Atlas / MCP servers / jnmetacode / Agency Orchestrator

Agency OrchestratorBLOCK

mcp/jnmetacode/agency-orchestrator

🚀 One sentence → your one-person company of AI experts → complete deliverable in minutes. 276 CN + 184 EN + 5 more languages (ko/ru/pt-BR/id/ar) · zero-code YAML · auto-verified acceptance · Web Studio / Desktop / Docker · 15 LLM providers (11 key-free). 一句话组建你的「一人公司」AI 专家团队,几分钟交付完整方案;验收自动核验,网页 / 桌面

Verdict
BLOCK
Grade
F
Trust score
38 /100
Exposed tools
16 15r · 1w · 0d
Transport
stdio
License
Apache-2.0
Stars
2,288
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

中文 | English

一句话,让多个 AI 角色自动协作,几分钟出完整方案。 也是你的「一人公司」:你当老板,AI 当团队——自动组队、重大决策请你签字、按验收标准交付。

[](https://github.com/jnMetaCode/agency-orchestrator/actions) [](https://www.npmjs.com/package/agency-orchestrator) [](./LICENSE) [](./CONTRIBUTING.md)

一句话出结果 · 276 个专业 AI 角色 · YAML 零代码 · 20+ 家 API(推荐 DeepSeek)· 10 种免 key 方式

📖 完整上手教程(从安装到实战,10 分钟上手) · 🎓 官方配套课程:AI 专家团队实战(35 节免费,桌面端零代码:单兵点名→自动组队→一人公司全流程,含官方评测的诚实用法边界)· 另有 AI 内容流水线(31 节免费——用 AO 产线真实生产两门课的全过程留档:蒸馏、换角色审核、机械闸门、断点续跑,含七类翻车现场)+ 从零学会 AI 编程(182 节)+ 从零构建 AI 智能体(40 节)(站上共 13 门课、648 节,全部 ¥0——另有 AI 绘画 / 写小说 / 漫剧 / 量化 / DeepSeek / 深度专注 等)
觉得有用?请点个 Star — 帮助更多人发现这个项目。

网页 Studio:打一句话,AI 自动从 200+ 专家里组队并运行

网页 Studio(图形界面)

不想敲命令行?本地跑一条 ao web,浏览器里勾选专家、运行工作流、查看产物、实时介入——全程图形界面,全中英双语。

先跑起来

  • 零配置首跑 —— 本机已登录 Claude Code / Gemini CLI 等?AO 自动探测并直接用,连 API key 都不用配
  • AI 自动组队 —— 不知道选哪些专家?角色页一句话、不选角色,AI 从全部专家里挑人组队并运行
  • 「一人公司」系列模板 —— 做产品 / 做内容 / 做投研 / 方案到代码 + 全员大会;关键步骤带验收标准(acceptance),投研含老板签字闸门,交付的是可验收的工作成果,不承诺奇迹

改成你要的样子

  • 可视化画布 —— 拖拽节点 / 连线(自动防环)/ 改任务与角色 / 保存;运行时节点按状态实时点亮
  • 我的角色 + 提示生成 —— 「提示生成」页产出的 system prompt 一
Read from source at commit f5845c839194OBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add agency-orchestrator-website --env AGNES_API_KEY=${AGNES_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ANTHROPIC_AUTH_TOKEN=${ANTHROPIC_AUTH_TOKEN} --env AO_API_KEY=${AO_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "agency-orchestrator-website": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AGNES_API_KEY": "${AGNES_API_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "ANTHROPIC_AUTH_TOKEN": "${ANTHROPIC_AUTH_TOKEN}",
        "AO_API_KEY": "${AO_API_KEY}"
      }
    }
  }
}
03

Exposed tools (16)

15 read · 1 write · 0 destructive.

ToolRiskDescription
SREread站点可靠性
Simplereadtest
Testreadtest
UXread体验设计
coderead待审查代码
compose_workflowreadGenerate a workflow YAML from a natural language description using AI
list_rolesreadList available AI roles from the agents directory
list_workflowsreadList available workflow templates from the workflows/ directory
plan_workflowreadShow the DAG execution plan for a workflow
run_workflowwriteExecute a YAML workflow with the DAG engine
validate_workflowreadValidate a workflow YAML without executing
代码审查read多角色代码审查流水线
开发read开发者
测试专家read一句话描述
自定义名read自定义说明
进销存方案read测试
04

Trust audit

BLOCKgrade F · trust 38/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (15 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/import-creative-prompts.mjs:68
const c = yaml.load(readFileSync(join(jimmylvRoot, 'cases', d, 'case.yml'), 'utf-8'));
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/canvas/graph.ts:42
const doc = (yaml.load(yamlText) || {}) as RawDoc;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/canvas/graph.ts:75
const doc = (yaml.load(baseYamlText) || {}) as RawDoc;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/cli/compose.ts:87
try { doc = yaml.load(yamlText); } catch { return { yaml: yamlText }; }
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/cli/ledger.ts:136
const doc = yaml.load(readFileSync(file, 'utf-8')) as { steps?: Array<{ id?: string; type?: string }> };
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
website/public/prompts/id/specialized/automation-governance-architect.md:128
- rate limit dan mode kegagalan
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
agency-agents/specialized/automation-governance-architect.md:80
`[ENV]-[SYSTEM]-[PROCESS]-[ACTION]-v[MAJOR.MINOR]`
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
website/public/prompts/ar/specialized/automation-governance-architect.md:72
`[ENV]-[SYSTEM]-[PROCESS]-[ACTION]-v[MAJOR.MINOR]`
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
website/public/prompts/en/specialized/automation-governance-architect.md:72
`[ENV]-[SYSTEM]-[PROCESS]-[ACTION]-v[MAJOR.MINOR]`
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
website/public/prompts/id/specialized/automation-governance-architect.md:72
`[ENV]-[SYSTEM]-[PROCESS]-[ACTION]-v[MAJOR.MINOR]`
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
website/public/prompts/ko/specialized/automation-governance-architect.md:72
`[ENV]-[SYSTEM]-[PROCESS]-[ACTION]-v[MAJOR.MINOR]`
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
website/public/prompts/ar/engineering/engineering-wechat-mini-program-developer.md:330
- **التصميم أوفلاين أولاً**: استراتيجيات التخزين المحلي للتعامل مع ظروف الشبكة المتقطعة
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:23
CMD node -e "fetch('http://127.0.0.1:8088/api/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/main.cjs:25
const base = () => `http://127.0.0.1:${port}/`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/utils/proxy-setting.ts:34
error: '暂不支持 SOCKS 代理。Clash / V2RayN / sing-box 的「混合端口」同时就是 HTTP 代理——填 http://127.0.0.1:<混合端口> 即可(Clash 默认 7890)',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/utils/proxy-setting.ts:39
catch { return { ok: false, error: `代理地址无法解析:${s.slice(0, 80)}(示例:http://127.0.0.1:7890)` }; }
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/utils/proxy-setting.ts:43
if (!u.hostname) return { ok: false, error: '代理地址缺少主机名(示例:http://127.0.0.1:7890)' };
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
website/public/prompts/zh/security/security-senior-secops.md:40
-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
website/public/prompts/zh/security/security-senior-secops.md:41
-----BEGIN EC PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
website/public/prompts/zh/security/security-senior-secops.md:42
-----BEGIN PGP PRIVATE KEY-----
LOWInventory / provenance · inv.hidden_file · CWE-1104
integrations/windsurf/.windsurfrules
.windsurfrules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/desktop-helpers.ts:19
const { isSafeExternalUrl, rotateLogIfLarge } = new Function(`${m![1]}; return { isSafeExternalUrl, rotateLogIfLarge };`)() as {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
test/legacy-ui.ts:76
const factory = new Function('window', '$', 'S', 'loadWorkflows', 'alert', 'fetch', `${src}; return window.saveComposed;`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/import-creative-extra.mjs:87
const fingerprint = (s) => createHash('sha1').update(s.replace(/\s+/g, ' ').trim().slice(0, 400)).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
web/server.js:2670
try { return createHash('sha1').update(readFileSync(f)).digest('hex'); } catch { return null; }

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha f5845c839194full audit observations/trust-audit/mcp-server/jnmetacode__agency-orchestrator.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-23f5845c839194BLOCKF38score 42 -> 38
2026-09-1991b9270a35b3BLOCKF42first audit
06

Questions

What is the Agency Orchestrator MCP server?

🚀 One sentence → your one-person company of AI experts → complete deliverable in minutes. 276 CN + 184 EN + 5 more languages (ko/ru/pt-BR/id/ar) · zero-code YAML · auto-verified acceptance · Web Studio / Desktop / Docker · 15 LLM providers (11 key-free). 一句话组建你的「一人公司」AI 专家团队,几分钟交付完整方案;验收自动核验,网页 / 桌面

What tools does Agency Orchestrator expose?

16 in total: 15 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Agency Orchestrator safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (38/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Agency Orchestrator need?

It reads AGNES_API_KEY, ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, AO_API_KEY, AO_OPENAI_TOKENS_PARAM, APPLE_APP_SPECIFIC_PASSWORD, DEEPSEEK_API_KEY, LANOX_API_KEY, METASO_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Agency Orchestrator run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as agency-orchestrator-website at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (f5845c839194), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement