Enables MCP clients to spawn and control Codex CLI and Claude Code sessions on the host machine, with session management and filesystem access.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
process.env. You'll be asked to provide them before it can run.AUTH_TOKEN— Env var whitelisting for child processes ( never leaks)IDLE_TIMEOUT— No 1800000 Session idle timeout in ms (30 min)MAX_SSE_CONNECTIONS— No 50 Max concurrent SSE connectionsPORT— No 3500 HTTP server portRATE_LIMIT_RPM— No 120 Max requests per minute per IP on POST /messagesSSE_IDLE_TIMEOUT— No 300000 Idle SSE connection eviction timeout in ms (5 min)WORKSPACE_DIR— Filesystem sandboxed to and active session directories[](https://m8ven.ai/mcp/meimakes-pokeclaw-11mt9t)