0
/ 100
25 days ago
github_topic

mazzap

Mazzap, part of the Mazzstack: essentials for the Singularity Slowlife

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Code appears obfuscated
2 files are unreadable to a human reviewer. Cannot audit what they do.
🔐
You'll be asked for 4 credentials: OPENAI_API_KEY, OPENAI_REQUIRE_USER_KEY, VEIL_LIVE_TOKEN, VEIL_SESSION_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCHAT_PROVIDERmodel. npm run start:local is the shortcut (=ollama,
configHOST
configOLLAMA_DEBUG
configOLLAMA_HOSTtune with (default http://127.0.0.1:11434), OLLAMA_NUM_CTX (default
configOLLAMA_MAX_TOOL_ROUNDS98304), OLLAMA_TEMPERATURE (default 0), (default 24)
configOLLAMA_MODEL=gpt-oss:20b) and also opens the viewer in an integrated-GPU Firefox
configOLLAMA_NUM_CTXtune with OLLAMA_HOST (default http://127.0.0.1:11434), (default
configOLLAMA_TEMPERATURE98304), (default 0), OLLAMA_MAX_TOOL_ROUNDS (default 24)
🔐 secretOPENAI_API_KEY(env var or a .env file) — see the chat section below. For an
configOPENAI_MODEL
configOPENAI_REASONING_EFFORT
🔐 secretOPENAI_REQUIRE_USER_KEY1. Hosted mode scopes /data, chat/MCP tools,
configPORTTWIN_DATA_DIR=./twins/mine/data =4174 npm start # -> http://127.0.0.1:4174
configSHOT_URL
configTWIN_DATA_DIR/app/twins/demo/data docker compose up # serve it
configVEIL_ALLOWED_HOSTSstop DNS rebinding; on any exposed deployment set
configVEIL_COOKIE_SECURE
configVEIL_HOSTEDtheir own OpenAI key, run with =1 and
configVEIL_HOSTED_ROOT
configVEIL_HOSTED_TEMPLATE_DATA_DIR
configVEIL_HYDRO_PYTHON
configVEIL_INIT
configVEIL_LAYER_UPLOAD_MAX_BYTES
configVEIL_LIVE_BRIDGE_RETRY_BASE_MS
configVEIL_LIVE_BRIDGE_RETRY_MAX_MS
configVEIL_LIVE_DB_APPEND_QUEUE_MAX
configVEIL_LIVE_DB_APPEND_TIMEOUT_MS
configVEIL_LIVE_GATEWAY_AUTOSTART
configVEIL_LIVE_POSITION_ACTIVE_MS
configVEIL_LIVE_POSITION_STALE_MS
configVEIL_LIVE_PYTHON
🔐 secretVEIL_LIVE_TOKENspawn local processes. Unless you set a .live_token (or ),
configVEIL_MCP_PYTHON
configVEIL_SELF_URL
🔐 secretVEIL_SESSION_SECRET
configVEIL_FETCH_RETRIES
configVEIL_GBIF_RICHNESS_REFRESH
configVEIL_GBIF_RICHNESS_GRID
configVEIL_GBIF_RICHNESS_FACET_LIMIT
configVEIL_GBIF_RICHNESS_FACET_PAGES
configVEIL_GBIF_RICHNESS_DELAY
configVEIL_GBIF_ZOOM
configVEIL_ART17_REFRESH
configVEIL_DISABLE_META_CHM
configVEIL_SENTINEL2_DATETIME
configVEIL_META_CHM_CACHE
configVEIL_NATIONAL_LAYER_MAX_FEATURES
configVEIL_NATIONAL_BIG_DOWNLOAD_MAX_BYTES
configVEIL_NATIONAL_BIG_DOWNLOAD_MIN_FREE_BYTES
configVEIL_NATIONAL_LIGHT_DOWNLOAD_MAX_BYTES
configVEIL_NATIONAL_LARGE_DOWNLOAD_BYTES
configVEIL_LIVE_POSITION_ACTIVE_SECONDS
configVEIL_LIVE_POSITION_STALE_SECONDS
configVEIL_LIVE_DB_BUSY_TIMEOUT_MS
configVEIL_URL
configTWIN_PACKPacks load via scripts/twin_pack.py (chosen by , else
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/zymazza-mazzap-1sn0zn)](https://m8ven.ai/mcp/zymazza-mazzap-1sn0zn)
commit: 2462b859aaa840e266d2554a41d23a7de8f29969
code hash: fd134dd9ade7f1dbb804ec3bd91d04693fc7314bbaaa6ebe789eef28ff3bda31
verified: 7/6/2026, 10:36:27 AM
view raw JSON →