Flyto CoreBLOCK
AI said it finished. Flyto2 shows the proof.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AI said it finished. Flyto2 shows the proof.
A Python execution engine for AI agents. It runs browser and API work as explicit steps, records what every step did, and replays from the step that failed — instead of re-running the whole job.
The current public inventory is 481 registry-backed modules across 89 catalog categories, including triggers, queue modules, workflow versioning, metering hooks, browser automation, API calls, data transforms, verification, files, and crypto.
[](https://pypi.org/project/flyto-core/) [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/downloads/)
flyto2.com · Cloud Automation · Documentation · MCP Docs · YouTube
Try it in 30 seconds
pip install flyto-core[browser] && playwright install chromium flyto recipe competitor-intel --url https://github.com/pricing
Step 1/12 browser.launch ✓ 420ms Step 2/12 browser.goto ✓ 1,203ms Step 3/12 browser.evaluate ✓ 89ms Step 4/12 browser.screenshot ✓ 1,847ms → saved intel-desktop.png Step 5/12 browser.viewport ✓ 12ms → 390×844 Step 6/12 browser.screenshot ✓ 1,621ms → saved intel-mobile.png Step 7/12 browser.viewport ✓ 8ms → 1280×720 Step 8/12 browser.performance ✓ 5,012ms → Web Vitals captured Step 9/12 browser.evaluate ✓ 45ms Step 10/12 browser.evaluate
dfca2d55d5aeOBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add flyto-core -- pip flyto-core==2.32.1
Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
internal-nacl-plugin | read | |
internal-pdf-viewer | read | Portable Document Format |
mhjfbmdgcfjbbpaeojofohoefgiehjai | read |
Trust audit
BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (13 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
stability='beta', # Uses eval() for auto-approve conditions - requires review
description="Detects dangerous eval() and exec() usage",
f"eval() used (allowed for debugger modules)",
placeholder='~/.kube/config'),
placeholder='~/.kube/config'),
placeholder='~/.kube/config'),
placeholder='~/.kube/config'),
connection_string = f"postgresql://{user}:{password}@{host}:{port}/{database}"connection_string = f"postgresql://{user}:{password}@{host}:{port}/{database}"connection_string = f"postgresql://{user}:{password}@{host}:{port}/{database}"package = importlib.import_module(package_name)
importlib.import_module(name)
importlib.import_module(f'.{name}', __package__)importlib.import_module(f'.{name}', __package__)importlib.import_module(modname)
print(f"{Colors.FAIL}No API key found. Set {env_map.get(provider, 'API_KEY')} or use --api-key{Colors.ENDC}")'callback_url': 'https://example.com/callback',
"env.get", # reads ANY host env var (API keys/DSNs) = secret exfil
callback_url: str | None = None
if body.callback_url:
return body.callback_url
"http://127.0.0.1:3000",
"http://127.0.0.1:8334",
{'connection_string': 'postgresql://u:[email protected]:5432/x','connection_string': 'postgresql://u:[email protected]:1/x',
Gates applied: no_behavioural_pass.
dfca2d55d5aefull audit observations/trust-audit/mcp-server/flytohub__flyto-core.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | dfca2d55d5ae | BLOCK | F | 41 | first audit |
Questions
What is the Flyto Core MCP server?
AI said it finished. Flyto2 shows the proof.
What tools does Flyto Core expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Flyto Core safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (41/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Flyto Core need?
It reads ANTHROPIC_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, FIGMA_TOKEN, FLYTO_API_TOKEN, FLYTO_DEV_TOKEN, FLYTO_RUNNER_SECRET, FLYTO_TEST_PASSWORD, FLYTO_TOKEN, FLYTO_VERIFICATION_API_KEY, FLYTO_VERIFICATION_SECRET and GOOGLE_AI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Flyto Core run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as flyto2-visual-worker at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (dfca2d55d5ae), read on 2026-09-30. The repository is watched and re-audited when it changes.