Prediction market intelligence for AI agents, enabling real-time access to whale trades, market data, signals, and AI-synthesized analysis from Kalshi and Polymarket via a standardized protocol.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
process.env. You'll be asked to provide them before it can run.ANTHROPIC_API_KEY— sk-ant-... # Required for AI synthesis toolsCREDENTIAL_ENCRYPTION_KEYDB_PATHKALSHI_API_KEY_IDKALSHI_PRIVATE_KEYKALSHI_PRIVATE_KEY_PATHMCP_ADMIN_SECRET— your-secret-hereMCP_PORTPOLY_BUILDER_API_KEYPOLY_BUILDER_PASSPHRASEPOLY_BUILDER_SECRETSTRIPE_ADVANCED_PRICE_IDSTRIPE_PRO_PRICE_IDSTRIPE_SECRET_KEYSTRIPE_WEBHOOK_SECRETVEYNOR_API_URL— The server runs on port 3001 by default. The Next.js app must be running at — the MCP server reads data files from disk and calls the intelligence endpoint via localhost HTTP.WIDE_SPREADS_PATH[](https://m8ven.ai/mcp/veynor-xyz-veynor-mcp-nfz9d1)