44
/ 100
1 month ago
glama

wishmock

Provides an MCP server for automation via Server-Sent Events (SSE) to manage mock gRPC and Connect RPC services.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 13 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
// known CVEs in dependencies1 critical13 high7 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalprotobufjs@7.5.4GHSA-xq3m-2v4x-88gg

Arbitrary code execution in protobufjs

high@grpc/grpc-js@1.14.1GHSA-5375-pq7m-f5r2

@grpc/grpc-js: A malformed request can cause a server crash

high@grpc/grpc-js@1.14.1GHSA-99f4-grh7-6pcq

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

high@modelcontextprotocol/sdk@1.25.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.25.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configADMIN_BASE_URL
configCLUSTER_WORKERS
configCONNECT_CORS_ENABLED
configCONNECT_CORS_HEADERS
configCONNECT_CORS_METHODS
configCONNECT_CORS_ORIGINS
configCONNECT_ENABLEDtrue # Enable Connect RPC (default: true)
configCONNECT_PORT50052 # Connect RPC port (default: 50052)
configCONNECT_TLS_CA_PATH
configCONNECT_TLS_CERT_PATH
configCONNECT_TLS_ENABLED
configCONNECT_TLS_KEY_PATH
configENABLE_MCP
configENABLE_MCP_SSE
configGRPC_PORT
configGRPC_PORT_PLAINTEXT50050 # gRPC port
configGRPC_PORT_TLS
configGRPC_TLS_CA_PATH
configGRPC_TLS_CERT_PATH
configGRPC_TLS_ENABLEDtrue # Enable TLS
configGRPC_TLS_KEY_PATH
configGRPC_TLS_REQUIRE_CLIENT_CERT
configHEALTHCHECK_TIMEOUT_MS
configHEALTHCHECK_URL
configHOT_RELOAD_PROTOS
configHOT_RELOAD_RULES
configHTTP_PORT3000 # Admin API port
configMCP_HTTP_HOST
configMCP_HTTP_PORT
configMCP_SESSION_ID
configON_UPLOAD_PROTO_ACTION
configREFLECTION_DISABLE_REGEN
configSTART_CLUSTER
configVALIDATION_CEL_MESSAGE
configVALIDATION_ENABLEDtrue # Enable validation
configVALIDATION_MODE
configVALIDATION_SOURCE
configWISHMOCK_BASE_DIR
configWISHMOCK_PROTOS_DIR"": "/path/to/protos",
configWISHMOCK_RULES_DIR"": "/path/to/rules"
configWISHMOCK_RULES_EXAMPLES_PATH
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/lukmanbaidhowi-wishmock-1o74s9)](https://m8ven.ai/mcp/lukmanbaidhowi-wishmock-1o74s9)
commit: f2e8c344f68f994274be3d7f2450490d9ada4d4a
code hash: ab9afb59e8c88b5bb025740b989778dd9ea47eaa2c41403181475a15429b7e2c
verified: 6/22/2026, 12:37:51 PM
view raw JSON →