74
/ 100
17 days ago
github_topic

project-os-for-codex

Open-source control plane for Codex projects: Git-backed context, visible agent progress, scoped MCP access, resumable work, and safe handoffs.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
2 tools verified — handlers match their declared behaviour
1 read-only tool verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 5 credentials: PROJECT_OS_AGENT_TOKEN, PROJECT_OS_AI_KEY, PROJECT_OS_AUTH_PASSWORD, PROJECT_OS_SMTP_PASS, SMTP_PASS
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high5 medium9 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highvite@5.3.5GHSA-c27g-q93r-2cwf

launch-editor vulnerable to command injection via the crafted request on Windows

highvite@5.3.5GHSA-fx2h-pf6j-xcff

vite: `server.fs.deny` bypass on Windows alternate paths

mediumvite@5.3.5GHSA-356w-63v5-8wf4

Vite has an `server.fs.deny` bypass with an invalid `request-target`

mediumvite@5.3.5GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

mediumvite@5.3.5GHSA-859w-5945-r5v3

Vite's server.fs.deny bypassed with /. for files under project root

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configGIT_PUBLIC_BASE
configGIT_PUBLIC_DIR
configPORT
🔐 secretPROJECT_OS_AGENT_TOKEN
configPROJECT_OS_AI_BASE
🔐 secretPROJECT_OS_AI_KEY
configPROJECT_OS_AI_MODEL
configPROJECT_OS_ALLOWED_ORIGINS
configPROJECT_OS_APP_NAME
configPROJECT_OS_AUDIT_NETWORK_METADATA
🔐 secretPROJECT_OS_AUTH_PASSWORDProduction refuses to start without PROJECT_OS_AUTH_USER and .
configPROJECT_OS_AUTH_USERProduction refuses to start without and PROJECT_OS_AUTH_PASSWORD.
configPROJECT_OS_BASE_URL
configPROJECT_OS_COOKIE_PATH
configPROJECT_OS_DATA_DIR
configPROJECT_OS_DEV_NO_AUTHtrue npm start
configPROJECT_OS_EMBEDDING_MODEL
configPROJECT_OS_KB_DIR
configPROJECT_OS_KB_INDEX
configPROJECT_OS_KB_KEYS
configPROJECT_OS_PDF_FONT
configPROJECT_OS_PDF_FONT_FAMILY
configPROJECT_OS_PROJECT_ID
configPROJECT_OS_PUBLIC_BASE
configPROJECT_OS_SMTP_FROM
configPROJECT_OS_SMTP_HOST
🔐 secretPROJECT_OS_SMTP_PASS
configPROJECT_OS_SMTP_PORT
configPROJECT_OS_SMTP_SECURE
configPROJECT_OS_SMTP_USER
configSMTP_HOST
🔐 secretSMTP_PASS
configSMTP_PORT
configSMTP_SECURE
configSMTP_USER
configVITE_API_TARGET
configVITE_BASE
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/herry2059-project-os-for-codex-o1arcj)](https://m8ven.ai/mcp/herry2059-project-os-for-codex-o1arcj)
commit: 3e6a63a9203aac04fbdf11a610da6417ba8af46f
code hash: c0f25fbf4c4983275e3abd18deac5610c0d3f0f04df70120bed733eb634132af
verified: 7/14/2026, 8:27:54 AM
view raw JSON →