52
/ 100
1 month ago
glama

Maple

Maple is a unified MCP server for agent observability, safety control, and behavior evolution, acting as a monitoring and auditing layer for high-agency agents. It enables developers to capture session timelines, replay risky branches, detect anomalies using ML, and enforce action guardrails.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 6 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 12 credentials: ANTHROPIC_API_KEY, MAPLE_ADMIN_PASSWORD, MAPLE_ANTHROPIC_API_KEY, MAPLE_DEV_PASSWORD, MAPLE_GPT_OAUTH_CLIENT_SECRET, MAPLE_OPENAI_API_KEY, MAPLE_SMITHERY_API_KEY, OPENAI_API_KEY, OPENCLAW_BRIDGE_TOKEN, OPENCLAW_GATEWAY_SESSION_KEY, OPENCLAW_GATEWAY_TOKEN, SLACK_BOT_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies6 high2 medium1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highreact-router@7.12.0GHSA-49rj-9fvp-4h2h

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

highreact-router@7.12.0GHSA-8646-j5j9-6r62

React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

highreact-router@7.12.0GHSA-8x6r-g9mw-2r78

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

highreact-router@7.12.0GHSA-rxv8-25v2-qmq8

React Router vulnerable to Denial of Service via reflected user input in single-fetch

highvite@7.3.0GHSA-p9ff-h696-f583

Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretANTHROPIC_API_KEYIf OPENAI_API_KEY and/or are set, Maple enables AI mode with automatic fallback.
configGOOGLE_CLIENT_ID
configHACKATHON_TOOLHUB_HOST
configMAPLE_ADMIN_EMAIL
🔐 secretMAPLE_ADMIN_PASSWORD
configMAPLE_ADMIN_USERNAME
configMAPLE_ALLOW_BRIDGE_OVERRIDEOptional local-only override: =true.
configMAPLE_ALLOW_NO_AUTH
🔐 secretMAPLE_ANTHROPIC_API_KEY
configMAPLE_AUTH_ALLOW_SELF_SIGNUP
configMAPLE_DB_PATH
configMAPLE_DEMO_DELAY
configMAPLE_DEMO_SESSION
configMAPLE_DEMO_SOURCE
configMAPLE_DEMO_URL
configMAPLE_DEV_EMAIL
🔐 secretMAPLE_DEV_PASSWORD
configMAPLE_DEV_USERNAME
configMAPLE_DOWNSTREAM_TOOLS_CACHE_TTL_MS
configMAPLE_ENABLE_DEMO_ROUTES
configMAPLE_ENABLE_JUDGE_UI
configMAPLE_ENABLE_LEGACY_SMITHERY_ROUTES
configMAPLE_FIREWALL_CHAT_ANTHROPIC_MODELclaude-sonnet-4-6
configMAPLE_FIREWALL_CHAT_OPENAI_MODELgpt-4o-mini
configMAPLE_FIREWALL_CHAT_PRIMARYopenai # openai anthropic
configMAPLE_FIREWALL_CHAT_TIMEOUT_MS
configMAPLE_FIREWALL_DEFAULT_ACTIONallow # allow deny log_only
configMAPLE_FIREWALL_ENABLED
configMAPLE_FIREWALL_LOG_DIR~/.maple/firewall-logs
configMAPLE_GPT_OAUTH_CLIENT_ID
🔐 secretMAPLE_GPT_OAUTH_CLIENT_SECRET
configMAPLE_LOCK_BRIDGE_TARGETSet =true to deny per-request bridgeUrl / token overrides.
configMAPLE_LOG_BODY_MAX_CHARS
configMAPLE_LOG_INCLUDE_BODIES
configMAPLE_LOG_LEVEL
configMAPLE_LOG_REQUESTS
configMAPLE_MAX_SHARED_TRACES
configMAPLE_MCPSO_BASE_URL
configMAPLE_MCPSO_CACHE_TTL_MS
configMAPLE_MCPSO_ENABLED
configMAPLE_MCPSO_TIMEOUT_MS
configMAPLE_MCP_EXECUTION_ORDER
configMAPLE_MCP_FIREWALL_DEFAULT_APP
configMAPLE_MCP_MARKETPLACE_AUTO_CONNECT
configMAPLE_MCP_MARKETPLACE_ENABLED
configMAPLE_MCP_PROXY_ALLOWED_HOSTS
configMAPLE_MCP_PROXY_ALLOW_DYNAMIC_TARGETS
configMAPLE_MCP_PROXY_ALLOW_HTTP
configMAPLE_MCP_PROXY_ALLOW_PRIVATE_TARGETS
configMAPLE_MCP_PROXY_DEFAULT_TARGET_URL
configMAPLE_MCP_ROUTE_LOCK
🔐 secretMAPLE_OPENAI_API_KEY
configMAPLE_SESSION_OWNER_SCOPE
configMAPLE_SESSION_POLL
configMAPLE_SESSION_POLL_MS
configMAPLE_SESSION_TTL_SECONDS
configMAPLE_SMITHERY_API_BASE_URL
🔐 secretMAPLE_SMITHERY_API_KEY
configMAPLE_SMITHERY_ENABLED
configMAPLE_SMITHERY_TIMEOUT_MS
configMAPLE_TOOLHUB_PORT
configMAPLE_TOOLHUB_TIMEOUT_MS
configMAPLE_TRACE_SESSION_ID
configMCP_URL
🔐 secretOPENAI_API_KEYIf and/or ANTHROPIC_API_KEY are set, Maple enables AI mode with automatic fallback.
configOPENCLAW_BRIDGE_MODE
configOPENCLAW_BRIDGE_PORT
configOPENCLAW_BRIDGE_REQUIRE_AUTH
🔐 secretOPENCLAW_BRIDGE_TOKENyour_token
configOPENCLAW_BRIDGE_URLIn production, and OPENCLAW_BRIDGE_TOKEN must be explicitly set.
configOPENCLAW_GATEWAY_HISTORY_LIMIT
🔐 secretOPENCLAW_GATEWAY_SESSION_KEY
🔐 secretOPENCLAW_GATEWAY_TOKEN
configOPENCLAW_GATEWAY_WS_URL
configOPENCLAW_SESSIONS_DIR
configPORTRailway provides automatically; do not hardcode it.
🔐 secretSLACK_BOT_TOKENBot mode: set and optionally SLACK_DEFAULT_CHANNEL
configSLACK_DEFAULT_CHANNELBot mode: set SLACK_BOT_TOKEN and optionally
configSLACK_WEBHOOK_URLIncoming webhook mode: set
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/omar2001ramadan-mcp-17v43o)](https://m8ven.ai/mcp/omar2001ramadan-mcp-17v43o)
commit: abdc595a21c233f50aab5751c2a5f5f559cb1aa0
code hash: 514b9b6f3e597833b4aad1de1f43479b35935132e9d81c8c41bac3b6844e038a
verified: 6/12/2026, 11:37:36 AM
view raw JSON →