Security-enforcing MCP proxy that sits between an AI agent and any number of downstream MCP servers, intercepting every tool call through a capability-token policy gateway that can allow, deny, or escalate to human approval before the call reaches any real tool. It also exposes built-in operator tools for approval workflows, audit trail queries, token management, voice/HUD output, and hierarchical
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
Trubo: Login callback CSRF/session fixation
Turbo: Unexpected local code execution during Yarn Berry detection
process.env. You'll be asked to provide them before it can run.DATABASE_URL— postgresql://...MODELOPENAI_MODELPAPERCLIP_AGENT_IDPAPERCLIP_RUN_IDPAPERCLIP_TASK_IDPORTREDIS_URL— redis://...SINT_AGENT_PRIVATE_KEYSINT_API_KEY— railway variables --set SINT_STORE=postgres SINT_CACHE=redis =$(openssl rand -hex 32)SINT_CACHE— railway variables --set SINT_STORE=postgres =redis SINT_API_KEY=$(openssl rand -hex 32)SINT_ENV— productionSINT_MCP_APPROVAL_TIMEOUTSINT_MCP_CONFIGSINT_MCP_POLICYSINT_MCP_PORTSINT_MCP_TRANSPORTSINT_PORTSINT_RATE_LIMITSINT_REQUIRE_SIGNATURESSINT_SESSION_IDSINT_STORE— railway variables --set =postgres SINT_CACHE=redis SINT_API_KEY=$(openssl rand -hex 32)SINT_TRAJECTORY_DIRSINT_WS_ALLOW_QUERY_API_KEY[](https://m8ven.ai/mcp/sint-ai-sint-protocol-1gkgbr)