Atlas / MCP servers / agiflow / AI Code Toolkit

AI Code ToolkitBLOCK

mcp/agiflow/ai-code-toolkit

Toolkit for Coding Agents to work reliably with repo of any size.

Verdict
BLOCK
Grade
D
Trust score
60 /100
Exposed tools
80 78r · 2w · 0d
Transport
sse · stdio · streamable-http
License
AGPL-3.0
Stars
161
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@agiflowai/scaffold-mcp) [](https://opensource.org/licenses/AGPL-3.0) [](https://discord.gg/NsB6q9Vas9)

This repo provides:

  • project and feature scaffolding via templates
  • file-level design guidance before edits
  • rule-based review after edits
  • design-system discovery for frontend work

Why This Exists

As projects scale, conventions in docs like CLAUDE.md, AGENTS.md, and style guides become hard to keep concise and consistently applied by AI agents. This toolkit moves those conventions into reusable template configs (scaffold.yaml, architect.yaml, RULES.yaml) so agents can discover only the relevant guidance when needed.

Purpose-based plugins

For toolkit users who prefer an agent plugin, install only the workflows you need: aicode-bootstrap (project creation), aicode-develop (features and patterns), aicode-review (rules-based review), aicode-admin (authoring reusable configuration), or aicode-design (frontend discovery). Self-contained plugin roots are under plugins/ and work with the Claude Code/Cowork marketplace, Codex marketplace, and local Gemini extension installation; Cursor/Grok and Cowork's local stdio runtime still need client acceptance tests. Read the installation and compatibility guide before use. These bundles group workflows rather than restrict tool access.

Initialize the consumer project before starting a scaffold-backed plugin with interactive npx -y @agiflowai/[email protected] init --skip-mcp; plugin installation does not supply templates. Keep MCP server cwd in the consumer workspace. P

Read from source at commit 83167176f97bOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add style-system --env API_KEY=${API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} --env CODEX_API_KEY=${CODEX_API_KEY} --env TEST_API_KEY=${TEST_API_KEY} -- npx -y @agiflowai/[email protected]
claude-desktop
{
  "mcpServers": {
    "style-system": {
      "command": "npx",
      "args": [
        "-y",
        "@agiflowai/[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "AUTH_TOKEN": "${AUTH_TOKEN}",
        "CODEX_API_KEY": "${CODEX_API_KEY}",
        "TEST_API_KEY": "${TEST_API_KEY}"
      }
    }
  }
}
03

Exposed tools (80)

78 read · 2 write · 0 destructive.

ToolRiskDescription
CodexreadOpenAI Codex CLI agent
CursorreadCursor AI-first code editor
OpenSpecreadSpec-driven development for AI coding assistants
OtherreadOther coding agent or skip MCP configuration
READMEreadProject readme
allowed_toolreadAllowed
analyzereadAnalyze from prompt
appNamereadApp name
arg1readFirst argument
arg2readSecond argument
auto-skillreadAuto detected skill
auto_promptreadAuto prompt
blocked_toolreadBlocked
cached_toolreadCached tool description
code-reviewerreadReview code for best practices
complex-skillreadA multi-line\ndescription
configured-skillreadConfigured skill description
configured_promptreadConfigured prompt
describe_toolsreadMock describe tools
doc-generatorreadGenerate documentation
duplicate-namereadPrompt-based duplicate
existing_promptreadExisting prompt
failing-skillreadThis skill will fail
fallback-skillreadFallback prompt-based skill
filePathreadFile type to focus on (e.g.
fiveread5
fourread4
full_promptreadFull prompt with all properties
git_statusreadGet git status
list_toolsreadMock list tools
live_toolreadLive tool description
local-skillreadLocal skill
my-skillreadA skill description
my_promptreadPrompt from server A
my_toolreadMy tool description
oneread1
orphan-skillreadSkill with missing client
other_promptreadOther prompt
pageNamereadPage name
pdfread...
projectPathreadPath to the project (e.g.,
prompt-skillreadA prompt-based skill
prompt_many_argsreadPrompt with many arguments
prompt_no_argsreadPrompt without arguments
prompt_onereadFirst prompt
prompt_tworeadSecond prompt
prompt_with_argsreadPrompt with arguments
read_filereadRead a file
requestwriteDescribe the boilerplate template you want to create
review-skillreadReview changes
review_codereadReview code changes
scaffold-componentreadGenerate a new React component
scaffold-featurereadScaffold a feature
scaffold-nextjs-appreadNext.js application template
scaffold-routereadGenerate a new route
scaffold-servicereadService
scaffold-toolreadGenerate a new MCP tool
scaffold-vite-appreadVite application template
searchreadSearch alpha
search_docsreadSearch docs
service-patternread...
serviceNamereadService name
shared-namereadMCP tool
shared-skillreadPrompt-based version
shared_promptreadPrompt from server A
shared_toolreadTool from server A
sixread6
statusreadStatus beta
templateNamewriteSpecific template to scope the sync to (e.g.
test-boilerplatereadTest boilerplate
threeread3
tool-namereadMCP tool
tool_onereadTool one description
tool_tworeadSecond tool
tworead2
unique-prompt-skillreadUnique prompt skill
unique-toolreadUnique tool
unique_promptreadUnique prompt
use_toolreadMock use tool
valid_toolreadValid tool
04

Trust audit

BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
apps/aicode-toolkit/src/commands/sync.ts:238
const parsed = yaml.load(content);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
apps/aicode-toolkit/src/services/TemplateSelectionService.ts:282
const scaffoldConfig = yaml.load(content) as {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/aicode-utils/src/services/TemplatesManagerService.ts:256
const base = yaml.load(baseContent) as ToolkitConfig;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/aicode-utils/src/services/TemplatesManagerService.ts:260
const local = yaml.load(localContent) as ToolkitConfig;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/aicode-utils/src/services/TemplatesManagerService.ts:274
return yaml.load(content) as ToolkitConfig;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/.env.example.liquid:2
{% if withDrizzle %}{% if databaseProvider == 'neon' %}DATABASE_URL=postgres://postgres:[email protected]:5432/main
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/.env.example.liquid:3
{% elsif databaseProvider == 'vercel-postgres' %}DATABASE_URL=postgres://default:[email protected]:5432/verceldb
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/.env.example.liquid:4
{% elsif databaseProvider == 'supabase' %}DATABASE_URL=postgres://postgres:[email protected]:5432/postgres
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/.env.example.liquid:5
{% else %}DATABASE_URL=postgres://postgres:postgres@localhost:5432/main
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/docker-compose.yml.liquid:16
# - PostgreSQL: postgres://postgres:postgres@localhost:5432/main{% if databaseProvider == "neon" %}
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxfmtrc.json
.oxfmtrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/nextjs-drizzle/.env.example.liquid
.env.example.liquid
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/nextjs-drizzle/.gitignore.liquid
.gitignore.liquid
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/nextjs-drizzle/public/.gitkeep.liquid
.gitkeep.liquid
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/hooks-adapter/src/services/ExecutionLogService.ts:324
const checksum = crypto.createHash('md5').update(content).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/hooks-adapter/tests/services/ExecutionLogService.test.ts:460
fileChecksum: crypto.createHash('md5').update(currentContent).digest('hex'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/commands/init.test.ts:2
import { resolveGeneratedSettingsValues, resolveOra } from '../../src/commands/init';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/commands/sync.test.ts:16
} from '../../src/commands/sync';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/services/CodingAgentService.test.ts:27
import { CodingAgentService } from '../../src/services/CodingAgentService';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/services/NewProjectService.test.ts:18
import { NewProjectService, RESERVED_PROJECT_NAMES } from '../../src/services/NewProjectService';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/services/TemplatesService.test.ts:19
import type { TemplateRepoConfig } from '../../src/services/TemplatesService';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/one-mcp/tests/utils/mcpConfigSchema.test.ts:831
url: 'https://169.254.169.254/latest/meta-data/',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/one-mcp/tests/utils/mcpConfigSchema.test.ts:933
it('should block IPv4-mapped IPv6 link-local (::ffff:169.254.169.254)', () => {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/one-mcp/tests/utils/mcpConfigSchema.test.ts:935
url: 'https://[::ffff:169.254.169.254]/latest/meta-data/',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 83167176f97bfull audit observations/trust-audit/mcp-server/agiflow__ai-code-toolkit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0683167176f97bBLOCKD60first audit
06

Questions

What is the AI Code Toolkit MCP server?

Toolkit for Coding Agents to work reliably with repo of any size.

What tools does AI Code Toolkit expose?

80 in total: 78 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is AI Code Toolkit safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (60/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does AI Code Toolkit need?

It reads API_KEY, AUTH_TOKEN, CODEX_API_KEY, TEST_API_KEY and TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AI Code Toolkit run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @agiflowai/style-system at 0.2.1.

How current is this page?

The grade is for one exact copy of the source (83167176f97b), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement