Systemprompt MultimodalBLOCK
[DEPRECATED] Superseded by systempromptio/systemprompt-template and systempromptio/systemprompt-core. Multi-modal MCP client for voice-powered agentic workflows.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
## ⚠️ Deprecated — no longer maintained This repository has been superseded. All new development and support lives in: - [systempromptio/systemprompt-template](https://github.com/systempromptio/systemprompt-template) — start here. Self-hosted evaluation of the full systemprompt.io AI governance infrastructure. - [systempromptio/systemprompt-core](https://github.com/systempromptio/systemprompt-core) — the underlying Rust library (MCP, A2A, OAuth 2.1, audit, compile-time extensions). Learn more at systemprompt.io. The original README is preserved below for historical reference.
[](https://discord.com/invite/wkAbSuPWpr) [](https://twitter.com/tyingshoelaces_) [](https://www.linkedin.com/in/edjburton/)
Website • Documentation • Blog • Get API Key
A modern voice-controlled AI interface powered by Google Gemini and Anthropic MCP (Model Control Protocol). Transform how you interact with AI through natural speech and multimodal inputs.
⚠️ Important Note: This open source project is currently in development and in early access. It is not currently compatible with Safari but has been tested on Chrome with Linux, Windows, and MacOS. If you have any problems, please let us know on Discord or GitHub.
If you find this project useful, please consider:
- ⭐ Starring it on GitHub
- 🔄 Sharing it with others
- 💬 Joining our Discord community
🌟 Overview
A modern Vite + TypeScript application that enables voice-controlled AI workflows through MCP (Model Co
94b06cad5cb7OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add google-auth-setup --env NOTION_API_KEY=${NOTION_API_KEY} --env SYSTEMPROMPT_API_KEY=${SYSTEMPROMPT_API_KEY} --env VITE_SYSTEMPROMPT_API_KEY=${VITE_SYSTEMPROMPT_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"google-auth-setup": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"NOTION_API_KEY": "${NOTION_API_KEY}",
"SYSTEMPROMPT_API_KEY": "${SYSTEMPROMPT_API_KEY}",
"VITE_SYSTEMPROMPT_API_KEY": "${VITE_SYSTEMPROMPT_API_KEY}"
}
}
}
}Exposed tools (15)
14 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
NewAgent | read | New agent |
TestAgent1 | read | Test agent 1 |
TestAgent2 | read | Test agent 2 |
create_connection | write | Create a new Celigo connection |
mcpTool | read | An MCP tool |
param1 | read | A test parameter |
sse | read | Server-sent events transport |
stdio | read | Standard input/output transport |
test-prompt | read | A test prompt |
testFunction | read | A test function |
testPrompt | read | Test prompt description |
testTool | read | A test tool |
test_tool | read | Test tool |
tool1 | read | Tool 1 |
tool2 | read | Tool 2 |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
exec(commands[index], (error) => {.gitkeep
console.log("Using API key starting with:", apiKey.substring(0, 4));console.log(chalk.cyan("After loadApiKey, using API key:"), apiKey);console.log(`Token file used: ${path.resolve(tokenPath)}`);import { ConfigHandlers } from "../../handlers/configHandlers.js";import type { McpConfig } from "../../types/index.js";import { McpHandlers } from "../../handlers/mcpHandlers.js";import type { McpConfig } from "../../types/index.js";import { McpApiService } from "../../services/McpApiService.js";const binaryString = atob(base64);
@google/generative-ai, @iconify/react, @modelcontextprotocol/sdk, @nextui-org/react, @types/react-router-dom, classnames, cors, dotenv
@inquirer/prompts, @modelcontextprotocol/sdk, axios, chalk, cors, dotenv, eventsource, express
googleapis, google-auth-library, ts-node, typescript, @types/node
Gates applied: no_behavioural_pass.
94b06cad5cb7full audit observations/trust-audit/mcp-server/ejb503__systemprompt-multimodal.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 94b06cad5cb7 | BLOCK | D | 69 | first audit |
Questions
What is the Systemprompt Multimodal MCP server?
[DEPRECATED] Superseded by systempromptio/systemprompt-template and systempromptio/systemprompt-core. Multi-modal MCP client for voice-powered agentic workflows.
What tools does Systemprompt Multimodal expose?
15 in total: 14 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Systemprompt Multimodal safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Systemprompt Multimodal need?
It reads NOTION_API_KEY, SYSTEMPROMPT_API_KEY and VITE_SYSTEMPROMPT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Systemprompt Multimodal run?
It speaks sse, so it runs as a service you connect to over the network. It is published on npm as google-auth-setup at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (94b06cad5cb7), read on 2026-10-06. The repository is watched and re-audited when it changes.