0
/ 100
10 days ago
glama

power-platform-orchestration-agent

Automates enterprise Power Platform project setup and management via MCP, reducing setup time from weeks to hours through template-based provisioning, Azure DevOps orchestration, and direct API integration.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Reads files from sensitive locations
Touches: .env, .env.first-time, .env.full-setup
⚠️
Known vulnerabilities in dependencies: 16 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
⚠️
Tests do not pass
Either the test suite is broken or the code regressed. Either way the published behaviour can’t be verified by the publisher’s own tests.
🔐
You'll be asked for 3 credentials: AZURE_CLIENT_SECRET, GRAPH_ACCESS_TOKEN, POWER_PLATFORM_CLIENT_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies16 high4 medium10 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.6.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.6.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAZURE_CLIENT_IDyour-service-principal-client-id
🔐 secretAZURE_CLIENT_SECRETyour-service-principal-secret
configAZURE_DEVOPS_BACKOFF_MULTIPLIER
configAZURE_DEVOPS_BASE_DELAY
configAZURE_DEVOPS_MAX_DELAY
configAZURE_DEVOPS_MAX_RETRIES
configAZURE_DEVOPS_ORGyour-org-name
configAZURE_DEVOPS_PATyour-personal-access-token
configAZURE_DEVOPS_TIMEOUT
configAZURE_SUBSCRIPTION_ID
configAZURE_TENANT_IDyour-tenant-id
configAZURE_USE_INTERACTIVE_AUTH
configDEFAULT_REGION
configENABLE_PARALLEL_EXECUTION
🔐 secretGRAPH_ACCESS_TOKEN
configLOG_LEVEL
configMAX_RETRIES
configMCP_AZURE_DEVOPS_ENABLED
configMCP_MICROSOFT_GRAPH_ENABLED
configMCP_POWER_PLATFORM_ENABLED
configMCP_SERVER_NAME
configPORT
configPOWER_PLATFORM_BASE_URL
configPOWER_PLATFORM_CLIENT_ID
🔐 secretPOWER_PLATFORM_CLIENT_SECRET
configPOWER_PLATFORM_DEFAULT_REGION
configPOWER_PLATFORM_ENVIRONMENT_URL
configPOWER_PLATFORM_RETRY_ATTEMPTS
configPOWER_PLATFORM_TENANT_ID
configPOWER_PLATFORM_TIMEOUT
configTEST_ENVIRONMENT_URL
configTIMEOUT_MS
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 9 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/jimiryquai-power-platform-orchestration-agent-1g6uc9)](https://m8ven.ai/mcp/jimiryquai-power-platform-orchestration-agent-1g6uc9)
commit: a98a96f53f7adb4d70bfc4e06020580034930c42
code hash: 7d85df803b5176595614e654eb4273e899af4ee6ac7c5efe6b3469cde99cd277
verified: 7/21/2026, 9:31:11 AM
view raw JSON →