Code-mode MCP server (docs_search + execute_code two-tool surface) backed by a unified capability manifest across three sandbox kernels (in-process node:vm, WASM via QuickJS / Pyodide / Wasmtime, and remote microVM via E2B / Cloudflare Sandbox). At N=30 tools the bootstrap-context cost drops to 13.6% of direct tool-use. Apache-2.0.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Happy DOM: VM Context Escape can lead to Remote Code Execution
happy-dom allows for server side code to be executed by a <script> tag
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
Trubo: Login callback CSRF/session fixation
Turbo: Unexpected local code execution during Yarn Berry detection
process.env. You'll be asked to provide them before it can run.ANTHROPIC_API_KEY— // Standard usage — reads from environmentANTHROPIC_BASE_URLOTEL_SEMCONV_STABILITY_OPT_IN[](https://m8ven.ai/mcp/wasmagent-wasmagent-js-1wog6j)