70
/ 100
15 days ago
github_topic

kernel-mcp-server

Open-source MCP server for secure, low-latency cloud-browser automation on Kernel.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: MINTLIFY_ASSISTANT_API_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 2 credentials: CLERK_SECRET_KEY, MINTLIFY_ASSISTANT_API_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@clerk/nextjs@6.39.2GHSA-w24r-5266-9c3c

Clerk has an authorization bypass when combining organization, billing, or reverification checks

highplaywright@1.49.1GHSA-7mvr-c777-76hp

Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate

lowpostcss@8.5.6GHSA-qx2v-qp2m-jg93

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAPI_BASE_URL
🔐 secretCLERK_SECRET_KEY
configKERNEL_CLI_DEV_CLIENT_ID
configKERNEL_CLI_PROD_CLIENT_ID
configKERNEL_CLI_STAGING_CLIENT_ID
configKERNEL_MCP_DISABLED_TOOLSETSSelf-hosted deployments can hide sensitive tool families by setting to a comma-separated list. For example, KERNEL_MCP_DISABLED_TOOLSETS=api_keys prevents manage_api_keys from being registered.
configKERNEL_PROJECT
🔐 secretMINTLIFY_ASSISTANT_API_TOKEN
configMINTLIFY_DOMAIN
configNEXT_PUBLIC_CLERK_DOMAIN
configREDIS_TLS_SERVER_NAME
configREDIS_URL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/kernel-kernel-mcp-server-175pdr)](https://m8ven.ai/mcp/kernel-kernel-mcp-server-175pdr)
commit: bca50d34dca776c6068688fe094d68f8df50ed7b
code hash: 3fc474d3656559ccc7e9fd967d9bfda948f2a0f373a3436a93548fe7219dfe1f
verified: 6/14/2026, 11:25:22 AM
view raw JSON →