Gemini-FlowBLOCK
rUv's Claude-Flow, translated to the new Gemini CLI; transforming it into an autonomous AI development team.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/clduab11-gemini-flow)
[](https://www.npmjs.com/package/@clduab11/gemini-flow) [](LICENSE) [](https://github.com/clduab11/gemini-flow/actions) [](https://github.com/clduab11/gemini-flow/stargazers)
⚡ A2A + MCP Dual Protocol Support | 🌟 Complete Google AI Services Integration | 🧠 66 Specialized AI Agents | 🚀 396,610 SQLite ops/sec
⭐ Star this repo | 🎯 Live Demo | 📚 Documentation | 🤝 Join the Revolution
Dev Note (IMPORTANT!):
Hi all! I wanted to write a short message thanking each and every one of you for supporting the repo and sharing it and I hope it was super useful for you!! As of January 29, 2026, this project will be archived/read-only.
Generative AI writ large is moving too fast given the amount of repositories I'm not managing have exploded, and with some of Google's latest releases (Antigravity), it really discontinues the need for this type of project.
I will keep it archived/read-only as a growing/learning experience! Thanks so much everyone; y'all have been awesome!!!
-clduab11
🚀 Production-Ready AI Orchestration
Gemini-Flow is the production-ready AI orchestration platform that transforms how organizations deploy, manage, and scale AI
9e2af5c4f768OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add gemini-flow --env AUTH_RESPONSE_TIME_MAX=${AUTH_RESPONSE_TIME_MAX} --env EMAIL_PASSWORD=${EMAIL_PASSWORD} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GEMINI_FLOW_ENCRYPTION_KEY=${GEMINI_FLOW_ENCRYPTION_KEY} -- npx -y @clduab11/[email protected]{
"mcpServers": {
"gemini-flow": {
"command": "npx",
"args": [
"-y",
"@clduab11/[email protected]"
],
"env": {
"AUTH_RESPONSE_TIME_MAX": "${AUTH_RESPONSE_TIME_MAX}",
"EMAIL_PASSWORD": "${EMAIL_PASSWORD}",
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"GEMINI_FLOW_ENCRYPTION_KEY": "${GEMINI_FLOW_ENCRYPTION_KEY}"
}
}
}
}Exposed tools (65)
57 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Architecture | read | Design system architecture and components |
Equalization | read | Adjusts frequency balance |
Implementation | write | Write production code |
Observation | read | Monitoring with minimal restrictions |
Pseudocode | write | Create algorithmic logic in pseudocode |
Refinement | read | Iterative improvement and optimization |
Reverb | read | Adds reverberation effects |
Specification | read | Define detailed requirements and acceptance criteria |
academic_search | read | Search academic papers and research |
agent-lifecycle | read | Tools for agent creation, management, and lifecycle |
build-status | read | Build status |
calculate | read | Perform calculations |
calculate_distance | read | Calculate distance between two locations |
cloud_sql_configure_database | read | Configures Google Cloud SQL database settings. |
cloud_sql_execute_query | write | Executes a SQL query on Google Cloud SQL. |
cloud_sql_list_databases | read | Lists databases in a Google Cloud SQL instance. |
cloud_sql_list_tables | read | Lists tables in a Google Cloud SQL database. |
cloud_sql_manage_instance | write | Manages Google Cloud SQL instance (start, stop, restart, resize). |
coder | read | Code implementation specialist |
daa-autonomous | read | Decentralized Autonomous Agent tools |
default | read | Default configuration profile |
deployment-url | read | URL of deployed application |
design | read | Design phase |
development | read | In development |
done | read | Complete |
environment | read | Deployment environment |
fact_check | read | Verify facts and claims |
firestore_add_document | write | Adds a document to a Google Cloud Firestore collection. |
firestore_delete_document | destructive | Deletes a document from a Google Cloud Firestore collection. |
firestore_get_document | read | Retrieves a document from a Google Cloud Firestore collection. |
firestore_query_collection | read | Queries a Google Cloud Firestore collection. |
firestore_update_document | write | Updates an existing document in a Google Cloud Firestore collection. |
gemini-1.0-pro | read | Natural language tasks, multi-turn text and code chat |
gemini-1.5-flash | read | Fast and versatile performance for diverse tasks |
gemini-1.5-pro | read | Complex reasoning tasks requiring more intelligence |
get_weather | read | Get current weather information for a location |
github-integration | read | GitHub repository and development tools |
in-progress | read | Being worked on |
investigation | read | Under investigation |
knowledge_base | read | Query structured knowledge bases |
memory-management | read | Memory and data persistence tools |
neural-ai | read | Neural network and AI-related tools |
news_search | read | Search recent news and current events |
payment-processing | read | Process A2P payments with quantum optimization |
performance-monitoring | read | Performance analysis and monitoring tools |
planner | read | Strategic planning and coordination |
proposal | read | Feature proposal |
protocol-translation | read | Translate between MCP and A2A protocols |
read_file | read | Reads content from a file. |
researcher | read | Information gathering and analysis |
resolved | read | Resolved |
review | read | Code review |
reviewer | read | Code review and quality assurance |
search | read | Search for information |
sentiment-analyzer | read | Advanced sentiment analysis tool |
swarm-management | read | Tools for managing agent swarms and coordination |
system-utilities | read | System-level utilities and diagnostics |
task-orchestration | read | Tools for task distribution and orchestration |
test-results | read | Test results |
tester | read | Test creation and validation |
testing | read | In testing |
triage | read | Initial triage |
web_search | read | Search the web for information |
workflow-automation | read | Workflow creation and automation tools |
write_file | write | Writes content to a file. |
Trust audit
BLOCKgrade F · trust 36/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (13 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(sql: any): void;
exec(sql: any): void;
exec(sql) {exec(sql) {exec(sql) {database-url: "postgres://unleash:password@postgres:5432/unleash"
gemini-flow-docs-v1.3.0.tar.gz
if (Math.random() < behavior.protocolViolations.nonceReuse) {if (Math.random() < behavior.protocolViolations.nonceReuse) {if (Math.random() < behavior.protocolViolations.nonceReuse) {console.log(` Cost per Token: $${metrics.costMetrics.costPerToken.toFixed(8)}`);console.log(chalk.gray(' Jules API Key:'), config.apiKey);console.log(` Cost per Token: $${metrics.costMetrics.costPerToken.toFixed(8)}`);console.log(''); // New line after password inputconsole.log(chalk.gray(' Jules API Key:'), config.apiKey);__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODA2NzczMTAtMm03Z2RpM2N6IiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDgwNzA3MzEzLWw4YngwMzR0aSIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODA3MDczMT
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODE5ODM0NjMtYm5rNmhuMTBoIiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDgyMDEzNDY0LXM5eXhubW9wcCIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODIwMTM0Nj
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODMwNDE5MjcteDhkcmV3YTN4IiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDgzMDcxOTM0LWoxeDVsMGdxOSIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODMwNzE5Mz
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODQ3OTI2MDgteXgweWYxanhvIiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDg0ODIyNjEwLTZ5djRmMTFqOSIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODQ4MjI2MT
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODU5NjYyNDEtMW5odXg0MDB1IiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDg1OTk2MjM2LWpkOWJ6ajl4YSIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODU5OTYyMz
const apiKey = "AIzaSyD-hardcoded-key-in-source";
unleash-secret: "your-unleash-secret-here"
private_key: '-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----\n',
"private_key": "-----BEGIN PRIVATE KEY-----\n...",
private_key: '-----BEGIN PRIVATE KEY-----...',
Gates applied: no_behavioural_pass.
9e2af5c4f768full audit observations/trust-audit/mcp-server/clduab11__gemini-flow.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | 9e2af5c4f768 | BLOCK | F | 36 | first audit |
Questions
What is the Gemini-Flow MCP server?
rUv's Claude-Flow, translated to the new Gemini CLI; transforming it into an autonomous AI development team.
What tools does Gemini-Flow expose?
65 in total: 57 read-only, 7 that write, and 1 that can delete or overwrite (firestore_delete_document). Every one is listed on this page with its risk.
Is Gemini-Flow safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (36/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Gemini-Flow need?
It reads AUTH_RESPONSE_TIME_MAX, EMAIL_PASSWORD, GEMINI_API_KEY, GEMINI_FLOW_ENCRYPTION_KEY, GEMINI_FLOW_SECRET, GITHUB_TOKEN, GOOGLE_AI_API_KEY, GOOGLE_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_CLIENT_SECRET, GOOGLE_SERVICES_API_KEY and GRAFANA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (9e2af5c4f768), read on 2026-10-01. The repository is watched and re-audited when it changes.