Atlas / MCP servers / apra-labs / Apra Fleet

Apra FleetBLOCK

mcp/apra-labs/apra-fleet

AI agents that write code, review each other's work, and coordinate across your machines

Verdict
BLOCK
Grade
F
Trust score
27 /100
Exposed tools
63 38r · 20w · 5d
Transport
stdio · streamable-http
License
NOASSERTION
Stars
101
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Run a fleet of AI agents across your devices, your providers, your workflows.

What Kubernetes did for containers, apra-fleet does for AI agents: scheduling, credentials, isolation, and observability for an agentic workforce -- on any machine, anywhere, using every LLM provider at once.

[](https://github.com/Apra-Labs/apra-fleet/actions/workflows/ci.yml) [](https://opensource.org/licenses/Apache-2.0) [](https://github.com/Apra-Labs/apra-fleet/releases) [](https://modelcontextprotocol.io) [](https://deepwiki.com/Apra-Labs/apra-fleet)

Quick Start - Live Demo - How It Works - fleet-sprint Getting Started Guide - Website

This repository is built by the product you are looking at. An autonomous apra-fleet workflow plans, codes, reviews, tests, and ships this codebase in multi-hour sprints -- filing bugs against itself and fixing them. The recording abo
Read from source at commit c474ac4e829eOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add fleet-api-contract --env APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE=${APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE} --env APRA_FLEET_BD_TEMPLATE_KEY=${APRA_FLEET_BD_TEMPLATE_KEY} --env CLAUDE_CODE_OAUTH_TOKEN=${CLAUDE_CODE_OAUTH_TOKEN} --env E2E_GH_TOKEN=${E2E_GH_TOKEN} -- npx -y @apralabs/[email protected]
claude-desktop
{
  "mcpServers": {
    "fleet-api-contract": {
      "command": "npx",
      "args": [
        "-y",
        "@apralabs/[email protected]"
      ],
      "env": {
        "APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE": "${APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE}",
        "APRA_FLEET_BD_TEMPLATE_KEY": "${APRA_FLEET_BD_TEMPLATE_KEY}",
        "CLAUDE_CODE_OAUTH_TOKEN": "${CLAUDE_CODE_OAUTH_TOKEN}",
        "E2E_GH_TOKEN": "${E2E_GH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (63)

38 read · 20 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
Originalreadorig desc
auto-sprintreadMulti-cycle sprint workflow: plan -> develop -> test -> harvest. Pass args as a JSON object with required
child_id_allocatorreadGlobal child-bead-id allocator hosted on the fleet server, so sprints launched WITHOUT a supervisor never mint the same child id under a shared parent.
cloud_controlwriteManually start, stop, or check status of a cloud fleet member. Start waits until the member is ready; stop is immediate.
code_contextreadGet callers, callees, and execution flows for a symbol. Prefer this over Glob/Grep/file reads for structural questions (symbol lookup, call chains, impact) -- the answer is pre-indexed.
code_flowreadFind process flows (entry -> steps -> exit) matching a name or endpoints. Prefer this over manually tracing call chains across files -- the flows are pre-indexed.
code_graphreadTrace the call graph for a symbol. Returns callers and callees across the codebase. Prefer this over Glob/Grep/file reads for structural questions (symbol lookup, call chains, impact) -- the answer is pre-indexed.
code_impactreadFind what is affected by changes to a symbol. Prefer this over Glob/Grep/file reads for structural questions (symbol lookup, call chains, impact) -- the answer is pre-indexed.
code_mapreadGet the architectural map of a repository: module communities with their key symbols and files, ranked by size. Prefer this over directory listings or file reads when orienting in an unfamiliar codebase -- the answer is pre-indexed.
code_queryreadSearch the codebase for symbols, patterns, or concepts using natural language or code patterns. Prefer this over Glob/Grep/file reads for structural questions (symbol lookup, call chains, impact) -- the answer is pre-indexed.
code_testsreadFind the test files and test functions that exercise a symbol (transitive callers, depth 2). Use this to run targeted tests for the code you changed instead of the full suite. Prefer this over Grep for test discovery -- the call graph is pre-indexed.
compose_permissionswriteSet up and deliver the right permissions to a member for their role or tags. Automatically tailors permissions to the project type. Pass tags (e.g. [
credential_store_deletedestructiveDelete a named credential from the store (both session and persistent tiers).
credential_store_listreadList all stored credentials (names and metadata only — no values).
credential_store_setwriteCollect a secret from the user out-of-band and store it. Returns a handle (sec://NAME) and scope. Use {{secret.NAME}} tokens in execute_command to inject the value.
credential_store_updatewriteUpdate metadata (members, TTL, network policy) on an existing credential without re-entering the secret.
dolt_push_mutexwriteGlobal cross-sprint dolt push mutex hosted on the fleet server, so sprints launched WITHOUT a supervisor still serialize their
execute_commandwriteRun a shell command on a member. Use for quick tasks like installing packages, checking versions, or running scripts.
execute_promptwriteRun an AI prompt on a member. Supports session resume for multi-turn conversations. On success, the reply text is returned in structuredContent.response (alongside usage and sessionId).
fleet_statusreadGet status of all fleet members. Use json format for structured data.
get_member_model_pricingreadReturns a member
hello-worldreadplain non-se workflow, no sprint/beads domain concepts
hello-world-workflowreadA sample workflow testing the fleet-workflow engine
kb_captureread
kb_contextreadCheck freshness of files against the knowledge bank. Returns {fresh, stale, missing} -- fresh files can be skipped, stale/missing files must be re-read.
kb_exportreadExport CONFIRMED, non-superseded, non-stale KB entries to a canonical bible file (stable field set, deterministic id order, ASCII-safe). scope=
kb_feedbackreadDownvote a KB entry that proved wrong in practice: { id, reason, role? }. Marks the entry stale=1 + flagged_for_review=1 and appends an ASCII feedback note
kb_freshness_sweepread
kb_harvestreadScan a session transcript for learnings and capture them into the KB. Returns {entries_captured, entries_updated, entries_skipped}. Extracted entries are UNVERIFIED and author=harvest, source=harvest.
kb_importwrite
kb_invalidatereadMark context-cache entries stale for the given file paths. Call after modifying files to ensure the KB reflects the current state.
kb_listwriteList KB entries by confidence/type/module/symbol/tag -- audit the CONFIRMED set (or any tier) without touching FTS ranking or use_count telemetry. Excludes superseded/stale entries. Returns {results, total} with each entry as {id, type, confidence, title, summary, symbols, source_files}.
kb_promotereadUpgrade KB entry confidence: UNVERIFIED -> INFERRED -> CONFIRMED. Appends promotion note to content as evidence trail. CONFIRMED entries are no-op.
kb_queryread
kb_reconcile_prefilterreadMechanical hash-basis prefilter over all flagged contradiction pairs (including stale members -- see flaggedPairs liveness contract). Re-hashes both sides of each pair against the CURRENT worktree: exactly one side fully matching wins mechanically via kb_resolve_contradiction (evidence
kb_resolve_contradictionread
kb_session_primereadPrime a session with KB context. Returns session_warm status, stale files needing re-read, top KB entries, and recommended GitNexus calls.
kb_setupwriteSet up KB: install git post-commit hook, write provider config, store remote credentials encrypted. Run once per repo.
kb_statsread
list_membersreadList all fleet members and their current status. Use format=
member_detailreadGet detailed status for one member: connectivity, AI version, authentication, active session, resources, and git branch.
member_reservationdestructiveReserve, release, or force-release exclusive ownership of a member for a sprint (server-side reservation; does not yet block dispatch).
monitor_taskreadCheck status of a long-running background task on a cloud member. Optionally stop the cloud instance automatically when the task completes.
provision_llm_authwriteAuthenticate a fleet member so it can run prompts. Copies your current login session to the member, or deploys an API key if provided. Run this before execute_prompt if the member reports no authentication.
provision_vcs_authwriteSet up git access credentials on a member. Supports GitHub, Bitbucket, and Azure DevOps. Tests connectivity after setup.
receive_filesreadDownload files from a member to a local directory. Always batch multiple files into a single call — never invoke repeatedly for individual files.
register_memberwriteAdd a machine to the fleet. Use member_type
remove_memberdestructiveRemove a member from the fleet.
report_statusreadCalled by a connected interactive member session (not the orchestrator) to report it is done responding to a send_message notification and available again (
respond_to_messagereadCalled by a connected interactive member session to respond to a prompt delivered via execute_prompt or send_message. Pass reply_to as the msgid from the original notification\
revoke_vcs_authdestructiveRemove VCS credentials from a member. Specify the provider (github, bitbucket, or azure-devops) to revoke.
send_emailwriteSend an email. Pass provider config inline (provider, from, and for SMTP: host, port, user, secure). Secrets (API keys, passwords) are resolved from the credential store -- store them first with credential_store_set (names:
send_fileswriteTransfer local files to a member. Always batch multiple files into a single call — never invoke repeatedly for individual files.
send_messagewriteSend a task message to a connected interactive member session via SSE. Returns the message ID.
setup_git_appread
setup_ssh_keyreadGenerate an SSH key pair and migrate a member from password to key-based authentication.
shutdown_serverwriteGracefully shut down the MCP server. Run /mcp afterwards to start a fresh instance with the latest code.
sprint-runnerreadA skeleton sprint runner workflow imitating the core logic of auto-sprint runner.js using new workflow primitives
stop_promptdestructiveKill the active LLM process on a member. Always call TaskStop on the dispatching background agent after calling this.
update_llm_cliwriteUpdate or install the AI provider CLI on members. Omit member to update all online members at once. Use install_if_missing to install on members that don
update_memberwriteChange a member
vcs_credential_execwriteRun a credential-requiring git/VCS command on a member WITHOUT ever learning the credential. Put one of two literal placeholders where the token belongs: {{vcs_token}}, referenced BARE (never inside your own quotes) -- the server substitutes it already escaped AND quoted for that member\
versionreadReturns the installed apra-fleet server version
04

Trust audit

BLOCKgrade F · trust 27/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/os/linux.ts:314
'mkdir -p ~/.ssh',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/os/linux.ts:315
'chmod 700 ~/.ssh',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/os/linux.ts:316
'touch ~/.ssh/authorized_keys',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/os/linux.ts:317
'chmod 600 ~/.ssh/authorized_keys',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/os/linux.ts:318
`echo ${escaped} >> ~/.ssh/authorized_keys`,
Why it matters. touches a credential store
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/apra-fleet-se/fleet-sprint/dolt-sync.mjs:442
const { command, log = () => {}, verify = false } = opts;
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docker-compose.hub-service.yml:34
HUB_DATABASE_URL: postgres://hub:hub-dev-password@db:5432/apra_fleet_hub
HIGHPrompt injection · prompt.hidden_comment · CWE-94, CWE-1427
docs/adr-oob-password.md:1
<!-- llm-context: Architecture Decision Record for how fleet collects passwords securely outside the LLM conversation. Covers the Unix domain socket approach, AES-256-GCM encryption, and cross-platfor
Why it matters. directive hidden in a comment the user does not see rendered
Fix. remove the comment
HIGHPrompt injection · prompt.hidden_comment · CWE-94, CWE-1427
docs/design-git-auth.md:1
<!-- llm-context: Design doc for fleet's git authentication system -- scoped token provisioning via GitHub Apps, PATs, Bitbucket, and Azure DevOps. Read when a user asks how to give members git access
Why it matters. directive hidden in a comment the user does not see rendered
Fix. remove the comment
HIGHPrompt injection · prompt.hidden_comment · CWE-94, CWE-1427
llms-full.txt:1767
<!-- llm-context: Design doc for fleet's git authentication system -- scoped token provisioning via GitHub Apps, PATs, Bitbucket, and Azure DevOps. Read when a user asks how to give members git access
Why it matters. directive hidden in a comment the user does not see rendered
Fix. remove the comment
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/auth.ts:311
console.log(`✓ OAuth token written for ${provider}`);
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/os/os-commands.ts:1
import { escapeDoubleQuoted, escapeWindowsArg, escapeGrepPattern, sanitizeSessionId } from '../utils/shell-escape.js';
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/os/windows.ts:3
import { execFileSync } from 'node:child_process';
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/utils/deep-merge.ts:1
export function isObject(item: unknown): item is Record<string, unknown> {
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/structured-tool-responses.test.ts:233
const FIXTURE_API_KEY = 'sk-ant-api03-FIXTURE-PLAINTEXT-DO-NOT-LEAK';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/apra-fleet-se/test/dolt-sync-budget.test.mjs:850
const TOKEN = 'ghp_SECRETSECRETSECRET';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/apra-fleet-se/test/mock-sprint-windows-vcs-credential.test.mjs:104
function buildMockWindowsCommand({ commitCount, pushShouldFail = false, prOutcome = 'created', prUrl, credentialShouldFail = false, token = 'mock-windows-vcs-token' } = {}) {
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/apra-fleet-se/test/mock-sprint-windows-vcs-credential.test.mjs:290
function buildMockGitbashCommand({ commitCount, prUrl, token = 'mock-gitbash-vcs-token' } = {}) {
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/apra-fleet-se/test/se-os-commands-shell-matrix.test.mjs:254
const TOKEN = 'PAT-TOKEN-shell-matrix';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/apra-fleet-se/test/vcs-http-stub.test.mjs:72
const TOKEN = 'ghs_stubtoken_A1b2C3d4E5f6G7h8I9j0';
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/apra-fleet-se/test/vcs-http-stub.test.mjs:72
const TOKEN = 'ghs_stubtoken_A1b2C3d4E5f6G7h8I9j0';
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/provision-vcs-auth.test.ts:37
loadPrivateKey: vi.fn().mockReturnValue('-----BEGIN PRIVATE KEY-----\nfake\n-----END PRIVATE KEY-----'),
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/vcs-auth.test.ts:17
loadPrivateKey: vi.fn().mockReturnValue('-----BEGIN PRIVATE KEY-----\nfake\n-----END PRIVATE KEY-----'),
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
credential_store_delete, member_reservation, remove_member, revoke_vcs_auth, stop_prompt
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
docs/features/apra-fleet-workflows.pptx
apra-fleet-workflows.pptx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c474ac4e829efull audit observations/trust-audit/mcp-server/apra-labs__apra-fleet.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c474ac4e829eBLOCKF27first audit
06

Questions

What is the Apra Fleet MCP server?

AI agents that write code, review each other's work, and coordinate across your machines

What tools does Apra Fleet expose?

63 in total: 38 read-only, 20 that write, and 5 that can delete or overwrite (credential_store_delete, member_reservation, remove_member, revoke_vcs_auth, stop_prompt). Every one is listed on this page with its risk.

Is Apra Fleet safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (27/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Apra Fleet need?

It reads APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE, APRA_FLEET_BD_TEMPLATE_KEY, CLAUDE_CODE_OAUTH_TOKEN, E2E_GH_TOKEN, GH_TOKEN and HUB_JWT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Apra Fleet run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @apralabs/fleet-api-contract at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (c474ac4e829e), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement