74
/ 100
1 day ago
glama

mcp-personal-suite

Local-first personal productivity MCP server bundling email, calendar, messaging, search, and image generation tools with BYOK and no cloud dependency.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 17 credentials: BRAVE_API_KEY, CREDENTIAL_ENCRYPTION_KEY, DISCORD_BOT_TOKEN, EXA_API_KEY, FAL_API_KEY, GEMINI_API_KEY, GOOGLE_CLIENT_SECRET, GOOGLE_REFRESH_TOKEN, IMAP_PASS, OAUTH2_CLIENT_SECRET, OAUTH2_REFRESH_TOKEN, OPENAI_API_KEY, SLACK_APP_TOKEN, SLACK_BOT_TOKEN, SMTP_PASS, TAVILY_API_KEY, TELEGRAM_BOT_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

critical@whiskeysockets/baileys@7.0.0-rc.9GHSA-qvv5-jq5g-4cgg

Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretBRAVE_API_KEY
🔐 secretCREDENTIAL_ENCRYPTION_KEYon first run, or you can provide your own via the
configCREDENTIAL_ENCRYPTION_SALT
🔐 secretDISCORD_BOT_TOKEN
🔐 secretEXA_API_KEY
🔐 secretFAL_API_KEY
🔐 secretGEMINI_API_KEY
configGOOGLE_CALENDAR_CREDENTIALS
configGOOGLE_CALENDAR_ID
configGOOGLE_CLIENT_ID
🔐 secretGOOGLE_CLIENT_SECRET
🔐 secretGOOGLE_REFRESH_TOKEN
configIMAP_HOST
🔐 secretIMAP_PASS
configIMAP_PORT
configIMAP_USER
configMCP_ALLOWED_ORIGINScomma-separated origin whitelist for browser-based
configMCP_DEBUG
configMCP_HOSTbind address (default 127.0.0.1). Change to 0.0.0.0 only
configMCP_HTTPe =1 -e MCP_PORT=5120 \
configMCP_MAX_SESSIONScap on concurrent sessions (default 100). Returns
configMCP_PORTe MCP_HTTP=1 -e =5120 \
configMCP_SUITE_DEEP_SEARCH_CONCURRENCY
configMULTI_CHANNEL_AUTO_CONNECT
configMULTI_CHANNEL_BUFFER_SIZE
configOAUTH2_CLIENT_ID
🔐 secretOAUTH2_CLIENT_SECRET
configOAUTH2_EMAIL
configOAUTH2_PROVIDER
🔐 secretOAUTH2_REFRESH_TOKEN
🔐 secretOPENAI_API_KEY
configPERSONAL_SUITE_CONFIG_DIR
configSEARXNG_ALLOW_LOCAL
configSEARXNG_URL
🔐 secretSLACK_APP_TOKEN
🔐 secretSLACK_BOT_TOKEN
configSMTP_HOST
🔐 secretSMTP_PASS
configSMTP_PORT
configSMTP_USER
🔐 secretTAVILY_API_KEY
🔐 secretTELEGRAM_BOT_TOKEN
configWHATSAPP_AUTH_DIR
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/studiomeyer-io-mcp-personal-suite-1yrt3n)](https://m8ven.ai/mcp/studiomeyer-io-mcp-personal-suite-1yrt3n)
commit: 36d77780e007ae715fc0f5cea8961de21f5eb910
code hash: dd46dc4e10f1a63594554412b8828fc6bc43c0f0a00beeda9f78dbe152d37dcc
verified: 7/30/2026, 8:46:04 AM
view raw JSON →