Local-first MCP gateway. One port for every tool and every AI client: lazy discovery (~90% token savings), tool integrity + quarantine, secrets in the OS keychain.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
vite: `server.fs.deny` bypass on Windows alternate paths
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
vite allows server.fs.deny bypass via backslash on Windows
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
process.env. You'll be asked to provide them before it can run.BENCH_NOCACHECONDUIT_EMBED_ENDPOINT— , CONDUIT_EMBED_MODEL, plus optional CONDUIT_EMBED_KEYCONDUIT_EMBED_MODEL— CONDUIT_EMBED_ENDPOINT, , plus optional CONDUIT_EMBED_KEYCONDUIT_REGISTRY— path> - override the registry file location. Defaults to aCONDUIT_SEMANTIC— embedding similarity for paraphrased queries: =on,CONDUIT_SIDECAR_TARGETCONNECT_WAIT_MSCOUNTSGATEWAYKLLM_API_KEYLLM_URLMAX_STEPSMODELOUT_DIRRUNSTAURI_DEV_HOSTTOOLS_ONLYXDG_CONFIG_HOME[](https://m8ven.ai/mcp/tsouth89-toolport-vrk6xd)