An MCP server for AI-assisted Glean connector development, enabling scaffolding, schema mapping, code generation, and testing of Glean connectors directly from your editor.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
js-yaml: YAML merge-key chains can force quadratic CPU consumption
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
process.env. You'll be asked to provide them before it can run.GLEAN_API_TOKEN— GLEAN_INSTANCE and belong in your connector project's .env file — create_connector generates a .env.example to get you started.GLEAN_CONNECTOR_TEMPLATE_PATH— No Path to a custom Copier template (defaults to copier-glean-connector in workspace)GLEAN_INSTANCE— and GLEAN_API_TOKEN belong in your connector project's .env file — create_connector generates a .env.example to get you started.GLEAN_PROJECT_PATH— No Default project directory; overridden by create_connectorGLEAN_WORKER_COMMAND— No Command to start the Python worker (default: uv run python -m glean.indexing.worker)GLEAN_WORKER_REQUEST_TIMEOUT— No Max seconds to wait for a worker JSON-RPC response (default: 30)GLEAN_WORKER_SHUTDOWN_TIMEOUT— No Seconds to wait for graceful worker shutdown before SIGKILL (default: 5)[](https://m8ven.ai/mcp/gleanwork-connector-mcp-14ckta)