0
/ 100
1 month ago
glama

Muninn

Provides persistent memory for AI coding agents via MCP, allowing them to recall fragility, decisions, and bugs across sessions.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: TURSO_API_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🚨
Code appears obfuscated
8 files are unreadable to a human reviewer. Cannot audit what they do.
⚠️
Known vulnerabilities in dependencies: 1 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 9 credentials: CSRF_SECRET, GITHUB_WEBHOOK_SECRET, METRICS_TOKEN, MGMT_DB_TOKEN, SSO_ENCRYPTION_KEY, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, TURSO_API_TOKEN, VOYAGE_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 high2 medium15 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highdrizzle-orm@0.45.1GHSA-gpj5-g38j-94v9

Drizzle ORM has SQL injection via improperly escaped SQL identifiers

medium@anthropic-ai/sdk@0.79.0GHSA-p7fg-763f-g4gf

Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool

mediumhono@4.12.8GHSA-xf4j-xp2r-rqqx

Hono: Path traversal in toSSG() allows writing files outside the output directory

low@anthropic-ai/sdk@0.79.0GHSA-5474-4w2j-mq4c

Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories

lowhono@4.12.8GHSA-26pp-8wgv-hjvm

Hono missing validation of cookie name on write path in setCookie()

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAPI_KEYS
configBASE_URL
configCORS_ORIGINS
🔐 secretCSRF_SECRET
configDATABASE_URL
configDB_PATH
🔐 secretGITHUB_WEBHOOK_SECRET
🔐 secretMETRICS_TOKEN
🔐 secretMGMT_DB_TOKEN
configMGMT_DB_URL
configMUNINN_PRIMARY_URL
configPORT
configSP_ENTITY_ID
🔐 secretSSO_ENCRYPTION_KEY
configSTRIPE_PRO_PRICE_ID
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
🔐 secretTURSO_API_TOKEN
configTURSO_ORG
🔐 secretVOYAGE_API_KEY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/ravnltd-muninn-1yt4kf)](https://m8ven.ai/mcp/ravnltd-muninn-1yt4kf)
commit: 573e5bf0b20f61a908e5e00131af8347f9669d0d
code hash: f3fbaad09603cb8e13bd42d58645fd05b247827a56f2cb4d6f1c71d20c4a526a
verified: 6/11/2026, 10:56:42 AM
view raw JSON →