Atlas / MCP servers / f / Poke Gate

Poke GateBLOCK

mcp/f/poke-gate

Expose your machine to your Poke AI assistant via MCP tunnel

Verdict
BLOCK
Grade
D
Trust score
60 /100
Exposed tools
9 5r · 4w · 0d
Transport
—
License
MIT
Stars
79
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Poke Gate

Let your Poke AI assistant access your machine. A community project — not affiliated with Poke or The Interaction Company.

Run Poke Gate on your Mac, then message Poke from iMessage, Telegram, or SMS to run commands, read files, take screenshots, and more — all on your machine.

Install

Homebrew (recommended)

brew install f/tap/poke-gate

Install via npx

If you have Node.js installed, you can download and install the macOS app with a single command:

npx poke-gate download-macos

This downloads the latest DMG from GitHub Releases, installs the app to /Applications, and clears the quarantine flag automatically.

Don't have Node.js? Install it first:

# Option 1: Homebrew
brew install node

# Option 2: Download from https://nodejs.org

Manual download

Download the latest Poke.macOS.Gate.dmg from Releases, open it, and drag to Applications. Since the app is not notarized, you may need to run:

xattr -cr /Applications/Poke\ macOS\ Gate.app

CLI only (no macOS app needed)

If you just want to run poke-gate from the terminal without the menu bar app:

n
Read from source at commit 6354bdbd58caOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add poke-gate --env BEEPER_TOKEN=${BEEPER_TOKEN} --env POKE_GATE_HMAC_SECRET=${POKE_GATE_HMAC_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "poke-gate": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "BEEPER_TOKEN": "${BEEPER_TOKEN}",
        "POKE_GATE_HMAC_SECRET": "${POKE_GATE_HMAC_SECRET}"
      }
    }
  }
}
03

Exposed tools (9)

5 read · 4 write · 0 destructive.

ToolRiskDescription
list_directoryreadList files and directories at a given path on the user
network_speedwriteRun a built-in internet speed test and return download/upload Mbps.
read_filereadRead the contents of a file on the user
read_imagereadRead an image or binary file and return it as base64-encoded data.
run_agentwriteRun a Poke Gate agent by name. Agents are scheduled scripts in ~/.config/poke-gate/agents/.
run_commandwriteExecute a shell command on the user
system_inforeadGet system information: OS, hostname, architecture, uptime, memory, and home directory.
take_screenshotreadTake a screenshot of the user
write_filewriteWrite content to a file on the user
04

Trust audit

BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (10 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (23)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/agents.js:143
exec(`node "${agent.path}"`, {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/mcp-server.js:462
exec(commandToRun, {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
src/mcp-server.js:52
/(^|\s)sudo(\s|$)/i,
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
src/mcp-server.js:276
const withoutSudo = withoutParens.replace(/^sudo\s+/, "");
Why it matters. asks for elevated privileges
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
src/mcp-server.js:60
/launchctl\s+bootout/i,
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/browser-session-token.js:124
const response = await fetchImpl(`http://127.0.0.1:${port}/json/version`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/browser-session-token.js:139
const response = await fetchImpl(`http://127.0.0.1:${port}/json/new?${encodeURIComponent(url)}`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/browser-session-token.js:148
const listResponse = await fetchImpl(`http://127.0.0.1:${port}/json/list`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/browser-session-token.js:164
const response = await fetchImpl(`http://127.0.0.1:${port}/json/list`);
LOWInventory / provenance · inv.hidden_file · CWE-1104
.remarkignore
.remarkignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.remarkrc.mjs
.remarkrc.mjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
examples/agents/.env.beeper
.env.beeper
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/browser-session-token.js:374
const expectedAccept = createHash('sha1')
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:33
sudo xcode-select -s "${XCODE_APP}/Contents/Developer"
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/release.yml:84
sudo xcode-select -s "${XCODE_APP}/Contents/Developer"
Why it matters. asks for elevated privileges
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
test/mcp-server-access-policy.test.js:9
assert.equal(evaluateAccessPolicy("run_command", { command: "sudo reboot" }, "full"), null);
Why it matters. asks for elevated privileges
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
docs/package.json
mermaid, vitepress-plugin-mermaid, vitepress
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
poke, @eslint/js, eslint, globals, prettier, remark-cli, remark-lint-list-item-indent, remark-parse
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
assets/logo.png
assets/logo.png
Why it matters. 1263701 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
clients/Poke macOS Gate/Poke macOS Gate/Assets.xcassets/AppIcon.appiconset/[email protected]
clients/Poke macOS Gate/Poke macOS Gate/Assets.xcassets/AppIcon.appiconset/[email protected]
Why it matters. 1403452 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
conns.json
conns.json
Why it matters. 1159934 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/public/logo.png
docs/public/logo.png
Why it matters. 1263701 bytes not read
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6354bdbd58cafull audit observations/trust-audit/mcp-server/f__poke-gate.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076354bdbd58caBLOCKD60first audit
06

Questions

What is the Poke Gate MCP server?

Expose your machine to your Poke AI assistant via MCP tunnel

What tools does Poke Gate expose?

9 in total: 5 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Poke Gate safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (60/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Poke Gate need?

It reads BEEPER_TOKEN and POKE_GATE_HMAC_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (6354bdbd58ca), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement