37
/ 100
1 month ago
npm

trycompai/comp

Model Context Protocol (MCP) Server for the *@trycompai/mcp-server* API.

trycompai/comp· npm: @trycompai/mcp-server· listed on npm
Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: POSTHOG_PERSONAL_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 15 credentials: APP_AWS_SECRET_ACCESS_KEY, AUTH_GITHUB_SECRET, AUTH_GOOGLE_SECRET, AUTH_MICROSOFT_CLIENT_SECRET, BACKGROUND_CHECK_API_KEY, BACKGROUND_CHECK_WEBHOOK_SECRET, GRAM_OAUTH_CLIENT_SECRET, INTERNAL_API_TOKEN, NEXT_PUBLIC_POSTHOG_KEY, OPENAI_API_KEY, POSTHOG_API_KEY, POSTHOG_PERSONAL_API_KEY, SECRET_KEY, STRIPE_SECRET_KEY, UPSTASH_REDIS_REST_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 medium2 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

mediumturbo@2.9.6GHSA-hcf7-66rw-9f5r

Trubo: Login callback CSRF/session fixation

lowbetter-auth@1.4.22GHSA-wxw3-q3m9-c3jr

Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE

lowturbo@2.9.6GHSA-3qcw-2rhx-2726

Turbo: Unexpected local code execution during Yarn Berry detection

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAPP_AWS_ACCESS_KEY_ID
configAPP_AWS_BUCKET_NAME
configAPP_AWS_ENDPOINT
configAPP_AWS_KNOWLEDGE_BASE_BUCKET
configAPP_AWS_ORG_ASSETS_BUCKET
configAPP_AWS_QUESTIONNAIRE_UPLOAD_BUCKET
configAPP_AWS_REGION
🔐 secretAPP_AWS_SECRET_ACCESS_KEY
configAPP_URL
configASSISTANT_CHAT_TTL_SECONDS
configAUTH_GITHUB_ID
🔐 secretAUTH_GITHUB_SECRET
configAUTH_GOOGLE_ID
🔐 secretAUTH_GOOGLE_SECRET
configAUTH_MICROSOFT_CLIENT_ID
🔐 secretAUTH_MICROSOFT_CLIENT_SECRET
configAUTH_MICROSOFT_TENANT_ID
configAUTH_TRUSTED_ORIGINS
configBACKGROUND_CHECK_API_BASE_URL
🔐 secretBACKGROUND_CHECK_API_KEY
🔐 secretBACKGROUND_CHECK_WEBHOOK_SECRET
configBACKGROUND_WH_ENDPOINT
configBASE_URL
configBETTER_AUTH_URL
configDATABASE_URL"postgresql://user:password@host:port/database"
configFLEET_AGENT_BUCKET_NAME
configGRAM_OAUTH_CLIENT_ID
🔐 secretGRAM_OAUTH_CLIENT_SECRET
configGRAM_OAUTH_REDIRECT_URI
🔐 secretINTERNAL_API_TOKEN
configMCP_OAUTH_LOGIN_PAGE
configMCP_RESOURCE_URL
configNEXT_PUBLIC_APP_URL
configNEXT_PUBLIC_POSTHOG_HOST
🔐 secretNEXT_PUBLIC_POSTHOG_KEY
🔐 secretOPENAI_API_KEY
🔐 secretPOSTHOG_API_KEY
configPOSTHOG_HOST
🔐 secretPOSTHOG_PERSONAL_API_KEY
configPOSTHOG_PROJECT_ID
configPRISMA_ALLOW_INSECURE_TLS
🔐 secretSECRET_KEY
🔐 secretSTRIPE_SECRET_KEY
configTRIGGER_PRISMA_FORCE_GENERATE
🔐 secretUPSTASH_REDIS_REST_TOKEN
configUPSTASH_REDIS_REST_URL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/trycompai-mcp-server-ya75ir)](https://m8ven.ai/mcp/trycompai-mcp-server-ya75ir)
commit: 4c526191d917e7952c55aa292e18e74cc070e695
code hash: 3f3f1012efe74bbb6884cba7ecdb2621edfc12d08b79b7a551b0c2d8e6d3e5e8
verified: 6/13/2026, 9:42:47 AM
view raw JSON →