MCP server for collecting and resolving website feedback via AI; reviewers click elements and type requests, then AI agents pull fix prompts and resolve notes automatically.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Next.js is vulnerable to RCE in React flight protocol
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Next.js has a Middleware / Proxy bypass through dynamic route parameter injection
process.env. You'll be asked to provide them before it can run.CRON_SECRETIP_HASH_SALT— cp .env.example .env # fill in NEXT_PUBLIC_APP_ORIGIN +NEXT_PUBLIC_APP_ORIGIN— cp .env.example .env # fill in + IP_HASH_SALTPB_ADMIN_EMAIL— PB_URL=http://127.0.0.1:8091 =admin@example.com PB_ADMIN_PASS=YOUR_PASSWORD npm run setupPB_ADMIN_PASS— PB_URL=http://127.0.0.1:8091 PB_ADMIN_EMAIL=admin@example.com =YOUR_PASSWORD npm run setupPB_SUPERUSER_TOKEN— 3) generate the app's superuser token → put it in .env asPB_URLRATE_LIMIT_PER_IP_MINRATE_LIMIT_PER_PROJECT_DAYS3_ACCESS_KEY_IDS3_BUCKETS3_REGIONS3_SECRET_ACCESS_KEYSES_ACCESS_KEY_IDSES_CONFIG_SETSES_FROMSES_REGIONSES_SECRET_ACCESS_KEYTG_BOT_TOKEN— , TG_CHAT_ID Telegram ping on new notes no pingsTG_CHAT_ID— TG_BOT_TOKEN, Telegram ping on new notes no pings[](https://m8ven.ai/mcp/kryphan-krymark-1c5mjv)