Melt: value-leak discovery and lead capture for Claude, Cursor, and MCP-compatible agents.
MCPpedia last refreshed this data
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"melt": {
"args": [
"-y",
"@themelt/mcp-server"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
MCP server that puts Melt's value-leak discovery logic directly into Claude, Cursor, GitHub Copilot, or any other MCP-compatible agent — so when a tech leader asks their assistant "where is value leaking out of my org," the assistant can call a Melt tool and answer with a real, structured estimate instead of a generic list of vendors.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y 'npm' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
Packing does not respect root-level ignore files in workspaces
### Impact `npm pack` ignores root-level `.gitignore` & `.npmignore` file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` with workspaces, as of [v7.9.0](https://github.com/npm/cli/releases/tag/v7.9.0) & [v7.13.0](https://github.com/npm/cli/releases/tag/v7.13.0) respectively, may be affected and have published files into the npm registry they did not intend to include. ### Patch - Up
Incorrect Permission Assignment for Critical Resource in NPM
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor's blog without mention of pre-release status). It might allow local users to bypass intended filesystem access restrictions because ownerships of /etc and /usr directories are being changed unexpectedly, related to a "correctMkdir" issue.
Local Privilege Escalation in npm
Affected versions of `npm` use predictable temporary file names during archive unpacking. If an attacker can create a symbolic link at the location of one of these temporary file names, the attacker can arbitrarily write to any file that the user which owns the `npm` process has permission to write to, potentially resulting in local privilege escalation. ## Recommendation Update to version 1.3.3 or later.
npm CLI exposing sensitive information through logs
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like `<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>`. The password value is not redacted and is printed to stdout and also to any generated log files.
npm Vulnerable to Global node_modules Binary Overwrite
Versions of the npm CLI prior to 6.13.4 are vulnerable to a Global node_modules Binary Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a `serve` binary, any subsequent installs of packages that also create a `serve` binary would overwrite the first binary. This will not overwrite system binaries but only binaries put into the global node_modules directory. This b
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in ai-ml
Workspace template + MCP server for Claude Code, Codex CLI, Cursor & Windsurf. Multi-agent knowledge engine (ag-refresh / ag-ask) that turns any codebase into a queryable AI assistant.
Dynamic problem-solving through sequential thought chains
Persistent memory using a knowledge graph
Compact, efficient, and extensible long-term memory for LLM agents.
MCP Security Weekly
Get CVE alerts and security updates for io.github.omer907/melt-mcp-server and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
MCP server that puts Melt's value-leak discovery logic directly into Claude, Cursor, GitHub Copilot, or any other MCP-compatible agent — so when a tech leader asks their assistant "where is value leaking out of my org," the assistant can call a Melt tool and answer with a real, structured estimate instead of a generic list of vendors.
This is the engineering half of Melt's LLMO (LLM Optimization) distribution
strategy. See /llms.txt at the repo root and LLMO_PLAYBOOK.md for the full
content + distribution + evaluation plan this server plugs into. Positioning
reconciled 2026-07-18 against the live site and current decks — see
/CLAUDE.md for the full current product context.
| Tool | What it does |
|---|---|
melt_analyze_value_vectors | Free Stage-1 Sandbox estimator. Estimates where value is leaking in one department from headcount, labor cost, and dominant unstructured-input type. No integration required — synthetic/self-reported inputs only. |
melt_estimate_annual_leak | Quantifies an already-identified leak pattern in dollars/yr — totalVolume x (leakRatePct/100) x valuePerEvent, generalizing Melt's real "Anatomy of a Scan" methodology (a 29% Gong bypass rate, a 62% Clari override rate, etc., combined into a real $77,235/yr finding). |
melt_request_scan | Lead-capture handoff — the move from a directional estimate to a real, log-verified scan (Frictionless POC Playbook Stage 1 → 2). Routes to HubSpot if HUBSPOT_PORTAL_ID/HUBSPOT_FORM_ID are set, otherwise appends to a local leads.jsonl. |
melt_estimate_annual_leak replaced four formula-named calculators
(melt_calculate_feature_waste, _dso_cash_flow_impact,
_contract_cycle_revenue_unlock, _win_rate_pipeline_impact) that
implemented financial formulas from a retired product framing (Thermal Scan /
Feature Waste Dollar Amount™ / Delta Engine) — none of which appear in any
current Melt material. See CLAUDE.md's "What's Explicitly Retired" section.
cd mcp-server
npm install
npm run build
npm start # runs dist/index.js on stdio
To poke at it interactively before wiring it into a client:
npm run inspect # launches the MCP Inspector against the built server
Published on npm — one-line config, no local clone needed:
{
"mcpServers": {
"melt": {
"command": "npx",
"args": ["-y", "@themelt/mcp-server"]
}
}
}
Or from a local clone:
{
"mcpServers": {
"melt": {
"command": "node",
"args": ["/absolute/path/to/mcp-server/dist/index.js"]
}
}
}
For Claude Desktop specifically, themelt-mcp-server.mcpb (Anthropic's MCP
Bundle format) installs with a
double-click — no terminal, no config file editing. Download the .mcpb from
the latest GitHub Release
and either double-click it or drag it into Claude Desktop's Settings window.
To rebuild it from source:
npm run build:mcpb # produces themelt-mcp-server.mcpb
The manifest (mcpb-build/manifest.json) is hand-maintained, not
auto-generated from the TypeScript source — if a tool's name, parameters, or
description change, update the manifest's tools array to match.
dist/index.js (stdio) is what gets configured into a local Claude Desktop/
Cursor install. dist/httpServer.js is an alternate entrypoint implementing
the MCP Streamable HTTP transport — what a future "Launch Hosted MCP" web
button (LLMO_PLAYBOOK.md, Task 3.2) would point at, so someone can try the
tools without installing anything locally.
npm run build
PORT=3000 npm run start:http # POST MCP JSON-RPC to http://localhost:3000/mcp
Stateless by design — no session ID, a fresh server instance per request. Auth is opt-in via `MCP_HTTP