60
/ 100
1 month ago
glama

SecureContext

Provides persistent memory, cryptographic audit trail, and HMAC-verified skill admission for Claude Code, running locally on PostgreSQL with zero cloud sync.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 8 credentials: ANTHROPIC_API_KEY, API_KEY, GH_TOKEN, SC_API_KEY, ZC_API_KEY, ZC_MACHINE_SECRET, ZC_POSTGRES_PASSWORD, ZC_SAVINGS_AVG_COST_PER_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highfastify@5.8.4GHSA-247c-9743-5963

Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretANTHROPIC_API_KEY
🔐 secretAPI_KEY
configAPI_URL
configAWS_ACCESS_KEY_ID
🔐 secretGH_TOKEN
configPERSONAL_WIKI_ROOT
🔐 secretSC_API_KEY
configSC_API_URL
configVITEST
configXDG_CONFIG_HOME
configZC_A2A_REGISTRY_DIR
configZC_A2A_REGISTRY_PATH
configZC_AGENT_ID
configZC_AGENT_MODEL
configZC_AGENT_ROLE
configZC_ALLOW_DESTRUCTIVE_TEST_HELPERS
configZC_ANTHROPIC_GEN_MODEL
configZC_API_CORS_ORIGINS
configZC_API_HOST
🔐 secretZC_API_KEY
configZC_API_LOG_LEVEL
configZC_API_PORT
configZC_API_URL
configZC_BASH_CAPTURE_LINES
configZC_CHANNEL_KEY_REQUIRED
configZC_COMPACT_DEFAULT_TURNS
configZC_COMPACT_MODEL
configZC_CONTEXT_ALERT_THRESHOLD
configZC_CONTEXT_BUDGET_TOKENS
configZC_CONTEXT_EMERGENCY_THRESHOLD
configZC_CONTEXT_WARN_THRESHOLD
configZC_CTX_DIST
configZC_DISABLE_INFRA_ZERO_COST
configZC_HOOK_DEBUG
configZC_HYDE_MODEL
configZC_L1_MUTATION_ENABLED
configZC_LOG_CONSOLE
configZC_LOG_DIR
configZC_LOG_LEVEL
configZC_LOG_RAW
🔐 secretZC_MACHINE_SECRET
configZC_MARKETPLACE_SOURCE
configZC_MODEL_TIER_HAIKU
configZC_MODEL_TIER_OPUS
configZC_MODEL_TIER_SONNET
configZC_MUTATION_COOLDOWN_HOURS
configZC_MUTATION_DAILY_CAP_PER_PROJECT
configZC_MUTATION_FAILURE_THRESHOLD
configZC_MUTATION_FAILURE_WINDOW
configZC_MUTATOR_MODEL
configZC_NIGHTLY_BROADCAST_ALERT
configZC_NIGHTLY_RUN_PROJECT_LEVEL_TOO
configZC_OLLAMA_GEN_MODEL
configZC_OLLAMA_URL
configZC_POSTGRES_DB
configZC_POSTGRES_HOST
🔐 secretZC_POSTGRES_PASSWORD
configZC_POSTGRES_POOL_MAX
configZC_POSTGRES_PORT
configZC_POSTGRES_SSL
configZC_POSTGRES_SSL_REJECT_UNAUTHORIZED
configZC_POSTGRES_URL
configZC_POSTGRES_USER
configZC_PROJECT_PATH
configZC_PROJECT_SKILL_PATHS
configZC_PYTHON_CMD
configZC_RBAC_ENFORCE
configZC_READ_DEDUP_ENABLED
configZC_REPO_DIR
configZC_RERANKER_MODEL
🔐 secretZC_SAVINGS_AVG_COST_PER_TOKEN
configZC_SAVINGS_RECALL_SPARSE_THRESHOLD
configZC_SKILLS_DIR
configZC_SKILLS_FORCE_FULL
configZC_SKILL_CANDIDATE_COOLDOWN_HRS
configZC_SKILL_CANDIDATE_MIN_REJECTS
configZC_SKILL_CANDIDATE_WINDOW_DAYS
configZC_SKILL_GEN_BACKEND
configZC_SPOTTER_DEFAULT_PROJECT_PATH
configZC_STORE
configZC_SUMMARY_REDIRECT
configZC_TELEMETRY_BACKEND
configZC_TELEMETRY_MODE
configZC_TEST_DB_DIR
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/iampantherr-securecontext-127hfe)](https://m8ven.ai/mcp/iampantherr-securecontext-127hfe)
commit: bba0949cd391b9713b7965a3f2147fa9adbe8aa5
code hash: 38d0edc73d7ef5c1de7e901994ebeafca787f1237a612574c3ea0e10f9cf66e5
verified: 6/12/2026, 10:36:39 AM
view raw JSON →