62
/ 100
1 month ago
glama

nodebench-mcp

NodeBench MCP server provides public research memory and tool access for entity intelligence, enabling agents to perform deep research, generate reports, and track entities without requiring signup.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
4 flows detected: ANTHROPIC_API_KEY, OPENAI_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🚨
Known vulnerabilities in dependencies: 1 critical, 4 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 13 credentials: ANTHROPIC_API_KEY, GEMINI_API_KEY, GITHUB_TOKEN, GOOGLE_AI_API_KEY, GOOGLE_GENERATIVE_AI_API_KEY, MCP_SECRET, OPENAI_API_KEY, OPENBB_API_KEY, OPENBB_MCP_AUTH_TOKEN, OPENROUTER_API_KEY, RESEARCH_API_KEY, TWILIO_AUTH_TOKEN, XAI_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical4 high3 medium10 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@2.1.5GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

high@modelcontextprotocol/sdk@1.17.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.17.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highstorybook@9.1.10GHSA-8452-54wp-rmv6

Storybook manager bundle may expose environment variables during build

highstorybook@9.1.10GHSA-mjf5-7g4m-gx5w

Storybook Dev Server is Vulnerable to WebSocket Hijacking

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretANTHROPIC_API_KEY
configAPI_FETCH_USER_AGENT
configAPI_KEYS
configAPI_PORT
configCONVEX_CALL_TIMEOUT_MS
configCONVEX_DEPLOYMENT
configCONVEX_URL
configCORE_AGENT_MCP_SERVER_URL
configCORE_AGENT_MCP_URL
configCORS_ORIGINS
🔐 secretGEMINI_API_KEY
🔐 secretGITHUB_TOKEN
🔐 secretGOOGLE_AI_API_KEY
🔐 secretGOOGLE_GENERATIVE_AI_API_KEY
configINGESTION_BASE_URL
🔐 secretMCP_SECRET
🔐 secretOPENAI_API_KEY
🔐 secretOPENBB_API_KEY
🔐 secretOPENBB_MCP_AUTH_TOKEN
configOPENBB_MCP_SERVER_URL
configOPENBB_MCP_URL
🔐 secretOPENROUTER_API_KEY
🔐 secretRESEARCH_API_KEY
configRESEARCH_MCP_SERVER_URL
configRESEARCH_MCP_URL
configSCRATCHNODE_CUE_LLM_DISABLED
configTSFM_BASE_URL
configTWILIO_ACCOUNT_SID
🔐 secretTWILIO_AUTH_TOKEN
configTWILIO_PHONE_NUMBER
configVITE_CONVEX_URL
🔐 secretXAI_API_KEY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/homenshum-nodebench-ai-15c769)](https://m8ven.ai/mcp/homenshum-nodebench-ai-15c769)
commit: 9d6bf190bf1ee4328294a7951884dbffc88a9b81
code hash: 94e9681b98135cc3426845c83fafb70915792d3d6f3519ea8b214dcb815a13df
verified: 6/13/2026, 10:20:40 AM
view raw JSON →