Guardrails for AI coding agents that enforces rules via compliance receipts, blocking destructive actions and syncing rules across all AI tools.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.AGENT_MEMORY_AUTO_EMIT_DIR— Set =/path/to/project and the server re-emits all four files automatically on every rule save.AGENT_MEMORY_COMPANION_DIRAGENT_MEMORY_DIR— "env": { "": "/abs/path/to/memory" }AGENT_MEMORY_EMBED_MODELAGENT_MEMORY_EMBED_URLAGENT_MEMORY_LOG— Operational logging is separate. Set =debuginfowarnerror (default info) and structured lines stream to stderr — won't pollute the MCP stdio channel.AGENT_MEMORY_SCOPE— "env": { "": "global" }CRP_SIGNING_MODE— CRP 1.1 · Ed25519 asymmetric signing (set =ed25519)EDITOR— e opens the highlighted memory in $ (vim/notepad/nano/whatever) — saves back to diskFORCE_COLOR— Color output is on by default in TTYs. Set NO_COLOR=1 to disable, =1 to force-enable in pipes.GIT_AUTHOR_EMAIL— Commits use the identity agent-memory <agent-memory@local> by default — set / GIT_COMMITTER_EMAIL in your environment if you want per-machine attribution.GIT_AUTHOR_NAMEGIT_COMMITTER_EMAIL— Commits use the identity agent-memory <agent-memory@local> by default — set GIT_AUTHOR_EMAIL / in your environment if you want per-machine attribution.GIT_COMMITTER_NAMENO_COLOR— Color output is on by default in TTYs. Set =1 to disable, FORCE_COLOR=1 to force-enable in pipes.[](https://m8ven.ai/mcp/xultrax-web-agent-memory-mcp-y0ygtt)