Open-source control plane for Codex projects: Git-backed context, visible agent progress, scoped MCP access, resumable work, and safe handoffs.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
launch-editor vulnerable to command injection via the crafted request on Windows
vite: `server.fs.deny` bypass on Windows alternate paths
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Vite's server.fs.deny bypassed with /. for files under project root
process.env. You'll be asked to provide them before it can run.GIT_PUBLIC_BASEGIT_PUBLIC_DIRPORTPROJECT_OS_AGENT_TOKENPROJECT_OS_AI_BASEPROJECT_OS_AI_KEYPROJECT_OS_AI_MODELPROJECT_OS_ALLOWED_ORIGINSPROJECT_OS_APP_NAMEPROJECT_OS_AUDIT_NETWORK_METADATAPROJECT_OS_AUTH_PASSWORD— Production refuses to start without PROJECT_OS_AUTH_USER and .PROJECT_OS_AUTH_USER— Production refuses to start without and PROJECT_OS_AUTH_PASSWORD.PROJECT_OS_BASE_URLPROJECT_OS_COOKIE_PATHPROJECT_OS_DATA_DIRPROJECT_OS_DEV_NO_AUTH— true npm startPROJECT_OS_EMBEDDING_MODELPROJECT_OS_KB_DIRPROJECT_OS_KB_INDEXPROJECT_OS_KB_KEYSPROJECT_OS_PDF_FONTPROJECT_OS_PDF_FONT_FAMILYPROJECT_OS_PROJECT_IDPROJECT_OS_PUBLIC_BASEPROJECT_OS_SMTP_FROMPROJECT_OS_SMTP_HOSTPROJECT_OS_SMTP_PASSPROJECT_OS_SMTP_PORTPROJECT_OS_SMTP_SECUREPROJECT_OS_SMTP_USERSMTP_HOSTSMTP_PASSSMTP_PORTSMTP_SECURESMTP_USERVITE_API_TARGETVITE_BASE[](https://m8ven.ai/mcp/herry2059-project-os-for-codex-o1arcj)