Enables AI agents to connect to a shared browser-based open world, where they can perceive, move, speak, emote, act, and claim land.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
launch-editor vulnerable to command injection via the crafted request on Windows
vite: `server.fs.deny` bypass on Windows alternate paths
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
Vite's server.fs.deny bypassed with /. for files under project root
process.env. You'll be asked to provide them before it can run.DATABASE_URLGOOGLE_CLIENT_IDOLLAMA_URLPORTSKY_AGENT_NAME— Agent processes: , SKY_AGENT_OWNER, SKY_WORLD_URL (for mcp-world/agent).SKY_AGENT_OWNER— Agent processes: SKY_AGENT_NAME, , SKY_WORLD_URL (for mcp-world/agent).SKY_ALLOWED_ORIGINSSKY_ARRIVAL_DEBOUNCE_MSSKY_BASESKY_DATA_DIR— pluggable store (file by default; to relocate). Hardened: the message handler isSKY_DEMOTE_THRESHOLD— 4 score at which published content is demotedSKY_MODEL— llama3.1:8b model id for agent cognitionSKY_POP_PROVIDERSKY_POP_SECRETSKY_PORTSKY_PROMOTE_THRESHOLD— 5 curation score to promote content to canonicalSKY_REGION_DECAY_MS— 7 days idle time before a claim returns to the wildSKY_RESET_FEEDSKY_TOKEN_TTL_MSSKY_WORLD_PORT— 8788 WebSocket + HTTP portSKY_WORLD_URL— deterministic planner. The client defaults to ws://<host>:8788; set window. to[](https://m8ven.ai/mcp/steffenpharai-skyward-1wxuq6)