Atlas / MCP servers / datazoode / FlAPI

FlAPIBLOCK

mcp/datazoode/flapi

API Framework heavily relying on the power of DuckDB and DuckDB extensions. Ready to build performant and cost-efficient APIs on top of BigQuery or Snowflake for AI Agents and Data Apps

Verdict
BLOCK
Grade
F
Trust score
28 /100
Exposed tools
4 4r · 0w · 0d
Transport
streamable-http
License
NOASSERTION
Stars
74
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Write a SQL template and a few lines of YAML; flAPI serves it as a REST endpoint and an MCP tool for AI agents — with the same parameter validators and the same cache behind both, and role-based access control on each. One static binary with DuckDB inside: Parquet, Postgres, BigQuery, S3 and 50+ more sources.

⚡ Features

  • Automatic API Generation: Create APIs for your datasets without coding
  • MCP (Model Context Protocol) Support: Declarative AI tools alongside REST endpoints, speaking the latest MCP `2026-07-28` revision (dual-era: modern and legacy clients) — with the Tasks extension for long-running queries, typed schemas + structured results, OAuth discovery, per-tool RBAC, shadow/dry-run, response shaping, rate limiting, and a prompt-injection hygiene scanner
  • Multiple Data Sources: Connect to BigQuery, SAP ERP & BW (via ERPL), Parquet, Iceberg, Postgres, MySQL, and more
  • SQL Templates: Mustache-like syntax. Typed {{ params.X }} references on int/double/boolean/date/time/uuid/enum/email/string fields are bound as DuckDB prepared statements — SQL injection is structurally impossible for those sites
  • Caching: DuckLake-backed cache with full refresh and incremental sync
  • Production security: PBKDF2-SHA256 password hashing, config-driven CORS allowlist, per-user rate limiting, JSONL request audit log, TLS termination, startup config auditor — all opt-in via single-line YAML so flapii project init demos stay simp
Read from source at commit ae764b3dfd2aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add flapi-io -- uvx flapi-io==0.0.0-dev
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
promptreaddesc
resourcereaddesc
test-toolreadTest tool
toolreaddesc
04

Trust audit

BLOCKgrade F · trust 28/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (7 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
cli/shared/src/lib/payload.ts
payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
cli/src/commands/payload.ts
payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
cli/src/lib/payload.ts
payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
cli/src/commands/config/validate.ts:50
const doc = YAML.load(content) as YamlEndpoint;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
cli/shared/src/lib/http.ts:29
httpsAgent: config.verifyTls ? undefined : new https.Agent({ rejectUnauthorized: false }),
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
cli/src/index.ts:33
.option('--insecure', 'Disable TLS/SSL certificate verification', false)
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
cli/vscode-extension/src/services/endpointTestService.ts:101
httpsAgent: settings.verifyTls ? undefined : new https.Agent({ rejectUnauthorized: false }),
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/template_secrets.cpp:27
///   postgresql://alice:hunter2@db/prod          (userinfo)
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/promotion/drafts/blog-flagship-rest-plus-mcp.md:239
model's context. A poisoned description ("ignore previous instructions and
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.clang-format
.clang-format
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.clang-tidy
.clang-tidy
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
compile_commands.json
compile_commands.json
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/vscode-extension/src/extension.ts:91
console.log('[Flapi] updateExplorerWithToken called, token', token ? 'set' : 'not set');
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/vscode-extension/src/extension.ts:102
console.log('[Flapi] updateSchemaWithToken called, token', token ? 'set' : 'not set');
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/vscode-extension/webview/1122.endpointEditor.bundle.js:2
"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1122],{1122:(e,t,n)=>{n.r(t),n.d(t,{conf:()=>i,language:()=>r});var i={wordPattern:/(#?-?\d*\.\d\w*%?)|([@#!.:]?[\
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/vscode-extension/webview/1560.endpointEditor.bundle.js:2
"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1560],{1560:(e,t,n)=>{n.r(t),n.d(t,{conf:()=>r,language:()=>s});var r={comments:{lineComment:"#",blockComment:["=b
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/vscode-extension/webview/1710.endpointEditor.bundle.js:2
"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1710],{91710:(e,t,n)=>{n.r(t),n.d(t,{conf:()=>i,language:()=>o});var i={comments:{lineComment:"#"},brackets:[["{",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/vscode-extension/webview/1740.endpointEditor.bundle.js:2
"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1740],{41740:(e,n,t)=>{t.r(n),t.d(n,{conf:()=>o,language:()=>r});var o={comments:{lineComment:"'",blockComment:["/
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/vscode-extension/webview/1888.endpointEditor.bundle.js:2
"use strict";(self.webpackChunkflapi_vscode=self.webpackChunkflapi_vscode||[]).push([[1888],{11888:(e,t,n)=>{n.r(t),n.d(t,{conf:()=>o,language:()=>i});var o={wordPattern:/(#?-?\d*\.\d\w*%?)|([@$#!.:]?
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
test/cpp/https_config_test.cpp:84
key_file << "-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----\n";
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
test/integration/fixtures/test_key.pem:1
-----BEGIN PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
test/integration/test_https_config.py:298
assert "-----BEGIN PRIVATE KEY-----" in content or "-----BEGIN RSA PRIVATE KEY-----" in content
LOWInventory / provenance · inv.binary · CWE-1104
examples/data/customers.parquet
customers.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
test/integration/api_configuration/data/customers.parquet
customers.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
test/integration/api_configuration/data/data_types.parquet
data_types.parquet
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ae764b3dfd2afull audit observations/trust-audit/mcp-server/datazoode__flapi.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ae764b3dfd2aBLOCKF28first audit
06

Questions

What is the FlAPI MCP server?

API Framework heavily relying on the power of DuckDB and DuckDB extensions. Ready to build performant and cost-efficient APIs on top of BigQuery or Snowflake for AI Agents and Data Apps

What tools does FlAPI expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is FlAPI safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (28/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does FlAPI need?

It reads FLAPI_CONFIG_SERVICE_TOKEN, FLAPI_GEMINI_KEY, FLAPI_TOKEN and POSTHOG_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does FlAPI run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as flapi-vscode at 26.6.13.

How current is this page?

The grade is for one exact copy of the source (ae764b3dfd2a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement