0
/ 100
4 days ago
glama

Santos Automation

Website intelligence tools for AI agents. Ten pay-per-call tools via x402 micropayments (USDC on Base) — no accounts, no API keys.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: FLY_API_TOKEN, RATE_LIMIT_STORE_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 4 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
⚠️
Tests do not pass
Either the test suite is broken or the code regressed. Either way the published behaviour can’t be verified by the publisher’s own tests.
🔐
You'll be asked for 12 credentials: ANTHROPIC_API_KEY, BUYER_PRIVATE_KEY, CDP_API_KEY_SECRET, FLY_API_TOKEN, IDEMPOTENCY_HASH_SECRET, NEXT_PUBLIC_SUPABASE_ANON_KEY, RATE_LIMIT_HASH_SECRET, RATE_LIMIT_STORE_TOKEN, REPORT_ACCESS_TOKEN_SECRET, RESEND_API_KEY, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies4 high5 medium

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highnext@16.2.10GHSA-6gpp-xcg3-4w24

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

highnext@16.2.10GHSA-89xv-2m56-2m9x

Next.js: Server-Side Request Forgery in Server Actions on custom servers

highnext@16.2.10GHSA-m99w-x7hq-7vfj

Next.js: Denial of Service in App Router using Server Actions

highnext@16.2.10GHSA-p9j2-gv94-2wf4

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

mediumnext@16.2.10GHSA-4633-3j49-mh5q

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configADMIN_EMAILS
configAGENT_READINESS_CACHE_TTL_SECONDS
configAGENT_READINESS_DEEP_MAX_PAGES
configAGENT_READINESS_ENABLED
configAGENT_READINESS_MAX_BYTES
configAGENT_READINESS_MAX_DOC_LINKS
configAGENT_READINESS_MAX_FETCHES
configAGENT_READINESS_MAX_SITEMAP_URLS
configAGENT_READINESS_MCP_PROBE_ENABLED
configAGENT_READINESS_PRICE_USDC
configAGENT_READINESS_REGISTRY_LOOKUP_ENABLED
configAGENT_READINESS_RENDERED_HTML_MAX_BYTES
configAGENT_READINESS_TIMEOUT_MS
configAGENT_READINESS_USER_AGENT
configALLOWED_TARGET_PORTS
🔐 secretANTHROPIC_API_KEY
configAPI_BASE_URL
configAUDIT_TIMEOUT_MS
configBASEnpm test # e2e checks against (default localhost:3000)
configBATCH_AUDIT_PRICE_USDC
configBROWSER_ALLOWED_PORTS
configBROWSER_MAX_FRAMES
configBROWSER_MAX_REQUESTS
configBROWSER_MAX_TOTAL_BYTES
configBROWSER_NAVIGATION_TIMEOUT_MS
🔐 secretBUYER_PRIVATE_KEYconst account = privateKeyToAccount(process.env.);
configCDP_API_KEY_IDSee [.env.example](.env.example). Required in production: ,
🔐 secretCDP_API_KEY_SECRET(facilitator auth). Optional: DISCORD_WEBHOOK_URL
configDATABASE_URL
configDEEP_AUDIT_ENABLED
configDEEP_AUDIT_PRICE_USDC
configDISCORD_WEBHOOK_URLCDP_API_KEY_SECRET (facilitator auth). Optional:
configEXTRACT_PRICE_USDC
configFEED_PRICE_USDC
🔐 secretFLY_API_TOKEN
configFLY_WORKER_APP
🔐 secretIDEMPOTENCY_HASH_SECRET
configIP_HASH_SALT
configLINKS_PRICE_USDC
configMAX_ARTIFACT_BYTES
configMAX_REDIRECTS
configMAX_RESPONSE_BYTES
configMAX_URL_LENGTH
configMCP_ALLOWED_ORIGINS
configMCP_REGISTRY_BASE_URL
🔐 secretNEXT_PUBLIC_SUPABASE_ANON_KEY
configNEXT_PUBLIC_SUPABASE_URL
configPG_POOL_MAX
configPUBLIC_API_BASE_URL(payment notifications), (canonical hostname in docs
configPUBLIC_SITE_URL
🔐 secretRATE_LIMIT_HASH_SECRET
🔐 secretRATE_LIMIT_STORE_TOKEN
configRATE_LIMIT_STORE_URL
🔐 secretREPORT_ACCESS_TOKEN_SECRET
configRESEND_API
🔐 secretRESEND_API_KEY
configRESEND_SENDER
configSAFE_FETCH_MAX_BYTES
configSAFE_FETCH_PRICE_USDC
configSCREENSHOT_PRICE_USDC
configSTRIPE_PRICE_ID
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
configSTRUCTURED_EXTRACT_PRICE_USDC
configSUMMARIZE_PRICE_USDC
configTEST_TARGET
configWORKER_CDP_PORT
configWORKER_IDLE_EXIT_SECONDS
configWORKER_JOB_TIMEOUT_SECONDS
configWORKER_MAX_ATTEMPTS
configWORKER_POLL_MS
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/thereal-baitjet-santos-audit-api-1sdbzo)](https://m8ven.ai/mcp/thereal-baitjet-santos-audit-api-1sdbzo)
commit: 4de99af31144d3e74149512336adde53e69d1220
code hash: 7471ce47212fb0ecc744c8cb1e368cdc828f320fcaaf4e8341c2dad8c4a713a0
verified: 7/27/2026, 10:21:22 AM
view raw JSON →