FurikakeBLOCK
CLI & API for MCP management
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
furi is an easy to use, CLI & API for MCP management.
- Download MCP servers [from GitHub]
- Smithery.yaml detection (or auto detects/handles execution)
- Fully featured CLI [nanospinners, readability]
- Typescript & Javascript MCP's are supported
- Python based MCP's are a key roadmap item (and will be supported)
- HTTP API Routes (uses Bun http, stdio to http, clear and standard routes)
- Customizable port and visibility of sudo routes
- View all running MCPs + logs for each process
- Process state management with PM2
- Built with Bun and Typescript
- is good with rice
Installation (macOS/Linux)
To install Furi, you can use the following command:
curl -fsSL https://furi.so/install | bash
Verify the installation by running:
furi
Furikake uses Bun under the hood, the install script will install Bun if it is not already installed.
Upgrade Furi
To upgrade Furi to the latest version, run:
furi upgrade
How to use
Manage MCPs
Furikake works with any public github repo as follows:
furi add
eg. furi add smithery-ai/mcp-fetch
You can also rename an MCP by using the rename command, please note this will restart the MCP if it is running.
furi rename
eg. furi rename smithery-ai/mcp-fetch mcp-fetch
Delete an MCP
furi remove
eg. furi remove mcp-fetch
List installed MCPs
Show all installed MCPs
furi list
Start an MCP
furi start -e '{"name1":"value1", "name2":"value2"}'-e env is optional and dependant on the MCP server being called
Ensure you pass a valid JSON object to the -e flag.
Once you start a server with the -e flag, it will be saved to the config file and re-used when using the server again.
In order to view the env variables required for an MCP, use:
f3cb5f0510daOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add furi-cli --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GITHUB_KEY=${GITHUB_KEY} --env HTTP_AUTH_TOKEN=${HTTP_AUTH_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"furi-cli": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"GITHUB_KEY": "${GITHUB_KEY}",
"HTTP_AUTH_TOKEN": "${HTTP_AUTH_TOKEN}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
name | read | Name of the log |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (14 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (15)
smitheryConfig = yaml.load(smitheryContent) as SmitheryConfig;
` \x1b[2mAggregator running on http://127.0.0.1:${displayPort}/sse`` \x1b[2mAggregator running on http://127.0.0.1:${port}/sse (persistent MCP connections)`message: `MCP Aggregator server restarted successfully. Running on http://127.0.0.1:${displayPort}/sse`,message: `MCP Aggregator server started successfully. Running on http://127.0.0.1:${port}/sse`,` \x1b[2mHTTP API server running on http://127.0.0.1:${port}\x1b[0m`.cleanup
import { extractMcpName } from "../../../utils";import { extractMcpName } from "../../utils";import { extractMcpName } from "../../utils"; // Import the utility functionimport { extractMcpName } from "../../utils";import { extractMcpName } from "../../utils";const decodedContent = atob(apiResponse.content.replace(/\s/g, ''));
@modelcontextprotocol/sdk, commander, fastmcp, isomorphic-git, js-yaml, nanospinner, pm2, @types/bun
curl -fsSL https://furi.so/install | bash
Gates applied: no_behavioural_pass.
f3cb5f0510dafull audit observations/trust-audit/mcp-server/ashwwwin__furikake.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | f3cb5f0510da | BLOCK | D | 69 | first audit |
Questions
What is the Furikake MCP server?
CLI & API for MCP management
What tools does Furikake expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Furikake safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Furikake need?
It reads GEMINI_API_KEY, GITHUB_KEY and HTTP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (f3cb5f0510da), read on 2026-10-07. The repository is watched and re-audited when it changes.