74
/ 100
1 month ago
glama

MCP Observatory

Finds problems in your MCP servers before your users do. Scans your Claude config, checks every server's capabilities, actually calls tools to make sure they work, and catches breaking changes between versions.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 3 credentials: GITHUB_PRIVATE_KEY, GITHUB_WEBHOOK_SECRET, MCP_OBSERVATORY_STATS_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical1 medium

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@4.0.8GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

mediumajv@8.17.1GHSA-2g4f-4pwh-qvx6

ajv has ReDoS when using `$data` option

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configBUILDKITE
configCODEBUILD_BUILD_ID
configDO_NOT_TRACK
configGITHUB_ACTIONS
configGITHUB_APP_ID
🔐 secretGITHUB_PRIVATE_KEY
configGITHUB_REPOSITORY
configGITHUB_SHA
🔐 secretGITHUB_WEBHOOK_SECRET
configGITLAB_CI
configJENKINS_URL
configMCP_OBSERVATORY_DEBUG
🔐 secretMCP_OBSERVATORY_STATS_TOKEN
configMCP_OBSERVATORY_TELEMETRY_DEBUG
configMCP_OBSERVATORY_TELEMETRY_DISABLED
configMCP_OBSERVATORY_TELEMETRY_URL
configNO_COLOR
configPORT
configTF_BUILD
configTRAVIS
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/kryptosai-mcp-observatory-1rmhe3)](https://m8ven.ai/mcp/kryptosai-mcp-observatory-1rmhe3)
commit: db36fc981360b318a84d040653e58d88cde62531
code hash: a09157e70d1face9dbc8f20fab95fe1dfa035c081c7e79e727c0e1408e58d8bb
verified: 6/15/2026, 2:29:16 PM
view raw JSON →