MCP server for querying Swagger/OpenAPI metadata efficiently from AI tools, enabling fast API discovery, search, and schema inspection.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.OPENAPI_CACHE_DIR— export =".cache/openapi"OPENAPI_CACHE_TTL_SECONDS— export ="86400"OPENAPI_FILE— export ="./openapi.json"OPENAPI_NAMEOPENAPI_SOURCES— export ="admin=http://localhost:8080/v3/api-docs/admin,public=http://localhost:8080/v3/api-docs/public"OPENAPI_URL— export ="http://localhost:8080/v3/api-docs"[](https://m8ven.ai/mcp/joyboy-yy-swagger-openapi-mcp-ywqu4z)