Time estimation MCP server for AI agents. It provides PERT, COCOMO II, Monte Carlo simulation, sprint forecasting, token-to-time and cost mapping, and schedule-risk tools.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
process.env. You'll be asked to provide them before it can run.CANARY_REPORTEPOCH_CANARY_LOCAL_ONLYEPOCH_COMMUNITY_DIR— data/community/ Community data directoryEPOCH_DATA_DIR— ~/.epoch/ Data directory for feedback and self-improvementEPOCH_DEBUGEPOCH_DRY_RUNEPOCH_HOST— 127.0.0.1 HTTP server bind addressEPOCH_LOG_REQUESTSEPOCH_PORT— or: EPOCH_TRANSPORT=http =3099 epochEPOCH_RATE_LIMIT— 100 Max requests per minute per IP (HTTP only)EPOCH_SOURCE— Source tagging: Set =<project-name> to tag estimates by project.EPOCH_TELEMETRY— 0 Set to 1 to enable anonymous telemetry. See [Telemetry & Privacy](#telemetry--privacy).EPOCH_TELEMETRY_ENDPOINT— _(none)_ Override the configured telemetry receiver endpoint for status/submission.EPOCH_TELEMETRY_SUBMIT_FORCEEPOCH_TELEMETRY_SUBMIT_INTERVAL_HOURSEPOCH_TRANSPORT— or: =http EPOCH_PORT=3099 epochEPOCH_TRUST_PROXYEPOCH_URLGLM_AUTH_TOKENLM_STUDIO_URLMINIMAX_API_KEYPORT[](https://m8ven.ai/mcp/kyanitelabs-epoch-z79lu6)