GlifSAFE
Deprecated — use the hosted Glif MCP server at https://glif.app/mcp
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Glif is a media-generation agent: generate images, video, and audio, transcribe, render HTML, search the web, run code, and chain multi-step media operations — from any MCP client.
- Endpoint:
https://glif.app/api/mcp(Streamable HTTP, JSON-RPC 2.0) - Auth: OAuth 2.1 with dynamic client registration — sign in with your Glif account, no API keys
- Install page with one-click buttons: https://glif.app/mcp
- Docs for agents: https://glif.app/llms.txt
This repo holds the registry metadata for the hosted server (see server.json); the server itself is part of the glif.app platform and is not open source.
[!NOTE] Looking for the old locally-run stdio server (npm @glifxyz/glif-mcp-server)? It's deprecated — the code is parked on the `legacy-local-server` branch.Tools
compose_project does the work — describe what you want in plain language, including a whole series of variations, and Glif picks the models and chains the steps. It returns a job_id immediately; poll get_job_status for the media, which comes back as resource_link blocks pointing at CDN URLs. The rest are read and upload helpers. Call tools/list for the authoritative set, or see https://glif.app/mcp.
Generation spends credits from the signed-in Glif account; read-only tools are free. See https://glif.app/pricing.
Install
Claude (web / desktop)
Settings → Connectors → Add custom connector, paste:
https://glif.app/api/mcp
Claude Code
claude mcp add --scope user --transport http glif "https://glif.app/api/mcp"
Cursor
[](https://cursor.com/install-mcp?name=glif&config=eyJ1cmwiOiJodHRwczovL2dsaWYuYXBwL2FwaS9tY3AifQ%3D%3D)
Or add to .cursor/mcp.json:
{ "mcpS7a8da71842dfOBSERVED · 2026-10-06Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
streamable-http
Gates applied: no_behavioural_pass.
7a8da71842dffull audit observations/trust-audit/mcp-server/glifxyz__glif.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 7a8da71842df | SAFE | B | 89 | first audit |
Questions
What is the Glif MCP server?
Deprecated — use the hosted Glif MCP server at https://glif.app/mcp
Is Glif safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Glif need?
No credential environment variables were found in its source, so it appears to need none.
How does Glif run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (7a8da71842df), read on 2026-10-06. The repository is watched and re-audited when it changes.