Cloudflare AIBLOCK
None
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Packages and examples for building AI-powered applications on Cloudflare. Includes providers for the Vercel AI SDK and TanStack AI, with support for Workers AI, AI Gateway, and AI Search.
Packages
0c7addca2977OBSERVED · 2026-09-25Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add workers-ai-provider-gateway-test --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CLOUDFLARE_AI_GATEWAY_TOKEN=${CLOUDFLARE_AI_GATEWAY_TOKEN} --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env CLOUDFLARE_GATEWAY_AUTH_TOKEN=${CLOUDFLARE_GATEWAY_AUTH_TOKEN} -- npx -y workers-ai-provider-gateway-test{
"mcpServers": {
"workers-ai-provider-gateway-test": {
"command": "npx",
"args": [
"-y",
"workers-ai-provider-gateway-test"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"CLOUDFLARE_AI_GATEWAY_TOKEN": "${CLOUDFLARE_AI_GATEWAY_TOKEN}",
"CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
"CLOUDFLARE_GATEWAY_AUTH_TOKEN": "${CLOUDFLARE_GATEWAY_AUTH_TOKEN}"
}
}
}
}Exposed tools (41)
31 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
CountryCapital | read | A country |
Result | read | A boolean result |
add | write | |
addKeyResult | write | Add a new key result to a specific objective |
addObjective | write | Add a new top-level objective for the organization |
calculate | read | |
calculate_bmi | read | Calculate BMI given weight in kg and height in meters |
calculator | write | Add two numbers. Returns their sum. Always use this tool for math. |
createTodo | write | Add a new TODO task |
deleteKeyResult | destructive | Remove a key result from a specific objective |
deleteObjective | destructive | Remove an existing top-level objective from the organization |
deleteTodo | read | Mark a TODO as deleted |
generateImage | read | Generate an image using the |
getChannelMessages | read | Get recent messages from a specific channel |
getCurrentUserInfo | read | Get current user info from Logto |
getToken | read | |
getUserInfo | read | Get authenticated user info from Descope |
get_current_time | read | Get the current UTC time |
get_time | read | t |
get_weather | read | Gets the weather for a specified location |
list-billing | read | List the current user |
list-todos | read | List the current user |
listChannels | read | Get a list of channels from your Slack workspace |
listObjectives | read | View all objectives and key results for the organization |
markTodoComplete | read | Mark a TODO as complete |
multiply | read | Multiply two numbers |
noop | read | noop |
ping | read | Ping |
postMessage | write | Attempt to post a message to a channel (will fail due to read-only permissions) |
random_number | read | Generate a random number between min and max |
read_data | read | Access your stored data |
read_profile | read | Read your basic profile information |
reverse_string | read | Reverse a string |
search | read | Search the web |
search_events | read | Search the calendar |
setKeyResultAttainment | write | Set the attainment value for a specific key result in a specific objective |
sum | read | Sum of two numbers |
userInfoOctokit | read | Get user info from GitHub, via Octokit |
web_scrape | read | Fetch and extract text content from a webpage URL. Only works with public HTTP/HTTPS URLs. |
whoami | read | Get information about your Slack user |
write_data | write | Create and modify your data |
Trust audit
BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
exec(
exec(query: string): Promise<D1ExecResult>;
exec(
exec(query: string): Promise<D1ExecResult>;
exec(
.DS_Store
demos/mcp-server-bearer-auth/static/img
demos/remote-mcp-server-autorag/static/img
demos/remote-mcp-server-descope-auth/static/img
demos/remote-mcp-server/static/img
deleteKeyResult, deleteObjective
.oxfmtrc.json
.oxlintrc.json
.oxfmtrc.json
.oxlintrc.json
.oxfmtrc.json
import type { AuthenticationContext } from "../../types";import { createAiGateway } from "../../src";import { createAISearchNamespace } from "../../../../../src/index";import { createWorkersAiChat, type WorkersAiTextModel } from "../../../../../src/index";import { WorkersAiTTSAdapter } from "../../../../../src/adapters/workers-ai-tts";hostname === "169.254.169.254" ||
atob(data: string): string;
declare function atob(data: string): string;
atob(data: string): string;
Gates applied: no_behavioural_pass.
0c7addca2977full audit observations/trust-audit/mcp-server/cloudflare__cloudflare-ai.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | 0c7addca2977 | BLOCK | F | 43 | first audit |
Questions
What is the Cloudflare AI MCP server?
None
What tools does Cloudflare AI expose?
41 in total: 31 read-only, 8 that write, and 2 that can delete or overwrite (deleteKeyResult, deleteObjective). Every one is listed on this page with its risk.
Is Cloudflare AI safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (43/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Cloudflare AI need?
It reads ANTHROPIC_API_KEY, CLOUDFLARE_AI_GATEWAY_TOKEN, CLOUDFLARE_API_TOKEN, CLOUDFLARE_GATEWAY_AUTH_TOKEN, CLOUDFLARE_GATEWAY_NAME_UNAUTH, DEEPSEEK_API_KEY, GEMINI_API_KEY, GOOGLE_API_KEY, GROK_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY and XAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (0c7addca2977), read on 2026-09-25. The repository is watched and re-audited when it changes.