Atlas / MCP servers / agiflow / aicode-toolkit

aicode-toolkitBLOCK

mcp/agiflow/aicode-toolkit

Toolkit for Coding Agents to work reliably with repo of any size.

Verdict
BLOCK
Grade
D
Trust score
60 /100
Exposed tools
79 77r · 2w · 0d
Transport
sse · stdio · streamable-http
License
AGPL-3.0
Stars
162
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@agiflowai/scaffold-mcp) [](https://opensource.org/licenses/AGPL-3.0) [](https://discord.gg/NsB6q9Vas9)

This repo provides:

  • project and feature scaffolding via templates
  • file-level design guidance before edits
  • rule-based review after edits
  • design-system discovery for frontend work

Why This Exists

As projects scale, conventions in docs like CLAUDE.md, AGENTS.md, and style guides become hard to keep concise and consistently applied by AI agents. This toolkit moves those conventions into reusable template configs (scaffold.yaml, architect.yaml, RULES.yaml) so agents can discover only the relevant guidance when needed.

Quick Start

Requirements:

  • Node.js >= 18
  • an MCP-compatible agent such as Claude Code, Cursor, or Gemini CLI

1. Initialize a Workspace

# Existing project
npx @agiflowai/aicode-toolkit init

# New project
npx @agiflowai/aicode-toolkit init --name my-app --project-type monolith

This creates templates/ and .toolkit/settings.yaml. Projects reference templates through sourceTemplate in project.json or .toolkit/settings.yaml.

2. Configure MCP

init can configure MCP automatically. For manual setup, add the servers you need to your agent config.

Example for Claude Code:

{
"mcpServers": {
"scaffold-mcp": {
"command": "npx",
"args": ["-y", "@agiflowai/scaffold-mcp", "mcp-serve", "--admin-enable"]
},
"architect-mcp": {
"command": "npx",
"args": [
"-y", "@agiflowai/architect-mcp", "mcp-serve",
"--admin-enable",
"--design-pattern-tool", "codex",
"
Read from source at commit 5805b16dc8adOBSERVED · 2026-09-22
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add style-system --env API_KEY=${API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} --env CODEX_API_KEY=${CODEX_API_KEY} --env TEST_API_KEY=${TEST_API_KEY} -- npx -y @agiflowai/[email protected]
claude-desktop
{
  "mcpServers": {
    "style-system": {
      "command": "npx",
      "args": [
        "-y",
        "@agiflowai/[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "AUTH_TOKEN": "${AUTH_TOKEN}",
        "CODEX_API_KEY": "${CODEX_API_KEY}",
        "TEST_API_KEY": "${TEST_API_KEY}"
      }
    }
  }
}
03

Exposed tools (79)

77 read · 2 write · 0 destructive.

ToolRiskDescription
CodexreadOpenAI Codex CLI agent
CursorreadCursor AI-first code editor
OpenSpecreadSpec-driven development for AI coding assistants
OtherreadOther coding agent or skip MCP configuration
READMEreadProject readme
allowed_toolreadAllowed
analyzereadAnalyze from prompt
appNamereadApp name
arg1readFirst argument
arg2readSecond argument
auto-skillreadAuto detected skill
auto_promptreadAuto prompt
blocked_toolreadBlocked
cached_toolreadCached tool description
code-reviewerreadReview code for best practices
complex-skillreadA multi-line\ndescription
configured-skillreadConfigured skill description
configured_promptreadConfigured prompt
describe_toolsreadMock describe tools
doc-generatorreadGenerate documentation
duplicate-namereadPrompt-based duplicate
existing_promptreadExisting prompt
failing-skillreadThis skill will fail
fallback-skillreadFallback prompt-based skill
filePathreadFile type to focus on (e.g.
fiveread5
fourread4
full_promptreadFull prompt with all properties
git_statusreadGet git status
list_toolsreadMock list tools
live_toolreadLive tool description
local-skillreadLocal skill
my-skillreadA skill description
my_promptreadPrompt from server A
my_toolreadMy tool description
oneread1
orphan-skillreadSkill with missing client
other_promptreadOther prompt
pageNamereadPage name
pdfread...
projectPathreadPath to the project (e.g.,
prompt-skillreadA prompt-based skill
prompt_many_argsreadPrompt with many arguments
prompt_no_argsreadPrompt without arguments
prompt_onereadFirst prompt
prompt_tworeadSecond prompt
prompt_with_argsreadPrompt with arguments
read_filereadRead a file
requestwriteDescribe the boilerplate template you want to create
review-skillreadReview changes
review_codereadReview code changes
scaffold-componentreadGenerate a new React component
scaffold-featurereadScaffold a feature
scaffold-nextjs-appreadNext.js application template
scaffold-routereadGenerate a new route
scaffold-servicereadService
scaffold-toolreadGenerate a new MCP tool
scaffold-vite-appreadVite application template
searchreadSearch alpha
search_docsreadSearch docs
service-patternread...
serviceNamereadService name
shared-namereadMCP tool
shared-skillreadPrompt-based version
shared_promptreadPrompt from server A
shared_toolreadTool from server A
sixread6
statusreadStatus beta
templateNamewriteSpecific template to scope the sync to (e.g.
threeread3
tool-namereadMCP tool
tool_onereadTool one description
tool_tworeadSecond tool
tworead2
unique-prompt-skillreadUnique prompt skill
unique-toolreadUnique tool
unique_promptreadUnique prompt
use_toolreadMock use tool
valid_toolreadValid tool
04

Trust audit

BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
apps/aicode-toolkit/src/commands/sync.ts:238
const parsed = yaml.load(content);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
apps/aicode-toolkit/src/services/TemplateSelectionService.ts:282
const scaffoldConfig = yaml.load(content) as {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/aicode-utils/src/services/TemplatesManagerService.ts:257
const base = yaml.load(baseContent) as ToolkitConfig;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/aicode-utils/src/services/TemplatesManagerService.ts:261
const local = yaml.load(localContent) as ToolkitConfig;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/aicode-utils/src/services/TemplatesManagerService.ts:275
return yaml.load(content) as ToolkitConfig;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/.env.example.liquid:2
{% if withDrizzle %}{% if databaseProvider == 'neon' %}DATABASE_URL=postgres://postgres:[email protected]:5432/main
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/.env.example.liquid:3
{% elsif databaseProvider == 'vercel-postgres' %}DATABASE_URL=postgres://default:[email protected]:5432/verceldb
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/.env.example.liquid:4
{% elsif databaseProvider == 'supabase' %}DATABASE_URL=postgres://postgres:[email protected]:5432/postgres
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/.env.example.liquid:5
{% else %}DATABASE_URL=postgres://postgres:postgres@localhost:5432/main
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
templates/nextjs-drizzle/docker-compose.yml.liquid:16
# - PostgreSQL: postgres://postgres:postgres@localhost:5432/main{% if databaseProvider == "neon" %}
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/nextjs-drizzle/.env.example.liquid
.env.example.liquid
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/nextjs-drizzle/.gitignore.liquid
.gitignore.liquid
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/nextjs-drizzle/public/.gitkeep.liquid
.gitkeep.liquid
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/nextjs-drizzle/src/db/migrations/.gitkeep.liquid
.gitkeep.liquid
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/typescript-mcp-package/.gitignore.liquid
.gitignore.liquid
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/hooks-adapter/src/services/ExecutionLogService.ts:324
const checksum = crypto.createHash('md5').update(content).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/hooks-adapter/tests/services/ExecutionLogService.test.ts:459
fileChecksum: crypto.createHash('md5').update(currentContent).digest('hex'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/commands/init.test.ts:2
import { resolveGeneratedSettingsValues, resolveOra } from '../../src/commands/init';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/commands/sync.test.ts:16
} from '../../src/commands/sync';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/services/CodingAgentService.test.ts:27
import { CodingAgentService } from '../../src/services/CodingAgentService';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/services/NewProjectService.test.ts:18
import { NewProjectService, RESERVED_PROJECT_NAMES } from '../../src/services/NewProjectService';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/aicode-toolkit/tests/services/TemplatesService.test.ts:19
import type { TemplateRepoConfig } from '../../src/services/TemplatesService';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/one-mcp/tests/utils/mcpConfigSchema.test.ts:811
url: 'https://169.254.169.254/latest/meta-data/',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/one-mcp/tests/utils/mcpConfigSchema.test.ts:913
it('should block IPv4-mapped IPv6 link-local (::ffff:169.254.169.254)', () => {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/one-mcp/tests/utils/mcpConfigSchema.test.ts:915
url: 'https://[::ffff:169.254.169.254]/latest/meta-data/',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha 5805b16dc8adfull audit observations/trust-audit/mcp-server/agiflow__aicode-toolkit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-225805b16dc8adBLOCKD60first audit
06

Questions

What is the aicode-toolkit MCP server?

Toolkit for Coding Agents to work reliably with repo of any size.

What tools does aicode-toolkit expose?

79 in total: 77 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is aicode-toolkit safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (60/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does aicode-toolkit need?

It reads API_KEY, AUTH_TOKEN, CODEX_API_KEY, TEST_API_KEY and TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does aicode-toolkit run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @agiflowai/style-system at 0.1.2.

How current is this page?

The grade is for one exact copy of the source (5805b16dc8ad), read on 2026-09-22. The repository is watched and re-audited when it changes.

Advertisement