Atlas / MCP servers / dcspark / Shinkai

ShinkaiBLOCK

mcp/dcspark/shinkai-1

Shinkai is a two click install App that allows you to create Local AI agents in 5 minutes or less using a simple UI. Supports: MCPs, Remote and Local AI, Crypto and Payments.

Verdict
BLOCK
Grade
F
Trust score
50 /100
Exposed tools
5 5r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
433
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Shinkai

Create Powerful AI Agents using local or remote AIs

Build collaborative AI agents that work together, handle payments, and automate complex workflows

Shinkai is a free, open-source platform that democratizes AI agent creation. No coding required – just drag, drop, and deploy intelligent agents that can work across platforms and handle real-world tasks.

Read this in: 简体中文 | 粵語 | 한국어 | 日本語 | Español

Features • Demo • Examples • Quick Start • Development • Documentation

🚀 Features

**🎯 No-Code Agent Buil

Read from source at commit ddaa96e5f6ecOBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add source -- npx -y @shinkai/[email protected]
claude-desktop
{
  "mcpServers": {
    "source": {
      "command": "npx",
      "args": [
        "-y",
        "@shinkai/[email protected]"
      ]
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
ExoreadA specialized model platform focused on precise information extraction, efficient summarization, and reliable knowledge retrieval.
GeminireadA state-of-the-art large language model offering advanced reasoning, multimodal capabilities, and extended context handling.
GroqreadA hardware-accelerated inference solution optimized for low-latency and high-throughput deployments.
OpenRouterreadA scalable orchestration layer that intelligently routes queries across multiple AI models, optimizing performance and cost.
gpt-ossreadOpenAI’s open-weight models designed for powerful reasoning, agentic tasks, and versatile developer use cases.
04

Trust audit

BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (10 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
apps/shinkai-desktop/src/windows/shinkai-artifacts/main.tsx:66
const evalCode = new Function('scope', fullCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
ci-scripts/download-side-binaries.ts:46
return exec(`chmod +x ${path}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/shinkai-desktop/public/sqljs/sql-wasm.wasm
sql-wasm.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/shinkai-desktop/src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
libs/shinkai-ui/src/assets/fonts/newake.otf
newake.otf
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/shinkai-desktop/src-tauri/src/local_shinkai_node/shinkai_node_options.rs:219
embeddings_server_url: Some("http://127.0.0.1:11435".to_string()),
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/shinkai-desktop/src/components/reset-connection-dialog.tsx:45
nodeAddress: 'http://127.0.0.1:9550',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/shinkai-desktop/src/components/shinkai-node-manager/components/ollama-model-install-button.tsx:26
const ollamaConfig = { host: ollamaApiUrl || 'http://127.0.0.1:11435' };
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/shinkai-desktop/src/components/shinkai-node-manager/components/ollama-models-repository.tsx:64
const ollamaConfig = { host: ollamaApiUrl || 'http://127.0.0.1:11435' };
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/shinkai-desktop/src/pages/ais.tsx:534
const ollamaConfig = { host: 'http://127.0.0.1:11435' };
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
libs/shinkai-ui/src/assets/icons/general.tsx:485
xlinkHref="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGQAAABkCAYAAABw4pVUAAAACXBIWXMAAAsTAAALEwEAmpwYAAAgAElEQVR4nO28Z3BU19auO2Vpf/eeqlO3bp179rbJYBAIRZQjapFzMs7ggAO2wQhjAybnnEzOOeeMSSZIQiihnFO3Oit
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cursor/skills/frontend-design/.skill-meta.json
.skill-meta.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/shinkai-desktop/src-tauri/.taurignore
.taurignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
libs/shinkai-artifacts/.babelrc
.babelrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
libs/shinkai-i18n/.babelrc
.babelrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/shinkai-desktop/eslint.config.mjs:1
import baseConfig from '../../eslint.config.mjs';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/shinkai-desktop/index.d.ts:6
resources: typeof import('../../libs/shinkai-i18n/src/lib/resources').default;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/shinkai-desktop/src/components/agent/agent-form.tsx:135
import { useSetJobScope } from '../../components/chat/context/set-job-scope-context';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/shinkai-desktop/src/components/agent/agent-form.tsx:136
import { useURLQueryParams } from '../../hooks/use-url-query-params';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/shinkai-desktop/src/components/agent/agent-form.tsx:137
import { treeOptions } from '../../lib/constants';
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
docs/shinkai-tray-update-system.md:128
"signature": "dW50cnVzdGVkIGNvbW1lbnQ6IHNpZ25hdHVyZSBmcm9tIHRhdXJpIHNlY3JldCBrZXkKUlVTNG50TktKVkozbXdiZXdua1pvUFVMT0d2M2pwd2g0RlZvck9zTjNNSHZ6TjJsN2ZtaWpnVzAySzFWSXZxckx0TUF6bmRjUHhiMDhsVVo5MTExcnJLR2
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/shinkai-desktop/src/components/vector-fs/components/vector-fs-item-detail.tsx:51
const binaryString = atob(fileContentBase64);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/shinkai-desktop/src/components/vector-fs/components/vector-fs-item-detail.tsx:64
const binaryString = atob(fileContentBase64);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/shinkai-desktop/src/components/vector-fs/components/vector-fs-item-detail.tsx:147
const binaryData = Uint8Array.from(atob(response), (c) =>

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha ddaa96e5f6ecfull audit observations/trust-audit/mcp-server/dcspark__shinkai-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01ddaa96e5f6ecBLOCKF50first audit
06

Questions

What is the Shinkai MCP server?

Shinkai is a two click install App that allows you to create Local AI agents in 5 minutes or less using a simple UI. Supports: MCPs, Remote and Local AI, Crypto and Payments.

What tools does Shinkai expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Shinkai safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (50/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Shinkai need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (ddaa96e5f6ec), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement