0
/ 100
1 month ago
github_topic

agent-afk

Start a run in your terminal and walk away. Get pinged when it finishes, or needs you. Every step is a readable trace you check before anything ships.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Hardcoded credentials detected
3 live-looking API keys in source: 1 AWS access key, 2 Slack token
🚨
Known vulnerabilities in dependencies: 2 critical, 1 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 4 credentials: AFK_RELEASE_THREADS_TOKEN, ANTHROPIC_API_KEY, OPENAI_API_KEY, TELEGRAM_BOT_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 critical1 high1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@2.1.8GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

criticalvitest@2.1.8GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

highplaywright@1.49.0GHSA-7mvr-c777-76hp

Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate

lowesbuild@0.28.0GHSA-g7r4-m6w7-qqqr

esbuild allows arbitrary file read when running the development server on Windows

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAFK_ALLOW_PROJECT_MCP
configAFK_CUSTOM_TEST_VAR
configAFK_DEBUG
configAFK_DISABLE_PATH_APPROVAL
configAFK_HOME
configAFK_MEMORY_EVIDENCE_GATE
🔐 secretAFK_RELEASE_THREADS_TOKEN
configAFK_RELEASE_THREADS_TOPIC_TAG
configAFK_TELEGRAM_ALLOWED_CHAT_IDSTelegram bot won't start — afk telegram status then afk telegram logs. Most common cause: missing after token setup.
configAFK_TRACE_DISABLED
configAFK_VISION_MODELS
🔐 secretANTHROPIC_API_KEYinvalid x-api-key / not found — run afk doctor. Confirm the key is set in your shell or in ~/.afk/config/afk.env.
🔐 secretOPENAI_API_KEY
configRELEASE_BRANCH
configSHELL
🔐 secretTELEGRAM_BOT_TOKEN1234567890:ABC...
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/griffinwork40-agent-afk-1ler4t)](https://m8ven.ai/mcp/griffinwork40-agent-afk-1ler4t)
commit: 0b2368a0149906cf33ffc63611835fe5d7e77942
code hash: 161c3023adb6ea267ab56d9982159a72b8662d591735145249abcb0be0edfc1c
verified: 6/25/2026, 9:48:31 AM
view raw JSON →