Enables adding inline, range-anchored comments to specific text fragments in Google Docs, overcoming the limitation that Google APIs cannot create anchored comments.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.GDOCS_COMMENTS_AUDIT_LOG— off JSONL audit log (hashes only, no content)GDOCS_COMMENTS_BROWSER_CHANNEL— chrome chrome \ msedge \ chromium (bundled; needs npx playwright install chromium)GDOCS_COMMENTS_CDP_URL— Attach to an existing browser over CDP instead of managing a profile ([see below](#running-on-a-server--datacenter-ip))GDOCS_COMMENTS_HEADLESS— true Set false to watch the automation workGDOCS_COMMENTS_IDLE_CLOSE_MIN— 10 Close the managed browser after N idle minutes (0 = keep open)GDOCS_COMMENTS_PROFILE_DIR— ~/.gdocs-comments-mcp/profile Where the logged-in browser profile lives (set a different dir per Google account)[](https://m8ven.ai/mcp/stanislawherjan1-gdocs-comments-mcp-1rx2kx)