A read-only MCP server that exposes a materials distributor database with four tools for querying tables, describing schemas, sampling rows, and running SELECT queries, secured by three independent layers to prevent any write operations.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
process.env. You'll be asked to provide them before it can run.CAMINHO_EVALS— $env:="C:\caminho\para\EVAL-QUESTIONS.md"; npm run coberturaDATABASE_URL_READONLY— que tem SELECT e mais nada. Vive na .DATABASE_URL_WRITE— Só com definida:MCP_HTTP_HOST— o servidor liga-se a 127.0.0.1 por omissão — mudar isso comMCP_HTTP_ORIGENS— as que a listar). Não é autenticação: é a proteção contra DNSMCP_HTTP_PORT— 3000 Porto do endpoint MCP (só no modo HTTP)MCP_LIMITE_AUTOMATICO— 200 LIMIT acrescentado a queries sem umMCP_LIMITE_MAXIMO— 500 LIMIT explícito máximo aceiteMCP_TIMEOUT_MS— 5000 statement_timeout por query (leitura e escrita)[](https://m8ven.ai/mcp/goncalosdev-mcpteste-k7t9ok)