FlAPIBLOCK
API Framework heavily relying on the power of DuckDB and DuckDB extensions. Ready to build performant and cost-efficient APIs on top of BigQuery or Snowflake for AI Agents and Data Apps
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Write a SQL template and a few lines of YAML; flAPI serves it as a REST endpoint and an MCP tool for AI agents — with the same parameter validators and the same cache behind both, and role-based access control on each. One static binary with DuckDB inside: Parquet, Postgres, BigQuery, S3 and 50+ more sources.
⚡ Features
- Automatic API Generation: Create APIs for your datasets without coding
- MCP (Model Context Protocol) Support: Declarative AI tools alongside REST endpoints, speaking the latest MCP `2026-07-28` revision (dual-era: modern and legacy clients) — with the Tasks extension for long-running queries, typed schemas + structured results, OAuth discovery, per-tool RBAC, shadow/dry-run, response shaping, rate limiting, and a prompt-injection hygiene scanner
- Multiple Data Sources: Connect to BigQuery, SAP ERP & BW (via ERPL), Parquet, Iceberg, Postgres, MySQL, and more
- SQL Templates: Mustache-like syntax. Typed
{{ params.X }}references onint/double/boolean/date/time/uuid/enum/email/stringfields are bound as DuckDB prepared statements — SQL injection is structurally impossible for those sites - Caching: DuckLake-backed cache with full refresh and incremental sync
- Production security: PBKDF2-SHA256 password hashing, config-driven CORS allowlist, per-user rate limiting, JSONL request audit log, TLS termination, startup config auditor — all opt-in via single-line YAML so
flapii project initdemos stay simp
ae764b3dfd2aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add flapi-io -- uvx flapi-io==0.0.0-dev
Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
prompt | read | desc |
resource | read | desc |
test-tool | read | Test tool |
tool | read | desc |
Trust audit
BLOCKgrade F · trust 28/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
payload.ts
payload.ts
payload.ts
const doc = YAML.load(content) as YamlEndpoint;
httpsAgent: config.verifyTls ? undefined : new https.Agent({ rejectUnauthorized: false }),.option('--insecure', 'Disable TLS/SSL certificate verification', false)httpsAgent: settings.verifyTls ? undefined : new https.Agent({ rejectUnauthorized: false }),/// postgresql://alice:hunter2@db/prod (userinfo)
model's context. A poisoned description ("ignore previous instructions and.clang-format
.clang-tidy
compile_commands.json
console.log('[Flapi] updateExplorerWithToken called, token', token ? 'set' : 'not set');console.log('[Flapi] updateSchemaWithToken called, token', token ? 'set' : 'not set');"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1122],{1122:(e,t,n)=>{n.r(t),n.d(t,{conf:()=>i,language:()=>r});var i={wordPattern:/(#?-?\d*\.\d\w*%?)|([@#!.:]?[\"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1560],{1560:(e,t,n)=>{n.r(t),n.d(t,{conf:()=>r,language:()=>s});var r={comments:{lineComment:"#",blockComment:["=b"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1710],{91710:(e,t,n)=>{n.r(t),n.d(t,{conf:()=>i,language:()=>o});var i={comments:{lineComment:"#"},brackets:[["{","use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1740],{41740:(e,n,t)=>{t.r(n),t.d(n,{conf:()=>o,language:()=>r});var o={comments:{lineComment:"'",blockComment:["/"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1888],{11888:(e,t,n)=>{n.r(t),n.d(t,{conf:()=>o,language:()=>i});var o={wordPattern:/(#?-?\d*\.\d\w*%?)|([@$#!.:]?key_file << "-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----\n";
-----BEGIN PRIVATE KEY-----
assert "-----BEGIN PRIVATE KEY-----" in content or "-----BEGIN RSA PRIVATE KEY-----" in content
customers.parquet
customers.parquet
data_types.parquet
Gates applied: instruction_override, no_behavioural_pass.
ae764b3dfd2afull audit observations/trust-audit/mcp-server/datazoode__flapi.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ae764b3dfd2a | BLOCK | F | 28 | first audit |
Questions
What is the FlAPI MCP server?
API Framework heavily relying on the power of DuckDB and DuckDB extensions. Ready to build performant and cost-efficient APIs on top of BigQuery or Snowflake for AI Agents and Data Apps
What tools does FlAPI expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is FlAPI safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (28/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does FlAPI need?
It reads FLAPI_CONFIG_SERVICE_TOKEN, FLAPI_GEMINI_KEY, FLAPI_TOKEN and POSTHOG_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does FlAPI run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as flapi-vscode at 26.6.13.
How current is this page?
The grade is for one exact copy of the source (ae764b3dfd2a), read on 2026-10-07. The repository is watched and re-audited when it changes.