Enables AI assistants to build, validate, and publish storefront pages to WebCake/StoreCake sites based on natural language descriptions.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
process.env. You'll be asked to provide them before it can run.DATABASE_URLPEXELS_API_KEY— x-webcake-jwt instead; pick the site in chat with switch_site). Server-side secrets likePORTREDIS_URLWEBCAKE_API_URL— Override a preset with / WEBCAKE_APP_URL. Optional, configured server-side:WEBCAKE_APP_URL— Override a preset with WEBCAKE_API_URL / . Optional, configured server-side:WEBCAKE_CONFIG_DIRWEBCAKE_DRAFT_TTL_MSWEBCAKE_ENV— Base URLs come from a named environment — set (or --env) and you never type a URL:WEBCAKE_OAUTHWEBCAKE_OAUTH_ACCESS_TTL_MSWEBCAKE_OAUTH_REFRESH_TTL_MSWEBCAKE_PG_POOL_MAXWEBCAKE_PG_SSLWEBCAKE_POSTGRES_URLWEBCAKE_REDIS_URLWEBCAKE_SESSION_ID— Two values are required: WEBCAKE_TOKEN (Bearer JWT) and (sent asWEBCAKE_SITE_ID— switch_site (your choice is saved and reused next session), so no is needed.WEBCAKE_SUPPORT_EMAILWEBCAKE_TOKEN— Two values are required: (Bearer JWT) and WEBCAKE_SESSION_ID (sent asWEBCAKE_TOOLS[](https://m8ven.ai/mcp/vuluu2k-webcake-storefront-mcp-uyl9z2)