AI Agents OrchestratorBLOCK
Intelligent orchestration system that coordinates multiple AI coding assistants (Claude, Codex, Gemini CLI, Copilot CLI) to collaborate on complex software development tasks via REPL or a Vue/Nuxt UI dashboard. Also includes an Agentic Team runtime with role-based multi-agent open communication & le
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

12 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
agentic_team_config | read | Get team role configuration: roles, agents, and responsibilities. |
agentic_team_health | read | Check agentic team health: status, team validity, agents. |
agentic_team_list_agents | read | List available agents in the agentic team. |
agentic_team_validate | read | Validate team configuration: check all roles map to available agents. |
analyze_deps | read | Analyze project dependencies. |
code_complexity | read | Analyze Python code complexity metrics. |
code_summary | read | Generate summary of a code file. |
find_patterns | read | Find code patterns and anti-patterns. |
list_engines | read | List both engines and their current status. |
orchestrator_health | read | Check orchestrator health: engine status, agent count, workflows. |
orchestrator_list_agents | read | List available orchestrator agents with their roles. |
orchestrator_list_workflows | read | List available workflows with their step sequences. |
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
ANTHROPIC_API_KEY: "sk-ant-YOUR-ANTHROPIC-API-KEY-HERE"
__import__(package)
secret = "-----BEGIN PRIVATE KEY-----\nabc\n-----END PRIVATE KEY-----"
.flake8
.gitlab-ci.yml
.pre-commit-config.yaml
.prettierignore
.worktreeinclude
"pattern": r"md5|sha1(?!ng)|DES|RC4",
- mkdir -p ~/.kube
- echo "$KUBE_CONFIG_STAGING" | base64 -d > ~/.kube/config
- mkdir -p ~/.kube
- echo "$KUBE_CONFIG_PROD" | base64 -d > ~/.kube/config
- mkdir -p ~/.kube
For general questions, please check the [README](../../README.md) and [ARCHITECTURE.md](../../ARCHITECTURE.md) first.
cd "$(dirname "$0")/../../kubernetes"
resp = client.get("/api/files/../../etc/passwd")response = client.get("/api/files/../../etc/passwd")make run-ui # Orchestrator → http://127.0.0.1:5001
make run-agentic-ui # Agentic Team → http://127.0.0.1:5002
python -m context_dashboard # Dashboard → http://127.0.0.1:5003
make run-mcp-http # HTTP → http://127.0.0.1:8000
**Base URL:** `http://127.0.0.1:5004`
@vueuse/core, axios, d3, marked, monaco-editor, pinia, socket.io-client, vue
@vueuse/core, axios, marked, monaco-editor, pinia, socket.io-client, vue, vue-router
Gates applied: critical_finding, no_behavioural_pass.
320cb530c8a3full audit observations/trust-audit/mcp-server/hoangsonww__ai-agents-orchestrator.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 320cb530c8a3 | BLOCK | D | 60 | first audit |
Questions
What is the AI Agents Orchestrator MCP server?
Intelligent orchestration system that coordinates multiple AI coding assistants (Claude, Codex, Gemini CLI, Copilot CLI) to collaborate on complex software development tasks via REPL or a Vue/Nuxt UI dashboard. Also includes an Agentic Team runtime with role-based multi-agent open communication & le
What tools does AI Agents Orchestrator expose?
12 in total: 12 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is AI Agents Orchestrator safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does AI Agents Orchestrator need?
It reads FLASK_SECRET_KEY and FLASK_SECRET_KEY_AGENTIC from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (320cb530c8a3), read on 2026-10-07. The repository is watched and re-audited when it changes.