75
/ 100
21 days ago
mcp_so

MCP Gateway

A Model Context Protocol (MCP) Gateway. Serves as a central management point for tools, resources, and prompts that can be accessed by MCP-compatible LLM applications. Converts REST API endpoints to MCP, composes virtual MCP servers with added security and observability, and converts between protocols (stdio, SSE).

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 8 credentials: SSL_KEY_PASSWORD, OPENAI_API_KEY, AZURE_OPENAI_API_KEY, ANTHROPIC_API_KEY, GOOGLE_API_KEY, WATSONX_API_KEY, AWS_SECRET_ACCESS_KEY, SANDBOX_API_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@4.0.18GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

lowpostcss@8.4.49GHSA-qx2v-qp2m-jg93

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configLOCUST_LOG_LEVEL
configOBJC_DISABLE_INITIALIZE_FORK_SAFETY
configSSL
🔐 secretSSL_KEY_PASSWORD
configKEY_FILE
configENVIRONMENT
configHEALTH_CHECK_PORT
configHEALTH_CHECK_HOST
configMCP_EVAL_MODELS_CONFIG
🔐 secretOPENAI_API_KEY
🔐 secretAZURE_OPENAI_API_KEY
configAZURE_OPENAI_ENDPOINT
configAZURE_DEPLOYMENT_NAME
🔐 secretANTHROPIC_API_KEY
configAWS_ACCESS_KEY_ID
🔐 secretGOOGLE_API_KEY
🔐 secretWATSONX_API_KEY
configWATSONX_PROJECT_ID
configOLLAMA_BASE_URL
configDEFAULT_JUDGE_MODEL
configAWS_REGION
configWATSONX_URL
configOPENAI_ORGANIZATION
configOPENAI_BASE_URL
🔐 secretAWS_SECRET_ACCESS_KEY
configSANDBOX_TIMEOUT
configSANDBOX_MAX_OUTPUT_SIZE
configSANDBOX_ENABLE_NETWORK
configSANDBOX_ENABLE_FILESYSTEM
configSANDBOX_ENABLE_DATA_SCIENCE
🔐 secretSANDBOX_API_TOKEN
configSANDBOX_ALLOWED_IMPORTS
configMARKDOWN_DEFAULT_TIMEOUT
configMARKDOWN_MAX_TIMEOUT
configMARKDOWN_MAX_CONTENT_SIZE
configMARKDOWN_MAX_REDIRECT_HOPS
configMARKDOWN_USER_AGENT
configRUST_MCP_PATH
configPYTEST_CURRENT_TEST
configGITHUB_ACTIONS
configOAUTH_REQUEST_TIMEOUT
configOAUTH_MAX_RETRIES
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/ibm-mcp-context-forge-vmgcxf)](https://m8ven.ai/mcp/ibm-mcp-context-forge-vmgcxf)
commit: 8e9c049e99ac9b3cf898e0bfe088a9deff3bbb19
code hash: 67429493d3996f85b69b63915ebd31c1e658185cccae866b5bceb538f6f45b83
verified: 6/30/2026, 9:56:38 AM
view raw JSON →