56
/ 100
10 days ago
glama

archery-mcp

Enables secure read-only queries and performance diagnostics for MySQL, Redis, and MongoDB databases through the Archery gateway, acting as a bridge between MCP clients and databases.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 5 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 2 credentials: ARCHERY_LOGIN_PASSWORD, ARCHERY_MCP_HTTP_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical5 high25 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@4.0.16GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

high@hono/node-server@1.19.8GHSA-wc8c-qw6v-h7f6

@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware

highhono@4.10.7GHSA-3vhc-576x-3qv4

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

highhono@4.10.7GHSA-88fw-hqm2-52qc

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

highhono@4.10.7GHSA-f67f-6cw9-8mq4

Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configARCHERY_BASE_URLexport =https://archery.example.com
🔐 secretARCHERY_LOGIN_PASSWORDexport =your-password
configARCHERY_LOGIN_USERNAMEexport =your-user
🔐 secretARCHERY_MCP_HTTP_API_KEY否 空 /mcp Bearer 鉴权 token(HTTP 模式)
configARCHERY_MCP_HTTP_HOST否 127.0.0.1 HTTP 监听地址(HTTP 模式)
configARCHERY_MCP_HTTP_PORT否 8080 HTTP 监听端口(HTTP 模式)
configARCHERY_QUERY_PATH否 /query/ Archery 查询接口路径
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/zhouruoye-archery-mcp-ehquuq)](https://m8ven.ai/mcp/zhouruoye-archery-mcp-ehquuq)
commit: 833dc8f5ce1b3035896b378f71b555d188d46cad
code hash: 7c92c88e3b1a91223f1a840da5ea9adc391ff270a58b1774a2150632d9b47570
verified: 7/21/2026, 8:38:18 AM
view raw JSON →