2
grade F
10 days ago
glama

mcp-fe/mcp-fe

Don't let AI guess from screenshots. Give LLMs direct access to your React state, Context, and Data Grids. Features bidirectional communication via SharedWorkers & WebSockets. Docker gateway included.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical, 6 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 1 credential: JWT_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOWED_DOMAIN
configAUTH_MODE
configCORS_ORIGIN[ ] WebSocket Origin Validation: Stricter origin allowlist enforcement beyond the current configuration.
🔐 secretJWT_SECRET
configKEYCLOAK_AUDIENCE
configKEYCLOAK_ISSUER
configKEYCLOAK_JWKS_URI
configMCP_BUILD_ID
configMCP_DEBUG
configMCP_PUBLIC_URL
configMCP_SERVER_URL
configMCP_WS_URL
configPORT
configSERVER_HOST
configSESSION_TTL_MINUTES[ ] Data Retention Limits (client-side): is configurable on the server, but the local IndexedDB has no automatic TTL yet.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/mcp-fe-mcp-fe-12n8cn)](https://m8ven.ai/mcp/mcp-fe-mcp-fe-12n8cn)
commit: a4ebb780caeeac30def4e1259319ef3fc2519893
code hash: 48aba1a0a619c534315dea4ec3bf8ede50495e2ecdef189b7276c9f3a4f37a88
verified: 4/11/2026, 3:05:03 PM
view raw JSON →