0
/ 100
1 day ago
glama

SecretVault MCP

Bounded egress gateway & secret proxy for AI agents and applications, enabling safe credential injection into upstream requests while keeping raw secrets out of LLM prompt contexts.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Hardcoded credentials detected
1 live-looking API key in source: 1 OpenAI API key
🚨
Known vulnerabilities in dependencies: 2 critical
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
⚠️
Tests do not pass
Either the test suite is broken or the code regressed. Either way the published behaviour can’t be verified by the publisher’s own tests.
🔐
You'll be asked for 10 credentials: ANON_KEY, PGRST_JWT_SECRET, SECRETVAULT_CLIENT_KEY, SECRETVAULT_MASTER_KEY, SECRETVAULT_PGRST_JWT_SECRET, SECRETVAULT_SUPABASE_SERVICE_KEY, SECRETVAULT_TLS_KEY, SECRETVAULT_TOKEN, SECRETVAULT_UI_PASSWORD, SERVICE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 critical

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@2.0.0GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

criticalvitest@2.0.0GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretANON_KEY
configANTIGRAVITY_CONFIG_DIR
configCLAUDE_CONFIG_DIR
configCODEX_HOME
configGEMINI_CONFIG_DIR
configJWT_CLIENT_ID
configJWT_IS_ADMIN
configJWT_TENANT_USER_ID
configNEW_MASTER_KEY_FILE
configOLD_MASTER_KEY_FILE
🔐 secretPGRST_JWT_SECRET
configPGRST_URL
configPORT
configSECRETVAULT_ALLOWED_ORIGINS
configSECRETVAULT_ALLOW_PERMISSIVE_KEY_FILE
configSECRETVAULT_ALLOW_PLAINTEXT_EXTERNAL
configSECRETVAULT_ALLOW_PLAINTEXT_EXTERNAL_CONFIRM
configSECRETVAULT_BIND_HOST
🔐 secretSECRETVAULT_CLIENT_KEY
configSECRETVAULT_DATABASE_SSL
configSECRETVAULT_DATABASE_SSL_CA
configSECRETVAULT_DATABASE_SSL_CA_FILE
configSECRETVAULT_DATABASE_SSL_INSECURE
configSECRETVAULT_DATABASE_SSL_INSECURE_CONFIRM
configSECRETVAULT_DATABASE_SSL_SERVERNAME
configSECRETVAULT_DATABASE_URL
configSECRETVAULT_EGRESS_ALLOWLIST
🔐 secretSECRETVAULT_MASTER_KEY
configSECRETVAULT_MASTER_KEY_FILE
configSECRETVAULT_MIGRATIONS_BASELINE
configSECRETVAULT_NEW_KEY_ID
configSECRETVAULT_OLD_KEY_ID
🔐 secretSECRETVAULT_PGRST_JWT_SECRET
configSECRETVAULT_PROXY_MAX_FREE_SOCKETS
configSECRETVAULT_PROXY_MAX_SOCKETS
configSECRETVAULT_PROXY_TIMEOUT_MS
configSECRETVAULT_PUBLISH_HOST
configSECRETVAULT_RATE_LIMIT_MAX_LOGIN
configSECRETVAULT_RATE_LIMIT_MAX_REGISTER
configSECRETVAULT_RATE_LIMIT_MAX_TOTP
configSECRETVAULT_RATE_LIMIT_WINDOW_MS
🔐 secretSECRETVAULT_SUPABASE_SERVICE_KEY
configSECRETVAULT_SUPABASE_URL
configSECRETVAULT_TLS_CERT
🔐 secretSECRETVAULT_TLS_KEY
🔐 secretSECRETVAULT_TOKEN
configSECRETVAULT_TRUSTED_PROXIES
🔐 secretSECRETVAULT_UI_PASSWORD
configSECRETVAULT_URL
🔐 secretSERVICE_KEY
configSOURCE_DATE_EPOCH
configTENANT_A_ID
configTENANT_B_ID
configXDG_CONFIG_HOME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 10 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/itsaygea-secretvault-myayyi)](https://m8ven.ai/mcp/itsaygea-secretvault-myayyi)
commit: 5c5a2ca136bf5e6cd2fd4a804ba1c47ab85eec46
code hash: 1601af46ad5372b1a1dc19a3bfe4c4f728bf8802890aef2c39b8116fa9761462
verified: 7/30/2026, 9:16:01 AM
view raw JSON →