Atlas / MCP servers / mario-andreschak / FLUJO

FLUJOCAUTION

mcp/mario-andreschak/flujo

Multi-Agent + Automation Harness: Graph-based Workflows, MCP, Self-Improving Agents. NextJs+React

Verdict
CAUTION
Grade
F
Trust score
45 /100
Exposed tools
185 139r · 36w · 10d
Transport
stdio · streamable-http
License
MIT
Stars
629
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Build private AI agents visually. Run them your way.

Connect your AIs and apps, build an agent, then talk to it, automate it, or call it from other software.

FLUJO is open-source and local-first. Start with the guided setup, build agents as simple step-by-step recipes or expert visual flows, inspect every run, and expose the same agents through OpenAI-compatible and MCP endpoints — while your keys and data stay under your control.

Simple + visual builders · MCP-native · Multi-model · Built-in debugger · Automation

**Visit flujo.com.co →** · **Watch the 2:28 product film →** · Install FLUJO ↓ · Explore features ↓ · **Try FLUJO online →**

[](LICENSE) [](package.json)

FLUJO is too complicated? You are missing a feature or are stuck on something? Hop into the Discord, or create an Issue on Github! We can only improve if we know what's wrong. It really helps a lot!

[](https://flujo.com.co/short/) Click the preview to see FLUJO in motion.

⚡ Quick Install (recommended)

The installer sets up everything FLUJO needs (Git, Node.js, Python, uv, ripgrep), clones FLUJO, builds it, and creates a global flujo command. This is the recommended way to run FLUJO — MCP servers get all their runtimes too.

Windows installer (recommended) — click below to download the latest flujo-setup.exe:

[![Download Setup.exe

Read from source at commit 1ac9def42990OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add flujo-ai --env CODEX_API_KEY=${CODEX_API_KEY} --env FAKE_SECRET=${FAKE_SECRET} --env FLUJO_SNAPSHOT_CONTROL_TOKEN=${FLUJO_SNAPSHOT_CONTROL_TOKEN} --env FLUJO_WORKER_SNAPSHOT_KEY=${FLUJO_WORKER_SNAPSHOT_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "flujo-ai": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CODEX_API_KEY": "${CODEX_API_KEY}",
        "FAKE_SECRET": "${FAKE_SECRET}",
        "FLUJO_SNAPSHOT_CONTROL_TOKEN": "${FLUJO_SNAPSHOT_CONTROL_TOKEN}",
        "FLUJO_WORKER_SNAPSHOT_KEY": "${FLUJO_WORKER_SNAPSHOT_KEY}"
      }
    }
  }
}
03

Exposed tools (185)

139 read · 36 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
API_TOKENreadAPI token
AdareadA product-facing description.
Alphareadhello
Existingreadalready here
Flow_GeneratorreadExperimental editable multi-stage Flow Generator: architecture, capability discovery, validation, repair, and unsaved drafting.
JimreadResearch carefully.
ModelsreadCRUD for model configurations and provider model discovery. API keys are encrypted at rest and never returned to the browser in clear text.
PrimaryreadMain development behavior.
REPOSITORY_URLreadRepository URL
SummarizerreadSummarizes text
TicketsreadWorkspace-scoped messages and follow-up tasks left by agents.
WorkspacesreadInstallation-wide workspace administration. Logical workspaces are not separate user accounts.
WriterreadDrafts polished copy
add_stepwriteAdd one visible AI task to a draft agent. FLUJO returns real connected-tool and saved-agent suggestions for this step; decide them before adding another step.
alpha_readreadRead another record
apply_tools_to_flow_stepwriteApply an EXPLICITLY APPROVED list of connected MCP tools to one Process step of an UNSAVED Flow draft. Idempotent and does not save.
browser_backreadNavigate an existing browser session backward in its page history.
browser_capture_element_metricsreadQuery per-selector layout metrics (bounding box, computed style, overflow/clipping flags, viewport visibility) without taking a screenshot.
browser_capture_pagereadCapture a page as PNG. source may be a remote URL, localhost URL, local path, file:// URL, or inline HTML; omit source to capture the active session. Resolution presets such as 720p, 1080p, and 4k are accepted and safely adjusted when necessary.
browser_capture_regionreadCapture a rectangular page region as PNG. source accepts remote URLs, localhost, or local paths; omit it to use the active session. Missing or out-of-range coordinates are safely normalized.
browser_clickreadClick either the first element matching a selector or viewport coordinates in an existing browser session.
browser_closereadClose the session tab. Sandbox state is discarded; trusted-mode cookies and profile state remain in the dedicated persistent profile.
browser_diagnosticsreadReport configured/actual browser mode, channel, headless state, persistence, locale, service-worker policy, and the active page fingerprint without opening a destination site.
browser_extensionsreadList extensions installed in FLUJO\
browser_forwardreadNavigate an existing browser session forward in its page history.
browser_list_sessionsreadList this caller owner scope\
browser_navigatereadNavigate the active browser to a remote URL, bare hostname, localhost address, or local file path. Only executable/non-browser URL schemes are rejected.
browser_openreadOpen a new browser session, or open/reuse the exact sessionId supplied. url may be remote, localhost, a bare hostname, or a local file path.
browser_pressreadPress a keyboard key or shortcut in the currently focused page element.
browser_record_startwriteStart a sturdy browser recording and immediately return a sessionId. Optionally load source first and auto-stop after durationMs. Unsupported resolutions fall back automatically and are reported in warnings/effectiveResolution.
browser_record_statusreadReport recording, finalizing, or recently completed state. Completed status includes the artifact and embeds the video as MCP media when small enough.
browser_record_stopwriteStop and finalize a recording, or retrieve one that just auto-stopped. Returns usable artifact paths, recovery warnings, and the video itself as MCP media when small enough.
browser_release_ownerreadClose every browser session owned by this authoritative caller scope. Idempotent.
browser_reloadreadReload the current page in an existing browser session.
browser_screenshotreadCapture an immutable PNG screenshot with artifact ID, SHA-256, geometry, and an optional safe no-overwrite outputPath.
browser_scrollreadScroll the current page by viewport-relative pixel deltas.
browser_snapshotreadRead the current page title, URL, and bounded visible body text without exposing cookies or storage.
browser_typereadFill an element matching a selector, or type into the currently focused page element; optionally press Enter afterward.
call_mcp_toolreadCall a tool on any configured MCP server by server name + tool name. This lets you use servers that are not bound to the current flow. Check the tool\
check_flow_plausibilityreadAnalyze a Flow and its subflows; returns issues, deterministic repair patches, and unsaved repaired previews. Read-only; consent is required to apply them.
correctreadPropose a correction to an existing memory. A model-issued correction stays candidate until reviewed.
create_agentwriteCreate the root draft agent or a new nested helper agent. A helper must name its parent agent and the parent process step that will call it.
create_flowwriteauthoring
create_issuewriteCreate issue
create_planned_executionwriteCreate a new planned execution: bind a flow to a trigger so it runs headlessly. Provide
create_recordwriteCreate one record.
create_ticket_for_humanwriteCreate a dashboard ticket for the human operator. Use a concise plain-text message and optional comma-separated labels. Pass conversation_id or flow_id when known so the human can navigate back to the related work.
decide_suggestionsreadAccept or reject the exact tool and saved-agent suggestions returned by add_step. Omitted suggestions are treated as rejected.
delete_flowdestructivePERMANENTLY delete a FLUJO flow (by name or id). This cannot be undone — the flow\
delete_issuedestructiveDelete an issue.
delete_planned_executiondestructivePermanently delete a planned execution (by id or name, see list_planned_executions), along with its run history. This cannot be undone.
delete_recorddestructiveDelete one record.
demoreadDemo
demo-skillreadDemonstrate Skills
demo_readread
demo_searchreadsearch
discover_capabilitiesreadSearch FLUJO flows and tools exposed by configured MCP servers in one call. Returns exact invocation recipes and downstream input schemas, so you do not need to guess names or arguments. Use this before execute_flow or call_mcp_tool when you know the goal but not the capability.
docs.group.conversations.namereaddocs.group.conversations.description
docs.group.env.namereaddocs.group.env.description
docs.group.flow.namereaddocs.group.flow.description
docs.group.mcp.namereaddocs.group.mcp.description
docs.group.mcpFlows.namereaddocs.group.mcpFlows.description
docs.group.model.namereaddocs.group.model.description
docs.group.oauth.namereaddocs.group.oauth.description
docs.group.openai.namereaddocs.group.openai.description
docs.group.planned.namereaddocs.group.planned.description
docs.group.proxy.namereaddocs.group.proxy.description
docs.group.storage.namereaddocs.group.storage.description
docs.group.system.namereaddocs.group.system.description
draft_flowreadCompile and validate a flow WITHOUT saving and return the complete draft bundle for review or opening in the Flow Builder.
draft_generated_flowreadHarden a complete advanced FlowSpec through the production Flow Generator pipeline and return the UNSAVED draft plus the hardened spec.
echoread
execute_flowwriteRun another FLUJO flow (by name or id) with the given input and return its final output. The run is ephemeral (no chat conversation is created). Use list_flows or discover_capabilities to find a flow. Nested runs are limited in depth — a flow cannot recurse through itself indefinitely.
explain_flowreadExplain one compiled FLUJO flow in natural language: its ordered steps, control connections and conditions, model/MCP capabilities, Subflow child-job queues, signal emissions, and how planned executions connect it to trigger Waves. Read-only and deterministic.
exportreadExport data.
freadd
fileread
find_best_mcp_serverreadResearch and rank MCP servers for a natural-language capability request without installing anything.
find_mcp_serverreadSearch the public MCP server registry. The registry matches the query against server NAMES only (substring), so use short single terms (
finish_agentreadMark one agent ready after its steps, suggestion decisions, routes, and child agents are complete.
finish_sessionreadCompile and validate the entire visible draft hierarchy. If errors are returned, repair them with update_step/set_routes and call finish_session again.
forgetdestructiveForget one Persona memory and remove it from core memory. Enable this authored tool only where policy/approval permits destructive memory changes.
get_flow_authoring_guidereadFetch the flow-authoring contract only when needed. The simple guide is compact; the advanced guide contains the complete FlowSpec reference.
get_weatherreadGet weather
handoff_to_finishreadFinish
handoff_to_finish_nodereadFinish the flow
identityreadReturns the fixture process identity.
install_best_mcp_serverwriteAI-assisted install from a natural-language capability request; preferred when no specific server name is known. DOWNLOADS AND MAY RUN third-party code.
install_mcp_serverwriteInstall an exact MCP registry result after the user enabled connector installation for this visual generation session.
journey_receiptreadReturn a deterministic receipt from the disposable local journey fixture.
killdestructiveKill a background session (and its whole process tree). Returns { sessionId, killed }.
kv_getreadRead a value from FLUJO\
kv_setwriteWrite a value to FLUJO\
leaky_flowreadreads a variable nobody captures
legacy_toolreadHas no behavior annotations.
list_conversationsreadList lightweight chat-conversation summaries with status, flow, activity, planned-execution and hierarchy filters. Defaults to the 50 most recently active conversations. Use read_conversation to get a transcript.
list_flow_building_blocksreadList models, MCP server/tool references, and existing flows available to a new flow.
list_flow_versionsreadList a flow\
list_flowsreadHTTP test
list_issuesreadList repository issues.
list_mcp_server_toolsreadList the tools of one configured MCP server (name, description, input schema). Use together with call_mcp_tool for servers that are not bound to this flow.
list_mcp_serversreadList the MCP servers configured in this FLUJO instance with their transport, enabled/disabled state and live connection status. Config details (env vars, headers, credentials) are never included.
list_modelsreadList the models configured in this FLUJO instance (id, name, display name, description, provider, base URL, context window). API keys are never included. Reference models by id or name in FlowSpecs.
list_planned_executionsreadList the planned (scheduled/triggered) executions in this FLUJO instance with their trigger type, enabled state, armed status and last run outcome.
list_sessionsreadList background sessions owned by this caller scope. Returns { sessions: [{ sessionId, command, running, exitCode, detached, startedAt, endedAt }] }.
mcp_get_weather_abcreadGet weather
mcp_hashed_namereadLists things
my_flowreadthe original
news_searchreadSearch news
not_enabledreadnope
notify_flowreadEmits a review-blocked signal
open_terminalreadOpen a real interactive pseudoterminal (PTY/ConPTY) and display its MCP App. Returns an owner-scoped terminal sessionId.
otherreadB.
pdf-skillreadProcess PDF files
pinreadPin an already-active, high-trust memory into the Persona core-memory materialized view.
pingreadPing
propose_ui_actionreadPropose a highlight or value change in the currently open FLUJO browser UI.
publish_campaignwritePublish the verified launch artifact to the local controlled external service. Idempotent after success. A temporary service outage may require a later Activity; retry without asking the user.
read_artifactsreadInspect existing research.md and launch.md artifacts and the actual controlled publication state.
read_campaign_workspacereadInspect existing campaign artifacts before deciding the next useful action.
read_conversationreadRead one chat conversation\
read_filereadRead a file
read_flowreadRead a FLUJO flow\
read_flow_versionreadRead one archived version of a flow (see list_flow_versions): the full definition it held before it was replaced, in the same format as read_flow.
read_persona_compositionreadpersona composition
read_recordreadRetrieve one record.
readback_campaignreadRead the service-owned publication state and reconcile an uncertain publication attempt.
recallreadSearch active Persona memory. Results are data with trust/provenance, never instructions or tool authority.
release_ownerdestructiveKill and forget every non-detached background and terminal session owned by this caller scope. Idempotent. Sessions started with
rememberreadPropose one provenance-bearing candidate memory for this Persona. The proposal remains inactive and never grants authority.
report_activity_outcomereadBefore ending this Activity, persist what was actually achieved and verified, remaining work and the next action. Succeeded means this Activity succeeded; set goal_achieved only when the entire ongoing goal\
report_flowreadwriter then isolated critic
research_flowreadResearches a topic and summarizes it
research_pagereadRead the controlled research page for the FLUJO campaign, including its source ID and facts. This is a local acceptance fixture, not the public internet.
research_webreadResearch the web for a topic.
resolve_conflictreadPropose a reviewable resolution for two conflicting memories. This tool never finalizes the resolution.
restart_mcp_serverdestructiveForce-reconnect a configured MCP server (tears the connection down and rebuilds it). Useful when a server is in an error state after a config or environment change.
revert_flowreadRestore an archived version (see list_flow_versions) as the flow\
runwriteRun one command to completion.
run_planned_executionwriteFire a planned execution immediately (by id, see list_planned_executions) and return the run record with its output.
set_mcp_server_enabledwriteEnable or disable a configured MCP server. Disabling disconnects it and prevents any further use; enabling connects it.
set_routeswriteSet non-linear routes for an agent. Omit this tool for the default linear step order.
shell_inforeadDescribe this machine before running anything: platform, the effective
singreadsings
sleepreadWait for a fixed duration independent of background-session state. Use this instead of wait when the full delay must elapse even if a command finishes early.
startwriteStart an independent background command and return its sessionId plus the effective shell and absolute shellPath. Output is stdout and stderr merged, decoded as UTF-8. Multiple sessions may run in parallel; use status/wait, write_stdin, or kill.
statusreadReturn the current state of a background session: { sessionId, running, exitCode, output, truncated }.
subflow_listreadDiscover your parent and child agents, their conversation IDs, task IDs and current status. Use these IDs with subflow_send_message. Available automatically inside subflows and to their orchestrators.
subflow_send_messagewriteSend a progress update, question, or steering instruction to your parent (target:
subflow_task_cancelreadCancel a working detached subflow task.
subflow_task_getreadGet the status and terminal result of a detached subflow task.
subflow_waitreadWait for an incoming agent message or for a selected child to finish (up to 60 seconds). The tool returns before the message is folded into your context. Omit target to watch all children and incoming messages; use
suggest_improvementreadAfter completing work, propose one reusable instruction-only Behavior improvement when concrete Activity evidence shows it would help future work. The change is validated, shown in Improvements, and follows the user-selected review rule.
suggest_tools_for_flow_stepreadSuggest tools for ONE Process step from already-connected MCP servers using a selected model. Read-only: it never changes or saves the flow.
terminalwriteExecute a general command in the isolated campaign workspace. Shell: ${process.platform ===
terminal_closereadClose an owner-scoped interactive terminal PTY.
terminal_listreadList interactive terminal PTY sessions owned by this MCP App scope.
terminal_readreadRead incremental ANSI/VT output from an owner-scoped interactive terminal session.
terminal_resizereadResize an owner-scoped interactive terminal PTY.
terminal_writewriteWrite raw keyboard or pasted input to an owner-scoped interactive terminal PTY.
testread
test__deletedestructiveDeletes something
test__lookupreadLooks something up
tool_areaddoes a
toolbar_flowreadToolbar regression fixture
unpindestructiveRemove a memory from the Persona core-memory materialized view without changing its record.
update_flowwriteREPLACE an existing FLUJO flow\
update_persona_compositionwriteAtomically update the Persona name, Core Flow, Behaviors, or core Memories after validating them in the active workspace. Apps are changed through Persona App grants. Requires the expected_updated_at concurrency token.
update_planned_executionwriteModify an existing planned execution (by id or name, see list_planned_executions). Patch any of:
update_stepwriteRevise a visible step after validation feedback. Supply only fields that should change.
validate_flow_specreadCompile and validate a guided flow without saving. Returns a compact summary and issues. Use draft_flow when the caller needs the complete unsaved draft.
waitreadWait until a background session completes or the maximum timeout elapses, sending new output as live progress when supported.
web_searchreadSearch the web
work_item_completereadComplete one durable Persona WorkItem after all dependencies are completed.
work_item_createwriteCreate a durable task. During ongoing-goal work it automatically belongs to that goal and runs when ready; outside an ongoing goal it is saved for assignment. List existing tasks first to avoid duplicates. Run todos remain scratch-scoped unless promoted separately.
work_item_listreadRead this Persona\
work_item_promote_todowriteExplicitly promote one pending/in-progress run todo into a durable Persona WorkItem. The scratch todo is not changed.
work_item_updatewriteUpdate a durable Persona WorkItem, including status, priority, dependencies, deadline, and next action.
writewriteWrite a record
write_artifactwriteWrite research.md or launch.md. Include the exact source ID, audience and benefit from research_page. At most one artifact should be authored per Activity; report progress and continue in the next Activity.
write_campaign_artifactwriteWrite a useful sourced research.md, launch.md or backlog.md campaign artifact. Content is independently hashed and checked against the service facts.
write_filewriteWrite a file
write_resourcewriteWrite an artifact
write_stdinwriteWrite UTF-8 text to a running background session\
zeta_readreadRead a record
04

Trust audit

CAUTIONgrade F · trust 45/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
src/backend/services/mcp/lifecycleCoordinator.ts
lifecycleCoordinator.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/backend/services/packages/deriveSecrets.ts
deriveSecrets.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/shared/types/package/secretProposal.ts
secretProposal.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
__tests__/backend/services/waves/automationMapResolver.test.ts:324
token: 'webhook-secret-value',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
__tests__/encryption/apiKeyRoundTrip.test.ts:57
const secret = 'eyJhbGciOiJIUzI1NiJ9.registry-access-token.signature';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
__tests__/encryption/apiKeyRoundTrip.test.ts:70
const secret = 'sk-test-bare-ciphertext-path';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
__tests__/enduringAgents/memoryRecallModes.test.ts:85
ApiKey: 'test-key-never-resolved',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
__tests__/enduringAgents/memorySemanticRecallPerf.test.ts:157
ApiKey: 'benchmark-never-resolved',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_flow, delete_issue, delete_planned_execution, delete_record, forget, kill, release_owner, restart_mcp_server, test__delete, unpin
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
__tests__/backend/services/waves/waveResolver.test.ts:235
exec(`e${index + 1}`, `f${index + 1}`, onExecution(`e${index}`)),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
__tests__/mcp/browserGateway.test.ts:153
expect(() => new Function(source)).not.toThrow();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
__tests__/mcp/browserServer.test.ts:140
expect(() => new Function(appScript!)).not.toThrow();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
__tests__/mcp/browserServer.test.ts:161
expect(() => new Function(viewScript!)).not.toThrow();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
__tests__/enduringAgents/fixtures/personaProcess.cjs:35
.createHash('sha1')
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
__tests__/mcp/runtimeBroker.test.ts:208
const accept = createHash('sha1')
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/backend/services/packages/installPackage.ts:416
return createHash('sha1').update(value).digest('hex').slice(0, 8);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/backend/services/snapshot/ShadowRepoService.ts:100
const hash = crypto.createHash('sha1').update(abs).digest('hex').slice(0, 16);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/backend/services/subflowTaskRestart.test.ts:7
} from '../../enduringAgents/personaProcessBoundaryHarness';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/backend/services/subflowTaskStore.test.ts:99
expect(parseSubflowTaskUri(`${SUBFLOW_TASK_SCHEME}../../evil`)).toBeNull();
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/backend/services/subflowTaskStore.test.ts:101
expect(() => buildSubflowTaskUri('../../evil')).toThrow(/Unsafe collection item id/);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/backend/services/subflowTaskStore.test.ts:105
await expect(getTask('../../etc/passwd')).resolves.toBeNull();
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
__tests__/backend/services/subflowTaskStore.test.ts:106
await expect(patchTask('../../etc/passwd', { status: 'failed' })).resolves.toBeNull();
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
__tests__/security/localRequestGuard.test.ts:549
describe('GET /api/env origin guard (secret exfiltration)', () => {
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
__tests__/model/adapterTranslate.test.ts:391
{ type: 'image_url', image_url: { url: 'http://169.254.169.254/latest/meta-data' } },
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/publish-image.yml:93
node scripts/smoke-mcp-artifacts.mjs --proxy-only http://127.0.0.1:4200

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha 1ac9def42990full audit observations/trust-audit/mcp-server/mario-andreschak__flujo.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-021ac9def42990CAUTIONF45first audit
06

Questions

What is the FLUJO MCP server?

Multi-Agent + Automation Harness: Graph-based Workflows, MCP, Self-Improving Agents. NextJs+React

What tools does FLUJO expose?

185 in total: 139 read-only, 36 that write, and 10 that can delete or overwrite (delete_flow, delete_issue, delete_planned_execution, delete_record, forget). Every one is listed on this page with its risk.

Is FLUJO safe to connect to an agent?

With care. The audit graded it F (45/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does FLUJO need?

It reads CODEX_API_KEY, FAKE_SECRET, FLUJO_SNAPSHOT_CONTROL_TOKEN, FLUJO_WORKER_SNAPSHOT_KEY, GITHUB_TOKEN, OPENAI_API_KEY and PERSONA_GOAL_ENDURANCE_FIXTURE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does FLUJO run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as flujo-ai at 3.46.1.

How current is this page?

The grade is for one exact copy of the source (1ac9def42990), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement