Atlas / MCP servers / clduab11 / Gemini-Flow

Gemini-FlowBLOCK

mcp/clduab11/gemini-flow

rUv's Claude-Flow, translated to the new Gemini CLI; transforming it into an autonomous AI development team.

Verdict
BLOCK
Grade
F
Trust score
36 /100
Exposed tools
65 57r · 7w · 1d
Transport
—
License
MIT
Stars
387
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/clduab11-gemini-flow)

[](https://www.npmjs.com/package/@clduab11/gemini-flow) [](LICENSE) [](https://github.com/clduab11/gemini-flow/actions) [](https://github.com/clduab11/gemini-flow/stargazers)

⚡ A2A + MCP Dual Protocol Support | 🌟 Complete Google AI Services Integration | 🧠 66 Specialized AI Agents | 🚀 396,610 SQLite ops/sec

⭐ Star this repo | 🎯 Live Demo | 📚 Documentation | 🤝 Join the Revolution

Dev Note (IMPORTANT!):

Hi all! I wanted to write a short message thanking each and every one of you for supporting the repo and sharing it and I hope it was super useful for you!! As of January 29, 2026, this project will be archived/read-only.

Generative AI writ large is moving too fast given the amount of repositories I'm not managing have exploded, and with some of Google's latest releases (Antigravity), it really discontinues the need for this type of project.

I will keep it archived/read-only as a growing/learning experience! Thanks so much everyone; y'all have been awesome!!!

-clduab11

🚀 Production-Ready AI Orchestration

Gemini-Flow is the production-ready AI orchestration platform that transforms how organizations deploy, manage, and scale AI

Read from source at commit 9e2af5c4f768OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add gemini-flow --env AUTH_RESPONSE_TIME_MAX=${AUTH_RESPONSE_TIME_MAX} --env EMAIL_PASSWORD=${EMAIL_PASSWORD} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GEMINI_FLOW_ENCRYPTION_KEY=${GEMINI_FLOW_ENCRYPTION_KEY} -- npx -y @clduab11/[email protected]
claude-desktop
{
  "mcpServers": {
    "gemini-flow": {
      "command": "npx",
      "args": [
        "-y",
        "@clduab11/[email protected]"
      ],
      "env": {
        "AUTH_RESPONSE_TIME_MAX": "${AUTH_RESPONSE_TIME_MAX}",
        "EMAIL_PASSWORD": "${EMAIL_PASSWORD}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "GEMINI_FLOW_ENCRYPTION_KEY": "${GEMINI_FLOW_ENCRYPTION_KEY}"
      }
    }
  }
}
03

Exposed tools (65)

57 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ArchitecturereadDesign system architecture and components
EqualizationreadAdjusts frequency balance
ImplementationwriteWrite production code
ObservationreadMonitoring with minimal restrictions
PseudocodewriteCreate algorithmic logic in pseudocode
RefinementreadIterative improvement and optimization
ReverbreadAdds reverberation effects
SpecificationreadDefine detailed requirements and acceptance criteria
academic_searchreadSearch academic papers and research
agent-lifecyclereadTools for agent creation, management, and lifecycle
build-statusreadBuild status
calculatereadPerform calculations
calculate_distancereadCalculate distance between two locations
cloud_sql_configure_databasereadConfigures Google Cloud SQL database settings.
cloud_sql_execute_querywriteExecutes a SQL query on Google Cloud SQL.
cloud_sql_list_databasesreadLists databases in a Google Cloud SQL instance.
cloud_sql_list_tablesreadLists tables in a Google Cloud SQL database.
cloud_sql_manage_instancewriteManages Google Cloud SQL instance (start, stop, restart, resize).
coderreadCode implementation specialist
daa-autonomousreadDecentralized Autonomous Agent tools
defaultreadDefault configuration profile
deployment-urlreadURL of deployed application
designreadDesign phase
developmentreadIn development
donereadComplete
environmentreadDeployment environment
fact_checkreadVerify facts and claims
firestore_add_documentwriteAdds a document to a Google Cloud Firestore collection.
firestore_delete_documentdestructiveDeletes a document from a Google Cloud Firestore collection.
firestore_get_documentreadRetrieves a document from a Google Cloud Firestore collection.
firestore_query_collectionreadQueries a Google Cloud Firestore collection.
firestore_update_documentwriteUpdates an existing document in a Google Cloud Firestore collection.
gemini-1.0-proreadNatural language tasks, multi-turn text and code chat
gemini-1.5-flashreadFast and versatile performance for diverse tasks
gemini-1.5-proreadComplex reasoning tasks requiring more intelligence
get_weatherreadGet current weather information for a location
github-integrationreadGitHub repository and development tools
in-progressreadBeing worked on
investigationreadUnder investigation
knowledge_basereadQuery structured knowledge bases
memory-managementreadMemory and data persistence tools
neural-aireadNeural network and AI-related tools
news_searchreadSearch recent news and current events
payment-processingreadProcess A2P payments with quantum optimization
performance-monitoringreadPerformance analysis and monitoring tools
plannerreadStrategic planning and coordination
proposalreadFeature proposal
protocol-translationreadTranslate between MCP and A2A protocols
read_filereadReads content from a file.
researcherreadInformation gathering and analysis
resolvedreadResolved
reviewreadCode review
reviewerreadCode review and quality assurance
searchreadSearch for information
sentiment-analyzerreadAdvanced sentiment analysis tool
swarm-managementreadTools for managing agent swarms and coordination
system-utilitiesreadSystem-level utilities and diagnostics
task-orchestrationreadTools for task distribution and orchestration
test-resultsreadTest results
testerreadTest creation and validation
testingreadIn testing
triagereadInitial triage
web_searchreadSearch the web for information
workflow-automationreadWorkflow creation and automation tools
write_filewriteWrites content to a file.
04

Trust audit

BLOCKgrade F · trust 36/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (13 observation(s))
Network
declared (5 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dist/dist/memory/sqlite-adapter.d.ts:31
exec(sql: any): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dist/dist/memory/sqlite-adapter.d.ts:42
exec(sql: any): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dist/dist/memory/sqlite-adapter.js:105
exec(sql) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dist/dist/memory/sqlite-adapter.js:164
exec(sql) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
dist/dist/memory/sqlite-adapter.js:277
exec(sql) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
infrastructure/feature-flags/unleash-config.yaml:411
database-url: "postgres://unleash:password@postgres:5432/unleash"
MEDIUMInventory / provenance · inv.binary · CWE-1104
release-assets/gemini-flow-docs-v1.3.0.tar.gz
gemini-flow-docs-v1.3.0.tar.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
dist/protocols/a2a/security/attack-simulation.js:641
if (Math.random() < behavior.protocolViolations.nonceReuse) {
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
dist/src/protocols/a2a/security/attack-simulation.js:641
if (Math.random() < behavior.protocolViolations.nonceReuse) {
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
src/protocols/a2a/security/attack-simulation.ts:968
if (Math.random() < behavior.protocolViolations.nonceReuse) {
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
dist/cli/adapter-commands.js:539
console.log(`  Cost per Token: $${metrics.costMetrics.costPerToken.toFixed(8)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
dist/cli/commands/jules.js:396
console.log(chalk.gray('  Jules API Key:'), config.apiKey);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
dist/src/cli/adapter-commands.js:539
console.log(`  Cost per Token: $${metrics.costMetrics.costPerToken.toFixed(8)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
security/secure-npm-auth.js:96
console.log(''); // New line after password input
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/jules.ts:482
console.log(chalk.gray('  Jules API Key:'), config.apiKey);
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
.hive-mind/sessions/session-1754080677310-2m7gdi3cz-auto-save-1754080707312.json:1
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODA2NzczMTAtMm03Z2RpM2N6IiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDgwNzA3MzEzLWw4YngwMzR0aSIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODA3MDczMT
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
.hive-mind/sessions/session-1754081983463-bnk6hn10h-auto-save-1754082013464.json:1
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODE5ODM0NjMtYm5rNmhuMTBoIiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDgyMDEzNDY0LXM5eXhubW9wcCIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODIwMTM0Nj
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
.hive-mind/sessions/session-1754083041927-x8drewa3x-auto-save-1754083071933.json:1
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODMwNDE5MjcteDhkcmV3YTN4IiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDgzMDcxOTM0LWoxeDVsMGdxOSIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODMwNzE5Mz
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
.hive-mind/sessions/session-1754084792608-yx0yf1jxo-auto-save-1754084822610.json:1
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODQ3OTI2MDgteXgweWYxanhvIiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDg0ODIyNjEwLTZ5djRmMTFqOSIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODQ4MjI2MT
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
.hive-mind/sessions/session-1754085966241-1nhux400u-auto-save-1754085996235.json:1
__compressed__eyJzZXNzaW9uSWQiOiJzZXNzaW9uLTE3NTQwODU5NjYyNDEtMW5odXg0MDB1IiwiY2hlY2twb2ludElkIjoiY2hlY2twb2ludC0xNzU0MDg1OTk2MjM2LWpkOWJ6ajl4YSIsImNoZWNrcG9pbnROYW1lIjoiYXV0by1zYXZlLTE3NTQwODU5OTYyMz
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/api/google-services/authentication-guide.md:327
const apiKey = "AIzaSyD-hardcoded-key-in-source";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
infrastructure/feature-flags/unleash-config.yaml:396
unleash-secret: "your-unleash-secret-here"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
VERTEX_AI_SETUP.md:84
private_key: '-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----\n',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/api/google-services/authentication-guide.md:76
"private_key": "-----BEGIN PRIVATE KEY-----\n...",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/api/google-services/getting-started.md:220
private_key: '-----BEGIN PRIVATE KEY-----...',

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 9e2af5c4f768full audit observations/trust-audit/mcp-server/clduab11__gemini-flow.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-019e2af5c4f768BLOCKF36first audit
06

Questions

What is the Gemini-Flow MCP server?

rUv's Claude-Flow, translated to the new Gemini CLI; transforming it into an autonomous AI development team.

What tools does Gemini-Flow expose?

65 in total: 57 read-only, 7 that write, and 1 that can delete or overwrite (firestore_delete_document). Every one is listed on this page with its risk.

Is Gemini-Flow safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (36/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Gemini-Flow need?

It reads AUTH_RESPONSE_TIME_MAX, EMAIL_PASSWORD, GEMINI_API_KEY, GEMINI_FLOW_ENCRYPTION_KEY, GEMINI_FLOW_SECRET, GITHUB_TOKEN, GOOGLE_AI_API_KEY, GOOGLE_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_CLIENT_SECRET, GOOGLE_SERVICES_API_KEY and GRAFANA_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (9e2af5c4f768), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement