Self-hosted MCP server that exposes Synology Drive, Spreadsheet, MailPlus, and Calendar as structured tools for AI agents, enabling file, spreadsheet, email, and calendar management via natural language.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
form-data uses unsafe random function in form-data for choosing boundary
When Vitest UI server is listening, arbitrary file can be read and executed
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.DOTENV_CONFIG_PATHMCP_SSE_HOST— 127.0.0.1 Bind address for SSEMCP_SSE_PORT— 3100 Port for SSEMCP_TRANSPORT— stdio stdio or sseSMOKE_TEST— Smoke Vitest, gated by =1 Hits a real NAS — disabled in CISYNO_HOST— export =192.168.1.100 # NAS hostname or IPSYNO_HTTPS— export =true # Use HTTPS for MCP → DSMSYNO_IGNORE_CERT— export =false # true ONLY for trusted self-signed certSYNO_OTP_CODE— 2FA accounts: the Spreadsheet /authorize endpoint does not accept OTP. Create a dedicated DSM service account without 2FA for unattended automation. Leave empty.SYNO_PORT— export =5001 # 5000 = HTTP, 5001 = HTTPSSYNO_SS_HOST— export =192.168.1.100 # Host running synology/spreadsheet-apiSYNO_SS_HTTPS— export =false # Container default is plain HTTPSYNO_SS_ID_CACHE_PATHSYNO_SS_PORT— export =3000 # Container port (default 3000)[](https://m8ven.ai/mcp/vocweb-synology-mcp-server-17zoc4)