub, Stripe, Snowflake, etc.). 84% fewer tokens, ~3x faster, holds PII leaks. AGPL or commercial.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: VAULT_TOKEN, OP_SERVICE_ACCOUNT_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 2 credentials: OP_SERVICE_ACCOUNT_TOKEN, VAULT_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

lowjs-yaml@4.1.0GHSA-h67p-54hq-rp68

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

lowjs-yaml@4.1.0GHSA-mh29-5h37-fv8m

js-yaml has prototype pollution in merge (<<)

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAWS_DEFAULT_REGION
configAWS_REGION"": "eu-west-2",
configJANUSCOPE_VERBOSE_SECRETS
🔐 secretOP_SERVICE_ACCOUNT_TOKEN${1pw://vaults/<v>/items/<i>/fields/<f>} (or a raw op://… after 1pw://) 1Password in env. Peer dep: npm install @1password/sdk.
configVAULT_ADDR${vault://<mount>/<path>#<field>} HashiCorp Vault (KV v2 by default) , VAULT_TOKEN in the process env. For KV v1 set VAULT_KV_VERSION=1. No SDK, uses fetch.
configVAULT_FETCH_TIMEOUT_MS
configVAULT_KV_VERSION${vault://<mount>/<path>#<field>} HashiCorp Vault (KV v2 by default) VAULT_ADDR, VAULT_TOKEN in the process env. For KV v1 set =1. No SDK, uses fetch.
🔐 secretVAULT_TOKEN${vault://<mount>/<path>#<field>} HashiCorp Vault (KV v2 by default) VAULT_ADDR, in the process env. For KV v1 set VAULT_KV_VERSION=1. No SDK, uses fetch.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/giancarloerra-januscope-hgrsov)](https://m8ven.ai/mcp/giancarloerra-januscope-hgrsov)
commit: 8925659b8bc69d0af0868cf205b8691983b34bb3
code hash: eaee9d2533795c9c12e1964d255753d0c79ea18e02dbc9c26e64ddb7ff454fd8
verified: 7/19/2026, 8:51:58 AM
view raw JSON →