Atlas / MCP servers / ashwwwin / Furikake

FurikakeBLOCK

mcp/ashwwwin/furikake

CLI & API for MCP management

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
NOASSERTION
Stars
172
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

furi is an easy to use, CLI & API for MCP management.

  • Download MCP servers [from GitHub]
  • Smithery.yaml detection (or auto detects/handles execution)
  • Fully featured CLI [nanospinners, readability]
  • Typescript & Javascript MCP's are supported
  • Python based MCP's are a key roadmap item (and will be supported)
  • HTTP API Routes (uses Bun http, stdio to http, clear and standard routes)
  • Customizable port and visibility of sudo routes
  • View all running MCPs + logs for each process
  • Process state management with PM2
  • Built with Bun and Typescript
  • is good with rice

Installation (macOS/Linux)

To install Furi, you can use the following command:

curl -fsSL https://furi.so/install | bash

Verify the installation by running:

furi

Furikake uses Bun under the hood, the install script will install Bun if it is not already installed.

Upgrade Furi

To upgrade Furi to the latest version, run:

furi upgrade

How to use

Manage MCPs

Furikake works with any public github repo as follows:

furi add 

eg. furi add smithery-ai/mcp-fetch

You can also rename an MCP by using the rename command, please note this will restart the MCP if it is running.

furi rename  

eg. furi rename smithery-ai/mcp-fetch mcp-fetch

Delete an MCP

furi remove 

eg. furi remove mcp-fetch

List installed MCPs

Show all installed MCPs

furi list

Start an MCP

furi start  -e '{"name1":"value1", "name2":"value2"}'

-e env is optional and dependant on the MCP server being called

Ensure you pass a valid JSON object to the -e flag.

Once you start a server with the -e flag, it will be saved to the config file and re-used when using the server again.

In order to view the env variables required for an MCP, use:

Read from source at commit f3cb5f0510daOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add furi-cli --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GITHUB_KEY=${GITHUB_KEY} --env HTTP_AUTH_TOKEN=${HTTP_AUTH_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "furi-cli": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "GITHUB_KEY": "${GITHUB_KEY}",
        "HTTP_AUTH_TOKEN": "${HTTP_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
namereadName of the log
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (14 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
app/packages/add/actions/initializePackage.ts:456
smitheryConfig = yaml.load(smitheryContent) as SmitheryConfig;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/aggregator/restart/index.ts:104
`     \x1b[2mAggregator running on http://127.0.0.1:${displayPort}/sse`
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/aggregator/start/index.ts:91
`     \x1b[2mAggregator running on http://127.0.0.1:${port}/sse (persistent MCP connections)`
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/http/server/endpoints/aggregator/restart.ts:92
message: `MCP Aggregator server restarted successfully. Running on http://127.0.0.1:${displayPort}/sse`,
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/http/server/endpoints/aggregator/start.ts:104
message: `MCP Aggregator server started successfully. Running on http://127.0.0.1:${port}/sse`,
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/http/start/index.ts:57
`     \x1b[2mHTTP API server running on http://127.0.0.1:${port}\x1b[0m`
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cleanup
.cleanup
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/http/server/endpoints/[mcpName]/env/getEnv.ts:2
import { extractMcpName } from "../../../utils";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/http/server/endpoints/[mcpName]/rename.ts:3
import { extractMcpName } from "../../utils";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/http/server/endpoints/[mcpName]/restart.ts:2
import { extractMcpName } from "../../utils"; // Import the utility function
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/http/server/endpoints/[mcpName]/start.ts:2
import { extractMcpName } from "../../utils";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/http/server/endpoints/[mcpName]/status.ts:3
import { extractMcpName } from "../../utils";
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
app/upgrade/actions/upgradeFuri.tsx:83
const decodedContent = atob(apiResponse.content.replace(/\s/g, ''));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, commander, fastmcp, isomorphic-git, js-yaml, nanospinner, pm2, @types/bun
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:22
curl -fsSL https://furi.so/install | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha f3cb5f0510dafull audit observations/trust-audit/mcp-server/ashwwwin__furikake.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07f3cb5f0510daBLOCKD69first audit
06

Questions

What is the Furikake MCP server?

CLI & API for MCP management

What tools does Furikake expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Furikake safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Furikake need?

It reads GEMINI_API_KEY, GITHUB_KEY and HTTP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (f3cb5f0510da), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement