Atlas / MCP servers / hoangsonww / AI Agents Orchestrator

AI Agents OrchestratorBLOCK

mcp/hoangsonww/ai-agents-orchestrator

Intelligent orchestration system that coordinates multiple AI coding assistants (Claude, Codex, Gemini CLI, Copilot CLI) to collaborate on complex software development tasks via REPL or a Vue/Nuxt UI dashboard. Also includes an Agentic Team runtime with role-based multi-agent open communication & le

Verdict
BLOCK
Grade
D
Trust score
60 /100
Exposed tools
12 12r · 0w · 0d
Transport
—
License
MIT
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

![Pinia](

Read from source at commit 320cb530c8a3OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ai-agentic-coding-tools-orchestrator --env FLASK_SECRET_KEY=${FLASK_SECRET_KEY} --env FLASK_SECRET_KEY_AGENTIC=${FLASK_SECRET_KEY_AGENTIC} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "ai-agentic-coding-tools-orchestrator": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "FLASK_SECRET_KEY": "${FLASK_SECRET_KEY}",
        "FLASK_SECRET_KEY_AGENTIC": "${FLASK_SECRET_KEY_AGENTIC}"
      }
    }
  }
}
03

Exposed tools (12)

12 read · 0 write · 0 destructive.

ToolRiskDescription
agentic_team_configreadGet team role configuration: roles, agents, and responsibilities.
agentic_team_healthreadCheck agentic team health: status, team validity, agents.
agentic_team_list_agentsreadList available agents in the agentic team.
agentic_team_validatereadValidate team configuration: check all roles map to available agents.
analyze_depsreadAnalyze project dependencies.
code_complexityreadAnalyze Python code complexity metrics.
code_summaryreadGenerate summary of a code file.
find_patternsreadFind code patterns and anti-patterns.
list_enginesreadList both engines and their current status.
orchestrator_healthreadCheck orchestrator health: engine status, agent count, workflows.
orchestrator_list_agentsreadList available orchestrator agents with their roles.
orchestrator_list_workflowsreadList available workflows with their step sequences.
04

Trust audit

BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (8 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.anthropic · CWE-798, CWE-321
deployment/kubernetes/secrets.yaml.template:18
ANTHROPIC_API_KEY: "sk-ant-YOUR-ANTHROPIC-API-KEY-HERE"
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
orchestrator/observability/health.py:226
__import__(package)
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
AI-Collaboration-Skills/tests/test_security.py:33
secret = "-----BEGIN PRIVATE KEY-----\nabc\n-----END PRIVATE KEY-----"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.flake8
.flake8
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitlab-ci.yml
.gitlab-ci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.worktreeinclude
.worktreeinclude
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
mcp_server/tools/security_tools.py:357
"pattern": r"md5|sha1(?!ng)|DES|RC4",
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.gitlab-ci.yml:145
- mkdir -p ~/.kube
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.gitlab-ci.yml:146
- echo "$KUBE_CONFIG_STAGING" | base64 -d > ~/.kube/config
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.gitlab-ci.yml:174
- mkdir -p ~/.kube
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.gitlab-ci.yml:175
- echo "$KUBE_CONFIG_PROD" | base64 -d > ~/.kube/config
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.gitlab-ci.yml:207
- mkdir -p ~/.kube
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/ISSUE_TEMPLATE/question.yml:9
For general questions, please check the [README](../../README.md) and [ARCHITECTURE.md](../../ARCHITECTURE.md) first.
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
deployment/azure/scripts/deploy.sh:256
cd "$(dirname "$0")/../../kubernetes"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_functional_e2e.py:430
resp = client.get("/api/files/../../etc/passwd")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_production_hardening.py:128
response = client.get("/api/files/../../etc/passwd")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
QUICKSTART.md:44
make run-ui              # Orchestrator  → http://127.0.0.1:5001
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
QUICKSTART.md:45
make run-agentic-ui      # Agentic Team  → http://127.0.0.1:5002
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
QUICKSTART.md:46
python -m context_dashboard  # Dashboard → http://127.0.0.1:5003
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
QUICKSTART.md:68
make run-mcp-http    # HTTP → http://127.0.0.1:8000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
graphify/API_REFERENCE.md:5
**Base URL:** `http://127.0.0.1:5004`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
agentic_team/ui/frontend/package.json
@vueuse/core, axios, d3, marked, monaco-editor, pinia, socket.io-client, vue
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
orchestrator/ui/frontend/package.json
@vueuse/core, axios, marked, monaco-editor, pinia, socket.io-client, vue, vue-router
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 320cb530c8a3full audit observations/trust-audit/mcp-server/hoangsonww__ai-agents-orchestrator.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07320cb530c8a3BLOCKD60first audit
06

Questions

What is the AI Agents Orchestrator MCP server?

Intelligent orchestration system that coordinates multiple AI coding assistants (Claude, Codex, Gemini CLI, Copilot CLI) to collaborate on complex software development tasks via REPL or a Vue/Nuxt UI dashboard. Also includes an Agentic Team runtime with role-based multi-agent open communication & le

What tools does AI Agents Orchestrator expose?

12 in total: 12 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is AI Agents Orchestrator safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (60/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does AI Agents Orchestrator need?

It reads FLASK_SECRET_KEY and FLASK_SECRET_KEY_AGENTIC from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (320cb530c8a3), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement