An MCP server that enforces development discipline and workflow best practices, guiding users through a structured process of coding, testing, documenting, committing, and releasing.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Vite: `server.fs.deny` bypassed with queries
ws affected by a DoS when handling a request with many HTTP headers
process.env. You'll be asked to provide them before it can run.ADMIN_EMAILADMIN_PASSWORDADMIN_USERNAMEAPI_PORTDEV_WORKFLOW_DB_PATH— Override path for the SQLite database file <project>/.state/dev-workflow.dbDEV_WORKFLOW_DB_TYPE— "": "postgres",DEV_WORKFLOW_DB_URL— "": "postgres://USER:PASS@HOST:5432/devworkflow"DEV_WORKFLOW_FORCE_RELEASEDEV_WORKFLOW_SKIP_RELEASEDEV_WORKFLOW_STATE_FILE— 4. Define environment variables – In the Node.js panel add any environment variables you need (for example DEV_WORKFLOW_USER_ID or ). This keeps state files outside the web root if desired.DEV_WORKFLOW_USER_ID— 4. Define environment variables – In the Node.js panel add any environment variables you need (for example or DEV_WORKFLOW_STATE_FILE). This keeps state files outside the web root if desired.INIT_CWDJWT_SECRETPORT— Environment overrides: Honors (common on hosts like Plesk/Render) or DEV_WORKFLOW_WEB_PORT before falling back to auto-selection.SESSION_SECRETTEST_MYSQL_URLTEST_POSTGRES_URL[](https://m8ven.ai/mcp/programinglive-dev-workflow-mcp-server-ehd49w)