Atlas / MCP servers / 1xn-labs / 1xn AI Workflow Composer

1xn AI Workflow ComposerBLOCK

mcp/1xn-labs/1xn-ai-workflow-composer

vMCP - Virtual Model Context Protocol

Verdict
BLOCK
Grade
F
Trust score
60 /100
Exposed tools
153 142r · 11w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
51
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/1xn-vmcp/) [](https://1xn.ai/docs/) [](https://1xn.ai)

Lego for AI workflows and agents: An open-source tool for composing, customizing and extending multiple MCP servers into a single logical, virtual MCP server

Built for fine grained context-engineering

  • Create vMCP, Add MCP servers and Fine-tune
  • Extend with your own prompts, tools and resources
  • Connect any client (Claude, ChatGPT, Gemini, Cursor, VScode, custom agents) to the vMCP
  • Create multiple logical vMCPs based on your workflow and agent needs

vMCP (virtual Model Context Protocol) is an AI configuration and management platform built on top of the Model Context Protocol. It is both :

  • A specification that builds on and extends MCPs: vMCP.json
  • A platform to create and deploy vMCP Servers:

Why We Built This

The Model Context Protocol has unlocked incredible possibilities for AI integrations, but users and developers quickly hit limitations:

  • Configuration Hell: Managing MCP configs across multiple clients (Claude, ChatGPT, VSCode, Cursor, Gemini) is tedious
  • Auth: Each mcp client needs its own auth for all the MCPs
  • Lack of Customization: Can't modify or extend existing MCPs for specific workflow needs - "context rot / confusion"
  • No Composition: Building complex workflows requires piecing together multiple tools from mult
Read from source at commit 83c836a6cbe7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add 1xn --env VMCP_DUMMY_USER_TOKEN=${VMCP_DUMMY_USER_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "1xn": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "VMCP_DUMMY_USER_TOKEN": "${VMCP_DUMMY_USER_TOKEN}"
      }
    }
  }
}
03

Exposed tools (153)

142 read · 11 write · 0 destructive.

ToolRiskDescription
areadFirst number
addwriteAdd two numbers
add_numberswriteAdd two numbers together.
agereadPerson age
api_info_toolreadAPI information tool
api_request_promptreadPrompt using API configuration
breadSecond number
base_greetingreadBase greeting
book_tablereadBook a table with date availability check.
calculatereadPerform calculations
calculate_areareadCalculate circle area
categoryreadProduct category
cityreadCity name
complex_prompt_toolreadA complex prompt tool
comprehensive_analysisreadComprehensive analysis with all features
comprehensive_reporterreadComprehensive reporting tool
contact_info_toolreadProvide contact information
convert_timereadConvert time from one timezone to another.
create_productwriteCreate a new product
create_thumbnailwriteCreate a thumbnail from an image
create_userwriteCreate a new user
dashboard_analysis_promptreadAnalyze dashboard data
datareadDictionary data
data_formatterreadFormat data tool
denominatorreadDenominator
descriptionreadProduct description
detailsreadAdditional details
dividereadDivide two numbers
echo_toolreadEcho tool
emailreadUser email
extended_greetingreadExtended greeting with base
fetch_healthreadFetch health status
fibonaccireadCalculate Fibonacci number
first_namereadFirst name
formatreadOutput format
generate_poemreadGenerate a poem using LLM sampling.
get_configreadThis returns unstructured output - no schema generated
get_current_timereadGet current time in specified timezone.
get_locationreadGet location coordinates for a city using the world cities database.
get_products_filteredreadGet filtered products
get_server_healthreadGet server health status
get_statisticsreadGet various statistics
get_test_promptreadPrompt for testing get operation
get_userreadGet user profile - returns structured data
get_user_by_idreadGet user by ID
get_user_by_id_collectionreadGet user by ID (from collection)
get_user_profilereadGet user profile
get_usersreadGet Users (imported from collection)
get_users_collectionreadGet users (from collection)
get_users_with_apikeyreadGet users with API key
get_users_with_configreadGet users using config API key
get_weatherreadGet weather for a city using Open-Meteo API.
get_weather_arrayreadGet weather for multiple cities - returns structured data. Input should
get_weather_jsonreadGet weather for multiple cities from JSON input. Each city can have location and unit settings.
get_weather_structuredreadGet weather for a city - returns structured data.
greet_in_languagereadGreet user in specific language
greet_userreadGreet user with optional title
greetingreadStandard greeting message
greeting_toolreadGreeting tool
health_checkreadHealth check endpoint from collection
helloreadSay hello to someone.
http_api_key_toolreadHTTP tool with API key
http_basic_auth_toolreadHTTP tool with basic auth
http_bearer_toolreadHTTP tool with bearer token
http_config_sub_toolreadHTTP tool with config substitution
http_get_toolreadA simple HTTP GET tool
http_param_sub_toolreadHTTP tool with param substitution
http_patch_toolwriteHTTP PATCH tool
http_post_toolwriteHTTP POST tool with JSON body
http_query_toolreadHTTP tool with query params
idreadResource ID
inputreadInput text
input_datareadInput data
itemsreadList of items
languagereadLanguage for greeting
last_namereadLast name
limitreadResult limit
list_citiesreadGet a list of cities
locationreadLocation
long_running_taskwriteExecute a task with progress updates.
messagereadMessage to process
multiplyreadMultiply two numbers
nreadPosition in Fibonacci sequence
namereadUser
new_pricereadNew price
notifywriteSend notification
numberreadFloat number
numbersreadList of numbers
numeratorreadNumerator
operationreadOperation type
param1readParameter 1
param2readParameter 2
personalized_greetingreadPersonalized greeting
personalized_reportreadGenerate personalized report
pricereadProduct price
process_datareadProcess data with logging.
product_idreadProduct ID
product_namereadProduct name
prompt_tool_1readPrompt tool 1
prompt_tool_2readPrompt tool 2
prompt_tool_with_configreadA prompt tool with config variables
prompt_tool_with_mcpreadA prompt tool that calls MCP tools
prompt_tool_with_varsreadA prompt tool with variables
python_complex_toolreadPython tool with complex logic
python_default_toolreadPython tool with default values
python_dict_toolreadPython tool with dict parameter
python_float_toolreadPython tool with float parameter
python_list_toolreadPython tool with list parameter
python_string_toolreadPython tool with string parameter
queryreadSearch query
query_dbreadTool that uses initialized resources.
radiusreadCircle radius
report_typereadType of report
rolereadUser
roll_dicereadRoll dice with specified number of dice and sides.
searchreadSearch for information
signaturereadEmail signature
simple_analyzerreadA simple analysis tool
simple_greetingreadA simple greeting prompt
simple_prompt_toolreadA simple prompt tool
simple_python_toolreadA simple Python tool
string_formatterreadFormat strings
sum_listreadSum a list of numbers
sum_of_arrayreadSum of array
summaryreadSummary text
system_info_promptreadSystem info prompt
test_audio_contentreadTests audio content response
test_elicitationreadTests server-initiated elicitation (user input request)
test_elicitation_sep1034_defaultsreadTests elicitation with default values for all primitive types (SEP-1034)
test_embedded_resourcereadTests embedded resource content response
test_error_handlingreadTests error response handling
test_get_envreadTests env setting for stdio servers
test_get_headersreadTests headers setting for sse/http servers
test_image_contentreadTests image content response
test_multiple_content_typesreadTests response with multiple content types (text, image, resource)
test_promptreadA test prompt
test_samplingreadTests server-initiated sampling (LLM completion request)
test_simple_textreadTests simple text content response
test_toolreadA test tool
test_tool_with_loggingreadTests tool that emits log messages during execution
test_tool_with_progressreadTests tool that reports progress notifications
test_tools_change_notificationreadTests tool that emits log messages during execution
textreadText input
titlereadUser
update_product_pricewriteUpdate product price
updateswriteUpdate data
user_idreadUser ID
user_namereadUser
usernamereadUser name
weather_analysis_promptreadAnalyze weather data
weather_reporterreadReport weather tool
xreadFirst number
yreadSecond number
04

Trust audit

BLOCKgrade F · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (11 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
frontend/src/lib/tsx-executor.tsx:180
componentFunction = new Function(...contextKeys, functionBody);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
frontend/public/cursor.avif
cursor.avif
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
backend/src/vmcp/scripts/postgres_setup.py:38
print(f"VMCP_DATABASE_URL=postgresql://{user}:{password}@localhost:{port}/{database}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
backend/src/vmcp/server/middleware.py:552
logger.debug(f"🔍 MCP AUTH: Token length: {len(token)}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
backend/src/vmcp/server/vmcp_mcp_server.py:112
logger.debug(f"[VMCPServer] DEBUG: Extracted token: '{token[:20] if token else 'EMPTY'}...')")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/src/vmcp/mcps/mcp_auth_manager.py:93
callback_url: Optional[str] = None, headers: Optional[Dict[str, str]] = None, **kwargs) -> Dict[str, str]:
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/src/vmcp/mcps/mcp_auth_manager.py:100
if callback_url is None:
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/src/vmcp/mcps/mcp_auth_manager.py:101
callback_url = f"{settings.base_url}/api/otherservers/oauth/callback"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/src/vmcp/mcps/mcp_auth_manager.py:117
discovery_response = await self._discover_oauth_endpoints(server_url, callback_url)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/src/vmcp/mcps/mcp_auth_manager.py:131
registered_client_id = await self._register_oauth_client(registration_endpoint, callback_url)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
frontend/src/api/generated/client.gen.ts:17
baseUrl: 'http://0.0.0.0:8000'
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
backend/src/vmcp/data/demo_vmcps/svelte_coding_assistant_config.json:72
"src": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAACvdJREFUeJztXQuQVMUVHT5GCYmSDwaVMhQWmpSRRIEkJqmdFVQCRuRjCiVq8MMGKKTYGESEREAFhI
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
backend/src/vmcp/data/demo_vmcps/svelte_coding_assistant_config.json:103
"src": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAACvdJREFUeJztXQuQVMUVHT5GCYmSDwaVMhQWmpSRRIEkJqmdFVQCRuRjCiVq8MMGKKTYGESEREAFhI
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
backend/src/vmcp/data/demo_vmcps/svelte_coding_assistant_config.json:167
"src": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAACvdJREFUeJztXQuQVMUVHT5GCYmSDwaVMhQWmpSRRIEkJqmdFVQCRuRjCiVq8MMGKKTYGESEREAFhI
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
backend/src/vmcp/data/demo_vmcps/svelte_coding_assistant_config.json:251
"src": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAACvdJREFUeJztXQuQVMUVHT5GCYmSDwaVMhQWmpSRRIEkJqmdFVQCRuRjCiVq8MMGKKTYGESEREAFhI
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
backend/src/vmcp/data/demo_vmcps/svelte_coding_assistant_config.json:2382
"src": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGAAAABgCAYAAADimHc4AAAAAXNSR0IB2cksfwAAAAlwSFlzAAALEwAACxMBAJqcGAAACvdJREFUeJztXQuQVMUVHT5GCYmSDwaVMhQWmpSRRIEkJqmdFVQCRuRjCiVq8MMGKKTYGESEREAFhI
LOWInventory / provenance · inv.hidden_file · CWE-1104
backend/.coveragerc
.coveragerc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
backend/tests/test_server/test_http_server.py:815
file_hash = hashlib.md5(file).hexdigest()
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
backend/tests/conftest.py:280
print(f"✅ Test token verified: {token[:20]}...")
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
frontend/src/api/test_06_custom_tools_http.integration.test.ts:178
console.log(`\n📦 Test 6.4 - HTTP tool with Bearer token: ${createdVMCP.id}`)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
frontend/src/components/ui/theme-toggle.tsx:14
import { useTheme } from '../../contexts/theme-context';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
frontend/src/api/README.md:28
# Generate the API client (backend must be running at http://0.0.0.0:8080)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
frontend/src/api/README.md:32
npx openapi-ts -i http://0.0.0.0:8080/openapi.json -o ./src/api/generated
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
frontend/src/api/README.md:96
Make sure your backend is running at `http://0.0.0.0:8080` (or update the URL in package.json script)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
frontend/src/api/README.md:106
1. Fetch the OpenAPI spec from `http://0.0.0.0:8080/openapi.json`

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 83c836a6cbe7full audit observations/trust-audit/mcp-server/1xn-labs__1xn-ai-workflow-composer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0883c836a6cbe7BLOCKF60first audit
06

Questions

What is the 1xn AI Workflow Composer MCP server?

vMCP - Virtual Model Context Protocol

What tools does 1xn AI Workflow Composer expose?

153 in total: 142 read-only, 11 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is 1xn AI Workflow Composer safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (60/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does 1xn AI Workflow Composer need?

It reads VMCP_DUMMY_USER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does 1xn AI Workflow Composer run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as 1xn at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (83c836a6cbe7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement