Atlas / MCP servers / allaboutai-yt / All About AI

All About AIBLOCK

mcp/allaboutai-yt/all-about-ai

All About AI MCP Servers

Verdict
BLOCK
Grade
D
Trust score
67 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
81
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This repository contains MCP (Model Context Protocol) servers for integrating with OpenAI's o1 model and Flux capabilities.

Server Configurations

OpenAI o1 MCP Server

The o1 server enables interaction with OpenAI's o1 preview model through the MCP protocol.

{
"mcpServers": {
"openai": {
"command": "openai-server",
"env": {
"OPENAI_API_KEY": "apikey"
}
}
}
}

Key features:

  • Direct access to o1-preview model
  • Streaming support
  • Temperature and top_p parameter control
  • System message configuration

Flux MCP Server

The Flux server provides integration with Flux capabilities through MCP.

{
"mcpServers": {
"flux": {
"command": "flux-server",
"env": {
"REPLICATE_API_TOKEN": "your-replicate-token"
}
}
}
}

Key features:

  • SOTA Image Model

Usage

  1. Clone or Fork Server
git clone https://github.com/AllAboutAI-YT/mcp-servers.git
  1. Set up environment variables in your .env file:
FLUX_API_KEY=your_flux_key_here
  1. Start the servers using the configurations above.

Security

  • Store API keys securely
  • Use environment variables for sensitive data
  • Follow security best practices in SECURITY.md

License

MIT License - See LICENSE file for details.

Read from source at commit d2f8dbd6303fOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add openai-server --env OPENAI_API_KEY=${OPENAI_API_KEY} --env REPLICATE_API_TOKEN=${REPLICATE_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "openai-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "REPLICATE_API_TOKEN": "${REPLICATE_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
chat_completionreadGenerate text using OpenAI
generate_imagereadGenerate an image using the Flux model
04

Trust audit

BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (10)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp.md:52
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp.md:56
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp.md:82
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp.md:100
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp.md:113
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
flux-server/package.json
dotenv, node-fetch, replicate, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
openai-server/package.json
dotenv, openai, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mcp.md:348
# Load environment variables
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d2f8dbd6303ffull audit observations/trust-audit/mcp-server/allaboutai-yt__all-about-ai.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d2f8dbd6303fBLOCKD67first audit
06

Questions

What is the All About AI MCP server?

All About AI MCP Servers

What tools does All About AI expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is All About AI safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (67/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does All About AI need?

It reads OPENAI_API_KEY and REPLICATE_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does All About AI run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as openai-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (d2f8dbd6303f), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement