Atlas / MCP servers / cloudflare / Cloudflare AI

Cloudflare AIBLOCK

mcp/cloudflare/cloudflare-ai

None

Verdict
BLOCK
Grade
F
Trust score
43 /100
Exposed tools
41 31r · 8w · 2d
Transport
—
License
MIT
Stars
1,171
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Packages and examples for building AI-powered applications on Cloudflare. Includes providers for the Vercel AI SDK and TanStack AI, with support for Workers AI, AI Gateway, and AI Search.

Packages

Read from source at commit 0c7addca2977OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add workers-ai-provider-gateway-test --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CLOUDFLARE_AI_GATEWAY_TOKEN=${CLOUDFLARE_AI_GATEWAY_TOKEN} --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env CLOUDFLARE_GATEWAY_AUTH_TOKEN=${CLOUDFLARE_GATEWAY_AUTH_TOKEN} -- npx -y workers-ai-provider-gateway-test
claude-desktop
{
  "mcpServers": {
    "workers-ai-provider-gateway-test": {
      "command": "npx",
      "args": [
        "-y",
        "workers-ai-provider-gateway-test"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "CLOUDFLARE_AI_GATEWAY_TOKEN": "${CLOUDFLARE_AI_GATEWAY_TOKEN}",
        "CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
        "CLOUDFLARE_GATEWAY_AUTH_TOKEN": "${CLOUDFLARE_GATEWAY_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (41)

31 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
CountryCapitalreadA country
ResultreadA boolean result
addwrite
addKeyResultwriteAdd a new key result to a specific objective
addObjectivewriteAdd a new top-level objective for the organization
calculateread
calculate_bmireadCalculate BMI given weight in kg and height in meters
calculatorwriteAdd two numbers. Returns their sum. Always use this tool for math.
createTodowriteAdd a new TODO task
deleteKeyResultdestructiveRemove a key result from a specific objective
deleteObjectivedestructiveRemove an existing top-level objective from the organization
deleteTodoreadMark a TODO as deleted
generateImagereadGenerate an image using the
getChannelMessagesreadGet recent messages from a specific channel
getCurrentUserInforeadGet current user info from Logto
getTokenread
getUserInforeadGet authenticated user info from Descope
get_current_timereadGet the current UTC time
get_timereadt
get_weatherreadGets the weather for a specified location
list-billingreadList the current user
list-todosreadList the current user
listChannelsreadGet a list of channels from your Slack workspace
listObjectivesreadView all objectives and key results for the organization
markTodoCompletereadMark a TODO as complete
multiplyreadMultiply two numbers
noopreadnoop
pingreadPing
postMessagewriteAttempt to post a message to a channel (will fail due to read-only permissions)
random_numberreadGenerate a random number between min and max
read_datareadAccess your stored data
read_profilereadRead your basic profile information
reverse_stringreadReverse a string
searchreadSearch the web
search_eventsreadSearch the calendar
setKeyResultAttainmentwriteSet the attainment value for a specific key result in a specific objective
sumreadSum of two numbers
userInfoOctokitreadGet user info from GitHub, via Octokit
web_scrapereadFetch and extract text content from a webpage URL. Only works with public HTTP/HTTPS URLs.
whoamireadGet information about your Slack user
write_datawriteCreate and modify your data
04

Trust audit

BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
demos/agent-scheduler/worker-configuration.d.ts:2501
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
demos/agent-scheduler/worker-configuration.d.ts:5285
exec(query: string): Promise<D1ExecResult>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
demos/agent-task-manager-human-in-the-loop/worker-configuration.d.ts:2501
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
demos/agent-task-manager-human-in-the-loop/worker-configuration.d.ts:5285
exec(query: string): Promise<D1ExecResult>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
demos/agent-task-manager/worker-configuration.d.ts:2501
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
demos/mcp-server-bearer-auth/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
demos/mcp-server-bearer-auth/static/img
demos/mcp-server-bearer-auth/static/img
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
demos/remote-mcp-server-autorag/static/img
demos/remote-mcp-server-autorag/static/img
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
demos/remote-mcp-server-descope-auth/static/img
demos/remote-mcp-server-descope-auth/static/img
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
demos/remote-mcp-server/static/img
demos/remote-mcp-server/static/img
Why it matters. link not followed
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deleteKeyResult, deleteObjective
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxfmtrc.json
.oxfmtrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
demos/agent-scheduler/.oxfmtrc.json
.oxfmtrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
demos/agent-scheduler/.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
demos/agent-task-manager-human-in-the-loop/.oxfmtrc.json
.oxfmtrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
demos/mcp-stytch-b2b-okr-manager/api/lib/auth.ts:5
import type { AuthenticationContext } from "../../types";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/ai-gateway-provider/test/e2e/gateway.e2e.test.ts:26
import { createAiGateway } from "../../src";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/ai-search-provider/test/e2e/fixtures/search-worker/src/index.ts:9
import { createAISearchNamespace } from "../../../../../src/index";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/tanstack-ai/test/e2e/fixtures/binding-worker/src/index.ts:9
import { createWorkersAiChat, type WorkersAiTextModel } from "../../../../../src/index";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/tanstack-ai/test/e2e/fixtures/binding-worker/src/index.ts:10
import { WorkersAiTTSAdapter } from "../../../../../src/adapters/workers-ai-tts";
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
examples/tanstack-ai/worker/index.ts:429
hostname === "169.254.169.254" ||
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
demos/agent-scheduler/worker-configuration.d.ts:216
atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
demos/agent-scheduler/worker-configuration.d.ts:330
declare function atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
demos/agent-task-manager-human-in-the-loop/worker-configuration.d.ts:216
atob(data: string): string;

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 0c7addca2977full audit observations/trust-audit/mcp-server/cloudflare__cloudflare-ai.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-250c7addca2977BLOCKF43first audit
06

Questions

What is the Cloudflare AI MCP server?

None

What tools does Cloudflare AI expose?

41 in total: 31 read-only, 8 that write, and 2 that can delete or overwrite (deleteKeyResult, deleteObjective). Every one is listed on this page with its risk.

Is Cloudflare AI safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (43/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Cloudflare AI need?

It reads ANTHROPIC_API_KEY, CLOUDFLARE_AI_GATEWAY_TOKEN, CLOUDFLARE_API_TOKEN, CLOUDFLARE_GATEWAY_AUTH_TOKEN, CLOUDFLARE_GATEWAY_NAME_UNAUTH, DEEPSEEK_API_KEY, GEMINI_API_KEY, GOOGLE_API_KEY, GROK_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY and XAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (0c7addca2977), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement