AI Code ToolkitBLOCK
Toolkit for Coding Agents to work reliably with repo of any size.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@agiflowai/scaffold-mcp) [](https://opensource.org/licenses/AGPL-3.0) [](https://discord.gg/NsB6q9Vas9)
This repo provides:
- project and feature scaffolding via templates
- file-level design guidance before edits
- rule-based review after edits
- design-system discovery for frontend work
Why This Exists
As projects scale, conventions in docs like CLAUDE.md, AGENTS.md, and style guides become hard to keep concise and consistently applied by AI agents. This toolkit moves those conventions into reusable template configs (scaffold.yaml, architect.yaml, RULES.yaml) so agents can discover only the relevant guidance when needed.
Purpose-based plugins
For toolkit users who prefer an agent plugin, install only the workflows you need: aicode-bootstrap (project creation), aicode-develop (features and patterns), aicode-review (rules-based review), aicode-admin (authoring reusable configuration), or aicode-design (frontend discovery). Self-contained plugin roots are under plugins/ and work with the Claude Code/Cowork marketplace, Codex marketplace, and local Gemini extension installation; Cursor/Grok and Cowork's local stdio runtime still need client acceptance tests. Read the installation and compatibility guide before use. These bundles group workflows rather than restrict tool access.
Initialize the consumer project before starting a scaffold-backed plugin with interactive npx -y @agiflowai/[email protected] init --skip-mcp; plugin installation does not supply templates. Keep MCP server cwd in the consumer workspace. P
83167176f97bOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add style-system --env API_KEY=${API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} --env CODEX_API_KEY=${CODEX_API_KEY} --env TEST_API_KEY=${TEST_API_KEY} -- npx -y @agiflowai/[email protected]{
"mcpServers": {
"style-system": {
"command": "npx",
"args": [
"-y",
"@agiflowai/[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"AUTH_TOKEN": "${AUTH_TOKEN}",
"CODEX_API_KEY": "${CODEX_API_KEY}",
"TEST_API_KEY": "${TEST_API_KEY}"
}
}
}
}Exposed tools (80)
78 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Codex | read | OpenAI Codex CLI agent |
Cursor | read | Cursor AI-first code editor |
OpenSpec | read | Spec-driven development for AI coding assistants |
Other | read | Other coding agent or skip MCP configuration |
README | read | Project readme |
allowed_tool | read | Allowed |
analyze | read | Analyze from prompt |
appName | read | App name |
arg1 | read | First argument |
arg2 | read | Second argument |
auto-skill | read | Auto detected skill |
auto_prompt | read | Auto prompt |
blocked_tool | read | Blocked |
cached_tool | read | Cached tool description |
code-reviewer | read | Review code for best practices |
complex-skill | read | A multi-line\ndescription |
configured-skill | read | Configured skill description |
configured_prompt | read | Configured prompt |
describe_tools | read | Mock describe tools |
doc-generator | read | Generate documentation |
duplicate-name | read | Prompt-based duplicate |
existing_prompt | read | Existing prompt |
failing-skill | read | This skill will fail |
fallback-skill | read | Fallback prompt-based skill |
filePath | read | File type to focus on (e.g. |
five | read | 5 |
four | read | 4 |
full_prompt | read | Full prompt with all properties |
git_status | read | Get git status |
list_tools | read | Mock list tools |
live_tool | read | Live tool description |
local-skill | read | Local skill |
my-skill | read | A skill description |
my_prompt | read | Prompt from server A |
my_tool | read | My tool description |
one | read | 1 |
orphan-skill | read | Skill with missing client |
other_prompt | read | Other prompt |
pageName | read | Page name |
pdf | read | ... |
projectPath | read | Path to the project (e.g., |
prompt-skill | read | A prompt-based skill |
prompt_many_args | read | Prompt with many arguments |
prompt_no_args | read | Prompt without arguments |
prompt_one | read | First prompt |
prompt_two | read | Second prompt |
prompt_with_args | read | Prompt with arguments |
read_file | read | Read a file |
request | write | Describe the boilerplate template you want to create |
review-skill | read | Review changes |
review_code | read | Review code changes |
scaffold-component | read | Generate a new React component |
scaffold-feature | read | Scaffold a feature |
scaffold-nextjs-app | read | Next.js application template |
scaffold-route | read | Generate a new route |
scaffold-service | read | Service |
scaffold-tool | read | Generate a new MCP tool |
scaffold-vite-app | read | Vite application template |
search | read | Search alpha |
search_docs | read | Search docs |
service-pattern | read | ... |
serviceName | read | Service name |
shared-name | read | MCP tool |
shared-skill | read | Prompt-based version |
shared_prompt | read | Prompt from server A |
shared_tool | read | Tool from server A |
six | read | 6 |
status | read | Status beta |
templateName | write | Specific template to scope the sync to (e.g. |
test-boilerplate | read | Test boilerplate |
three | read | 3 |
tool-name | read | MCP tool |
tool_one | read | Tool one description |
tool_two | read | Second tool |
two | read | 2 |
unique-prompt-skill | read | Unique prompt skill |
unique-tool | read | Unique tool |
unique_prompt | read | Unique prompt |
use_tool | read | Mock use tool |
valid_tool | read | Valid tool |
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
const parsed = yaml.load(content);
const scaffoldConfig = yaml.load(content) as {const base = yaml.load(baseContent) as ToolkitConfig;
const local = yaml.load(localContent) as ToolkitConfig;
return yaml.load(content) as ToolkitConfig;
{% if withDrizzle %}{% if databaseProvider == 'neon' %}DATABASE_URL=postgres://postgres:[email protected]:5432/main{% elsif databaseProvider == 'vercel-postgres' %}DATABASE_URL=postgres://default:[email protected]:5432/verceldb{% elsif databaseProvider == 'supabase' %}DATABASE_URL=postgres://postgres:[email protected]:5432/postgres{% else %}DATABASE_URL=postgres://postgres:postgres@localhost:5432/main# - PostgreSQL: postgres://postgres:postgres@localhost:5432/main{% if databaseProvider == "neon" %}.oxfmtrc.json
.oxlintrc.json
.env.example.liquid
.gitignore.liquid
.gitkeep.liquid
const checksum = crypto.createHash('md5').update(content).digest('hex');fileChecksum: crypto.createHash('md5').update(currentContent).digest('hex'),import { resolveGeneratedSettingsValues, resolveOra } from '../../src/commands/init';} from '../../src/commands/sync';
import { CodingAgentService } from '../../src/services/CodingAgentService';import { NewProjectService, RESERVED_PROJECT_NAMES } from '../../src/services/NewProjectService';import type { TemplateRepoConfig } from '../../src/services/TemplatesService';url: 'https://169.254.169.254/latest/meta-data/',
it('should block IPv4-mapped IPv6 link-local (::ffff:169.254.169.254)', () => {url: 'https://[::ffff:169.254.169.254]/latest/meta-data/',
Gates applied: no_behavioural_pass.
83167176f97bfull audit observations/trust-audit/mcp-server/agiflow__ai-code-toolkit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 83167176f97b | BLOCK | D | 60 | first audit |
Questions
What is the AI Code Toolkit MCP server?
Toolkit for Coding Agents to work reliably with repo of any size.
What tools does AI Code Toolkit expose?
80 in total: 78 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is AI Code Toolkit safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does AI Code Toolkit need?
It reads API_KEY, AUTH_TOKEN, CODEX_API_KEY, TEST_API_KEY and TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does AI Code Toolkit run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @agiflowai/style-system at 0.2.1.
How current is this page?
The grade is for one exact copy of the source (83167176f97b), read on 2026-10-06. The repository is watched and re-audited when it changes.