Apra FleetBLOCK
AI agents that write code, review each other's work, and coordinate across your machines
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Run a fleet of AI agents across your devices, your providers, your workflows.
What Kubernetes did for containers, apra-fleet does for AI agents: scheduling, credentials, isolation, and observability for an agentic workforce -- on any machine, anywhere, using every LLM provider at once.
[](https://github.com/Apra-Labs/apra-fleet/actions/workflows/ci.yml) [](https://opensource.org/licenses/Apache-2.0) [](https://github.com/Apra-Labs/apra-fleet/releases) [](https://modelcontextprotocol.io) [](https://deepwiki.com/Apra-Labs/apra-fleet)
Quick Start - Live Demo - How It Works - fleet-sprint Getting Started Guide - Website
This repository is built by the product you are looking at. An autonomous apra-fleet workflow plans, codes, reviews, tests, and ships this codebase in multi-hour sprints -- filing bugs against itself and fixing them. The recording abo
c474ac4e829eOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add fleet-api-contract --env APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE=${APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE} --env APRA_FLEET_BD_TEMPLATE_KEY=${APRA_FLEET_BD_TEMPLATE_KEY} --env CLAUDE_CODE_OAUTH_TOKEN=${CLAUDE_CODE_OAUTH_TOKEN} --env E2E_GH_TOKEN=${E2E_GH_TOKEN} -- npx -y @apralabs/[email protected]{
"mcpServers": {
"fleet-api-contract": {
"command": "npx",
"args": [
"-y",
"@apralabs/[email protected]"
],
"env": {
"APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE": "${APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE}",
"APRA_FLEET_BD_TEMPLATE_KEY": "${APRA_FLEET_BD_TEMPLATE_KEY}",
"CLAUDE_CODE_OAUTH_TOKEN": "${CLAUDE_CODE_OAUTH_TOKEN}",
"E2E_GH_TOKEN": "${E2E_GH_TOKEN}"
}
}
}
}Exposed tools (63)
38 read · 20 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Original | read | orig desc |
auto-sprint | read | Multi-cycle sprint workflow: plan -> develop -> test -> harvest. Pass args as a JSON object with required |
child_id_allocator | read | Global child-bead-id allocator hosted on the fleet server, so sprints launched WITHOUT a supervisor never mint the same child id under a shared parent. |
cloud_control | write | Manually start, stop, or check status of a cloud fleet member. Start waits until the member is ready; stop is immediate. |
code_context | read | Get callers, callees, and execution flows for a symbol. Prefer this over Glob/Grep/file reads for structural questions (symbol lookup, call chains, impact) -- the answer is pre-indexed. |
code_flow | read | Find process flows (entry -> steps -> exit) matching a name or endpoints. Prefer this over manually tracing call chains across files -- the flows are pre-indexed. |
code_graph | read | Trace the call graph for a symbol. Returns callers and callees across the codebase. Prefer this over Glob/Grep/file reads for structural questions (symbol lookup, call chains, impact) -- the answer is pre-indexed. |
code_impact | read | Find what is affected by changes to a symbol. Prefer this over Glob/Grep/file reads for structural questions (symbol lookup, call chains, impact) -- the answer is pre-indexed. |
code_map | read | Get the architectural map of a repository: module communities with their key symbols and files, ranked by size. Prefer this over directory listings or file reads when orienting in an unfamiliar codebase -- the answer is pre-indexed. |
code_query | read | Search the codebase for symbols, patterns, or concepts using natural language or code patterns. Prefer this over Glob/Grep/file reads for structural questions (symbol lookup, call chains, impact) -- the answer is pre-indexed. |
code_tests | read | Find the test files and test functions that exercise a symbol (transitive callers, depth 2). Use this to run targeted tests for the code you changed instead of the full suite. Prefer this over Grep for test discovery -- the call graph is pre-indexed. |
compose_permissions | write | Set up and deliver the right permissions to a member for their role or tags. Automatically tailors permissions to the project type. Pass tags (e.g. [ |
credential_store_delete | destructive | Delete a named credential from the store (both session and persistent tiers). |
credential_store_list | read | List all stored credentials (names and metadata only — no values). |
credential_store_set | write | Collect a secret from the user out-of-band and store it. Returns a handle (sec://NAME) and scope. Use {{secret.NAME}} tokens in execute_command to inject the value. |
credential_store_update | write | Update metadata (members, TTL, network policy) on an existing credential without re-entering the secret. |
dolt_push_mutex | write | Global cross-sprint dolt push mutex hosted on the fleet server, so sprints launched WITHOUT a supervisor still serialize their |
execute_command | write | Run a shell command on a member. Use for quick tasks like installing packages, checking versions, or running scripts. |
execute_prompt | write | Run an AI prompt on a member. Supports session resume for multi-turn conversations. On success, the reply text is returned in structuredContent.response (alongside usage and sessionId). |
fleet_status | read | Get status of all fleet members. Use json format for structured data. |
get_member_model_pricing | read | Returns a member |
hello-world | read | plain non-se workflow, no sprint/beads domain concepts |
hello-world-workflow | read | A sample workflow testing the fleet-workflow engine |
kb_capture | read | |
kb_context | read | Check freshness of files against the knowledge bank. Returns {fresh, stale, missing} -- fresh files can be skipped, stale/missing files must be re-read. |
kb_export | read | Export CONFIRMED, non-superseded, non-stale KB entries to a canonical bible file (stable field set, deterministic id order, ASCII-safe). scope= |
kb_feedback | read | Downvote a KB entry that proved wrong in practice: { id, reason, role? }. Marks the entry stale=1 + flagged_for_review=1 and appends an ASCII feedback note |
kb_freshness_sweep | read | |
kb_harvest | read | Scan a session transcript for learnings and capture them into the KB. Returns {entries_captured, entries_updated, entries_skipped}. Extracted entries are UNVERIFIED and author=harvest, source=harvest. |
kb_import | write | |
kb_invalidate | read | Mark context-cache entries stale for the given file paths. Call after modifying files to ensure the KB reflects the current state. |
kb_list | write | List KB entries by confidence/type/module/symbol/tag -- audit the CONFIRMED set (or any tier) without touching FTS ranking or use_count telemetry. Excludes superseded/stale entries. Returns {results, total} with each entry as {id, type, confidence, title, summary, symbols, source_files}. |
kb_promote | read | Upgrade KB entry confidence: UNVERIFIED -> INFERRED -> CONFIRMED. Appends promotion note to content as evidence trail. CONFIRMED entries are no-op. |
kb_query | read | |
kb_reconcile_prefilter | read | Mechanical hash-basis prefilter over all flagged contradiction pairs (including stale members -- see flaggedPairs liveness contract). Re-hashes both sides of each pair against the CURRENT worktree: exactly one side fully matching wins mechanically via kb_resolve_contradiction (evidence |
kb_resolve_contradiction | read | |
kb_session_prime | read | Prime a session with KB context. Returns session_warm status, stale files needing re-read, top KB entries, and recommended GitNexus calls. |
kb_setup | write | Set up KB: install git post-commit hook, write provider config, store remote credentials encrypted. Run once per repo. |
kb_stats | read | |
list_members | read | List all fleet members and their current status. Use format= |
member_detail | read | Get detailed status for one member: connectivity, AI version, authentication, active session, resources, and git branch. |
member_reservation | destructive | Reserve, release, or force-release exclusive ownership of a member for a sprint (server-side reservation; does not yet block dispatch). |
monitor_task | read | Check status of a long-running background task on a cloud member. Optionally stop the cloud instance automatically when the task completes. |
provision_llm_auth | write | Authenticate a fleet member so it can run prompts. Copies your current login session to the member, or deploys an API key if provided. Run this before execute_prompt if the member reports no authentication. |
provision_vcs_auth | write | Set up git access credentials on a member. Supports GitHub, Bitbucket, and Azure DevOps. Tests connectivity after setup. |
receive_files | read | Download files from a member to a local directory. Always batch multiple files into a single call — never invoke repeatedly for individual files. |
register_member | write | Add a machine to the fleet. Use member_type |
remove_member | destructive | Remove a member from the fleet. |
report_status | read | Called by a connected interactive member session (not the orchestrator) to report it is done responding to a send_message notification and available again ( |
respond_to_message | read | Called by a connected interactive member session to respond to a prompt delivered via execute_prompt or send_message. Pass reply_to as the msgid from the original notification\ |
revoke_vcs_auth | destructive | Remove VCS credentials from a member. Specify the provider (github, bitbucket, or azure-devops) to revoke. |
send_email | write | Send an email. Pass provider config inline (provider, from, and for SMTP: host, port, user, secure). Secrets (API keys, passwords) are resolved from the credential store -- store them first with credential_store_set (names: |
send_files | write | Transfer local files to a member. Always batch multiple files into a single call — never invoke repeatedly for individual files. |
send_message | write | Send a task message to a connected interactive member session via SSE. Returns the message ID. |
setup_git_app | read | |
setup_ssh_key | read | Generate an SSH key pair and migrate a member from password to key-based authentication. |
shutdown_server | write | Gracefully shut down the MCP server. Run /mcp afterwards to start a fresh instance with the latest code. |
sprint-runner | read | A skeleton sprint runner workflow imitating the core logic of auto-sprint runner.js using new workflow primitives |
stop_prompt | destructive | Kill the active LLM process on a member. Always call TaskStop on the dispatching background agent after calling this. |
update_llm_cli | write | Update or install the AI provider CLI on members. Omit member to update all online members at once. Use install_if_missing to install on members that don |
update_member | write | Change a member |
vcs_credential_exec | write | Run a credential-requiring git/VCS command on a member WITHOUT ever learning the credential. Put one of two literal placeholders where the token belongs: {{vcs_token}}, referenced BARE (never inside your own quotes) -- the server substitutes it already escaped AND quoted for that member\ |
version | read | Returns the installed apra-fleet server version |
Trust audit
BLOCKgrade F · trust 27/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
'mkdir -p ~/.ssh',
'chmod 700 ~/.ssh',
'touch ~/.ssh/authorized_keys',
'chmod 600 ~/.ssh/authorized_keys',
`echo ${escaped} >> ~/.ssh/authorized_keys`,const { command, log = () => {}, verify = false } = opts;HUB_DATABASE_URL: postgres://hub:hub-dev-password@db:5432/apra_fleet_hub
<!-- llm-context: Architecture Decision Record for how fleet collects passwords securely outside the LLM conversation. Covers the Unix domain socket approach, AES-256-GCM encryption, and cross-platfor
<!-- llm-context: Design doc for fleet's git authentication system -- scoped token provisioning via GitHub Apps, PATs, Bitbucket, and Azure DevOps. Read when a user asks how to give members git access
<!-- llm-context: Design doc for fleet's git authentication system -- scoped token provisioning via GitHub Apps, PATs, Bitbucket, and Azure DevOps. Read when a user asks how to give members git access
console.log(`✓ OAuth token written for ${provider}`);import { escapeDoubleQuoted, escapeWindowsArg, escapeGrepPattern, sanitizeSessionId } from '../utils/shell-escape.js';import { execFileSync } from 'node:child_process';export function isObject(item: unknown): item is Record<string, unknown> {const FIXTURE_API_KEY = 'sk-ant-api03-FIXTURE-PLAINTEXT-DO-NOT-LEAK';
const TOKEN = 'ghp_SECRETSECRETSECRET';
function buildMockWindowsCommand({ commitCount, pushShouldFail = false, prOutcome = 'created', prUrl, credentialShouldFail = false, token = 'mock-windows-vcs-token' } = {}) {function buildMockGitbashCommand({ commitCount, prUrl, token = 'mock-gitbash-vcs-token' } = {}) {const TOKEN = 'PAT-TOKEN-shell-matrix';
const TOKEN = 'ghs_stubtoken_A1b2C3d4E5f6G7h8I9j0';
const TOKEN = 'ghs_stubtoken_A1b2C3d4E5f6G7h8I9j0';
loadPrivateKey: vi.fn().mockReturnValue('-----BEGIN PRIVATE KEY-----\nfake\n-----END PRIVATE KEY-----'),loadPrivateKey: vi.fn().mockReturnValue('-----BEGIN PRIVATE KEY-----\nfake\n-----END PRIVATE KEY-----'),credential_store_delete, member_reservation, remove_member, revoke_vcs_auth, stop_prompt
apra-fleet-workflows.pptx
Gates applied: no_behavioural_pass.
c474ac4e829efull audit observations/trust-audit/mcp-server/apra-labs__apra-fleet.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c474ac4e829e | BLOCK | F | 27 | first audit |
Questions
What is the Apra Fleet MCP server?
AI agents that write code, review each other's work, and coordinate across your machines
What tools does Apra Fleet expose?
63 in total: 38 read-only, 20 that write, and 5 that can delete or overwrite (credential_store_delete, member_reservation, remove_member, revoke_vcs_auth, stop_prompt). Every one is listed on this page with its risk.
Is Apra Fleet safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (27/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Apra Fleet need?
It reads APRA_FLEET_ALLOW_REAL_CLI_AUTH_PROBE, APRA_FLEET_BD_TEMPLATE_KEY, CLAUDE_CODE_OAUTH_TOKEN, E2E_GH_TOKEN, GH_TOKEN and HUB_JWT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Apra Fleet run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @apralabs/fleet-api-contract at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (c474ac4e829e), read on 2026-10-07. The repository is watched and re-audited when it changes.