aicode-toolkitBLOCK
Toolkit for Coding Agents to work reliably with repo of any size.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@agiflowai/scaffold-mcp) [](https://opensource.org/licenses/AGPL-3.0) [](https://discord.gg/NsB6q9Vas9)
This repo provides:
- project and feature scaffolding via templates
- file-level design guidance before edits
- rule-based review after edits
- design-system discovery for frontend work
Why This Exists
As projects scale, conventions in docs like CLAUDE.md, AGENTS.md, and style guides become hard to keep concise and consistently applied by AI agents. This toolkit moves those conventions into reusable template configs (scaffold.yaml, architect.yaml, RULES.yaml) so agents can discover only the relevant guidance when needed.
Quick Start
Requirements:
- Node.js >= 18
- an MCP-compatible agent such as Claude Code, Cursor, or Gemini CLI
1. Initialize a Workspace
# Existing project npx @agiflowai/aicode-toolkit init # New project npx @agiflowai/aicode-toolkit init --name my-app --project-type monolith
This creates templates/ and .toolkit/settings.yaml. Projects reference templates through sourceTemplate in project.json or .toolkit/settings.yaml.
2. Configure MCP
init can configure MCP automatically. For manual setup, add the servers you need to your agent config.
Example for Claude Code:
{
"mcpServers": {
"scaffold-mcp": {
"command": "npx",
"args": ["-y", "@agiflowai/scaffold-mcp", "mcp-serve", "--admin-enable"]
},
"architect-mcp": {
"command": "npx",
"args": [
"-y", "@agiflowai/architect-mcp", "mcp-serve",
"--admin-enable",
"--design-pattern-tool", "codex",
"5805b16dc8adOBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add style-system --env API_KEY=${API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} --env CODEX_API_KEY=${CODEX_API_KEY} --env TEST_API_KEY=${TEST_API_KEY} -- npx -y @agiflowai/[email protected]{
"mcpServers": {
"style-system": {
"command": "npx",
"args": [
"-y",
"@agiflowai/[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"AUTH_TOKEN": "${AUTH_TOKEN}",
"CODEX_API_KEY": "${CODEX_API_KEY}",
"TEST_API_KEY": "${TEST_API_KEY}"
}
}
}
}Exposed tools (79)
77 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Codex | read | OpenAI Codex CLI agent |
Cursor | read | Cursor AI-first code editor |
OpenSpec | read | Spec-driven development for AI coding assistants |
Other | read | Other coding agent or skip MCP configuration |
README | read | Project readme |
allowed_tool | read | Allowed |
analyze | read | Analyze from prompt |
appName | read | App name |
arg1 | read | First argument |
arg2 | read | Second argument |
auto-skill | read | Auto detected skill |
auto_prompt | read | Auto prompt |
blocked_tool | read | Blocked |
cached_tool | read | Cached tool description |
code-reviewer | read | Review code for best practices |
complex-skill | read | A multi-line\ndescription |
configured-skill | read | Configured skill description |
configured_prompt | read | Configured prompt |
describe_tools | read | Mock describe tools |
doc-generator | read | Generate documentation |
duplicate-name | read | Prompt-based duplicate |
existing_prompt | read | Existing prompt |
failing-skill | read | This skill will fail |
fallback-skill | read | Fallback prompt-based skill |
filePath | read | File type to focus on (e.g. |
five | read | 5 |
four | read | 4 |
full_prompt | read | Full prompt with all properties |
git_status | read | Get git status |
list_tools | read | Mock list tools |
live_tool | read | Live tool description |
local-skill | read | Local skill |
my-skill | read | A skill description |
my_prompt | read | Prompt from server A |
my_tool | read | My tool description |
one | read | 1 |
orphan-skill | read | Skill with missing client |
other_prompt | read | Other prompt |
pageName | read | Page name |
pdf | read | ... |
projectPath | read | Path to the project (e.g., |
prompt-skill | read | A prompt-based skill |
prompt_many_args | read | Prompt with many arguments |
prompt_no_args | read | Prompt without arguments |
prompt_one | read | First prompt |
prompt_two | read | Second prompt |
prompt_with_args | read | Prompt with arguments |
read_file | read | Read a file |
request | write | Describe the boilerplate template you want to create |
review-skill | read | Review changes |
review_code | read | Review code changes |
scaffold-component | read | Generate a new React component |
scaffold-feature | read | Scaffold a feature |
scaffold-nextjs-app | read | Next.js application template |
scaffold-route | read | Generate a new route |
scaffold-service | read | Service |
scaffold-tool | read | Generate a new MCP tool |
scaffold-vite-app | read | Vite application template |
search | read | Search alpha |
search_docs | read | Search docs |
service-pattern | read | ... |
serviceName | read | Service name |
shared-name | read | MCP tool |
shared-skill | read | Prompt-based version |
shared_prompt | read | Prompt from server A |
shared_tool | read | Tool from server A |
six | read | 6 |
status | read | Status beta |
templateName | write | Specific template to scope the sync to (e.g. |
three | read | 3 |
tool-name | read | MCP tool |
tool_one | read | Tool one description |
tool_two | read | Second tool |
two | read | 2 |
unique-prompt-skill | read | Unique prompt skill |
unique-tool | read | Unique tool |
unique_prompt | read | Unique prompt |
use_tool | read | Mock use tool |
valid_tool | read | Valid tool |
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
const parsed = yaml.load(content);
const scaffoldConfig = yaml.load(content) as {const base = yaml.load(baseContent) as ToolkitConfig;
const local = yaml.load(localContent) as ToolkitConfig;
return yaml.load(content) as ToolkitConfig;
{% if withDrizzle %}{% if databaseProvider == 'neon' %}DATABASE_URL=postgres://postgres:[email protected]:5432/main{% elsif databaseProvider == 'vercel-postgres' %}DATABASE_URL=postgres://default:[email protected]:5432/verceldb{% elsif databaseProvider == 'supabase' %}DATABASE_URL=postgres://postgres:[email protected]:5432/postgres{% else %}DATABASE_URL=postgres://postgres:postgres@localhost:5432/main# - PostgreSQL: postgres://postgres:postgres@localhost:5432/main{% if databaseProvider == "neon" %}.env.example.liquid
.gitignore.liquid
.gitkeep.liquid
.gitkeep.liquid
.gitignore.liquid
const checksum = crypto.createHash('md5').update(content).digest('hex');fileChecksum: crypto.createHash('md5').update(currentContent).digest('hex'),import { resolveGeneratedSettingsValues, resolveOra } from '../../src/commands/init';} from '../../src/commands/sync';
import { CodingAgentService } from '../../src/services/CodingAgentService';import { NewProjectService, RESERVED_PROJECT_NAMES } from '../../src/services/NewProjectService';import type { TemplateRepoConfig } from '../../src/services/TemplatesService';url: 'https://169.254.169.254/latest/meta-data/',
it('should block IPv4-mapped IPv6 link-local (::ffff:169.254.169.254)', () => {url: 'https://[::ffff:169.254.169.254]/latest/meta-data/',
Gates applied: no_behavioural_pass.
5805b16dc8adfull audit observations/trust-audit/mcp-server/agiflow__aicode-toolkit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | 5805b16dc8ad | BLOCK | D | 60 | first audit |
Questions
What is the aicode-toolkit MCP server?
Toolkit for Coding Agents to work reliably with repo of any size.
What tools does aicode-toolkit expose?
79 in total: 77 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is aicode-toolkit safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does aicode-toolkit need?
It reads API_KEY, AUTH_TOKEN, CODEX_API_KEY, TEST_API_KEY and TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does aicode-toolkit run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @agiflowai/style-system at 0.1.2.
How current is this page?
The grade is for one exact copy of the source (5805b16dc8ad), read on 2026-09-22. The repository is watched and re-audited when it changes.