A deception-based threat detection server that impersonates enterprise MCP integrations to log and forward attacker interactions to SIEM systems. It provides convincing fake responses across 38 tools while capturing forensic details of all MCP tool calls.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.DASHBOARD_TOKEN— _(unset)_ Optional bearer token for /api/ and dashboard data access. MCP decoy endpoints stay unauthenticatedPORT— 3110 TCP port the Express server binds toSERVER_NAME— enterprise-integrations MCP serverInfo.name sent to clients during handshake[](https://m8ven.ai/mcp/gweber-mcp-decoy-1c4rca)