29
/ 100
23 hours ago
glama

PQC-Khepra-MCP

A sovereign compliance engine with 36,195 STIG/CCI/NIST/CMMC mappings and 76 tools, enabling AI assistants to scan systems, generate risk reports, and ensure post-quantum cryptographic attestation—all air-gappable with zero token costs.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
6 flows detected: SUPABASE_SERVICE_ROLE_KEY, STRIPE_SECRET_KEY, HUBSPOT_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 4 credentials: DISCORD_BOT_TOKEN, HUBSPOT_API_KEY, STRIPE_SECRET_KEY, SUPABASE_SERVICE_ROLE_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high4 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highpostcss@8GHSA-6g55-p6wh-862q

PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments

highpostcss@8GHSA-r28c-9q8g-f849

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

Regular Expression Denial of Service in postcss

PostCSS line return parsing error

Regular Expression Denial of Service in postcss

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAGENT_URL
configASAF_INTERNAL_API_URL
configDISCORD_APPLICATION_ID
🔐 secretDISCORD_BOT_TOKEN
🔐 secretHUBSPOT_API_KEY
configNEXT_PUBLIC_APP_URL
configNEXT_PUBLIC_SUPABASE_URL
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSUPABASE_SERVICE_ROLE_KEY
configVITE_SUPABASE_URL
configKHEPRA_MODEdocker run --rm -i -e =sovereign ghcr.io/nouchix/pqc-khepra-mcp:latest
configKHEPRA_LICENSE_SERVER
configADINKHEPRA_LLM_URL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/nouchix-pqc-khepra-mcp-v5vwjg)](https://m8ven.ai/mcp/nouchix-pqc-khepra-mcp-v5vwjg)
commit: 50a814caed7d878e5ec64af7104f826b7de02ab2
code hash: 469e645a90d204d2bfcedf7965b5b94e7bc29d3341e0c30cf9208be5eafa52a7
verified: 7/30/2026, 8:03:52 PM
view raw JSON →