Atlas / MCP servers / flytohub / Flyto Core

Flyto CoreBLOCK

mcp/flytohub/flyto-core

AI said it finished. Flyto2 shows the proof.

Verdict
BLOCK
Grade
F
Trust score
41 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
Apache-2.0
Stars
483
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI said it finished. Flyto2 shows the proof.

A Python execution engine for AI agents. It runs browser and API work as explicit steps, records what every step did, and replays from the step that failed — instead of re-running the whole job.

The current public inventory is 481 registry-backed modules across 89 catalog categories, including triggers, queue modules, workflow versioning, metering hooks, browser automation, API calls, data transforms, verification, files, and crypto.

[](https://pypi.org/project/flyto-core/) [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/downloads/)

flyto2.com · Cloud Automation · Documentation · MCP Docs · YouTube

Try it in 30 seconds

pip install flyto-core[browser] && playwright install chromium
flyto recipe competitor-intel --url https://github.com/pricing
Step  1/12  browser.launch         ✓      420ms
Step  2/12  browser.goto           ✓    1,203ms
Step  3/12  browser.evaluate       ✓       89ms
Step  4/12  browser.screenshot     ✓    1,847ms  → saved intel-desktop.png
Step  5/12  browser.viewport       ✓       12ms  → 390×844
Step  6/12  browser.screenshot     ✓    1,621ms  → saved intel-mobile.png
Step  7/12  browser.viewport       ✓        8ms  → 1280×720
Step  8/12  browser.performance    ✓    5,012ms  → Web Vitals captured
Step  9/12  browser.evaluate       ✓       45ms
Step 10/12  browser.evaluate       
Read from source at commit dfca2d55d5aeOBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add flyto-core -- pip flyto-core==2.32.1
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
internal-nacl-pluginread
internal-pdf-viewerreadPortable Document Format
mhjfbmdgcfjbbpaeojofohoefgiehjairead
04

Trust audit

BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (12 observation(s))
Shell
declared (13 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/core/modules/atomic/flow/breakpoint.py:24
stability='beta',  # Uses eval() for auto-approve conditions - requires review
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/core/modules/registry/rule_config.py:78
description="Detects dangerous eval() and exec() usage",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/core/modules/validator.py:871
f"eval() used (allowed for debugger modules)",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/core/modules/atomic/k8s/apply.py:166
placeholder='~/.kube/config'),
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/core/modules/atomic/k8s/get_pods.py:132
placeholder='~/.kube/config'),
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/core/modules/atomic/k8s/logs.py:96
placeholder='~/.kube/config'),
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/core/modules/atomic/k8s/scale.py:86
placeholder='~/.kube/config'),
Why it matters. touches a credential store
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/core/modules/atomic/database/insert.py:354
connection_string = f"postgresql://{user}:{password}@{host}:{port}/{database}"
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/core/modules/atomic/database/query.py:332
connection_string = f"postgresql://{user}:{password}@{host}:{port}/{database}"
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/core/modules/atomic/database/update.py:254
connection_string = f"postgresql://{user}:{password}@{host}:{port}/{database}"
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/lint_modules.py:437
package = importlib.import_module(package_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/lint_modules.py:446
importlib.import_module(name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/core/modules/atomic/__init__.py:69
importlib.import_module(f'.{name}', __package__)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/core/modules/atomic/__init__.py:73
importlib.import_module(f'.{name}', __package__)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/core/modules/quality/engine.py:375
importlib.import_module(modname)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/learn.py:95
print(f"{Colors.FAIL}No API key found. Set {env_map.get(provider, 'API_KEY')} or use --api-key{Colors.ENDC}")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/fix_schema_v2.py:96
'callback_url': 'https://example.com/callback',
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/core/module_policy.py:56
"env.get",          # reads ANY host env var (API keys/DSNs) = secret exfil
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/core/verification_service.py:54
callback_url: str | None = None
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/core/verification_service.py:323
if body.callback_url:
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/core/verification_service.py:324
return body.callback_url
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/core/api/security.py:33
"http://127.0.0.1:3000",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/core/api/security.py:34
"http://127.0.0.1:8334",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/core/test_reported_advisories_2026_08_19.py:58
{'connection_string': 'postgresql://u:[email protected]:5432/x',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/core/test_reported_advisories_2026_08_19.py:117
'connection_string': 'postgresql://u:[email protected]:1/x',

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha dfca2d55d5aefull audit observations/trust-audit/mcp-server/flytohub__flyto-core.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-30dfca2d55d5aeBLOCKF41first audit
06

Questions

What is the Flyto Core MCP server?

AI said it finished. Flyto2 shows the proof.

What tools does Flyto Core expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Flyto Core safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (41/100) and found 10 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Flyto Core need?

It reads ANTHROPIC_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, FIGMA_TOKEN, FLYTO_API_TOKEN, FLYTO_DEV_TOKEN, FLYTO_RUNNER_SECRET, FLYTO_TEST_PASSWORD, FLYTO_TOKEN, FLYTO_VERIFICATION_API_KEY, FLYTO_VERIFICATION_SECRET and GOOGLE_AI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Flyto Core run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as flyto2-visual-worker at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (dfca2d55d5ae), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement