74
/ 100
17 days ago
glama

Starlog

Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 2 credentials: OPENROUTER_API_KEY, STARLOG_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

lowesbuild@0.28.0GHSA-g7r4-m6w7-qqqr

esbuild allows arbitrary file read when running the development server on Windows

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCLAUDE_PROJECT_DIR
configDO_NOT_TRACKexport =1 # honored too
configGITHUB_REF_NAME
configGITHUB_REF_TYPE
🔐 secretOPENROUTER_API_KEY
🔐 secretSTARLOG_API_KEY
configSTARLOG_API_URL
configSTARLOG_NO_NUDGE
configSTARLOG_NO_UPDATE_CHECK
configSTARLOG_POLICY
configSTARLOG_PRIVATE_CORPUS
configSTARLOG_PRIVATE_FACTS
configSTARLOG_RANK_MODEL
configSTARLOG_REGISTRY_URL
configSTARLOG_TELEMETRYexport =0 # env opt-out
configSTARLOG_TELEMETRY_HOST
configVITEST
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/starloghq-index-1q820q)](https://m8ven.ai/mcp/starloghq-index-1q820q)
commit: b42264437c245ceebf9afb7b587efacf27c0676e
code hash: f2c4f0a451a62029ecf65f789b41fbc6446efb8ac61c68a700c291058e333012
verified: 7/14/2026, 8:31:22 AM
view raw JSON →