FLUJOCAUTION
Multi-Agent + Automation Harness: Graph-based Workflows, MCP, Self-Improving Agents. NextJs+React
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Build private AI agents visually. Run them your way.
Connect your AIs and apps, build an agent, then talk to it, automate it, or call it from other software.
FLUJO is open-source and local-first. Start with the guided setup, build agents as simple step-by-step recipes or expert visual flows, inspect every run, and expose the same agents through OpenAI-compatible and MCP endpoints — while your keys and data stay under your control.
Simple + visual builders · MCP-native · Multi-model · Built-in debugger · Automation
**Visit flujo.com.co →** · **Watch the 2:28 product film →** · Install FLUJO ↓ · Explore features ↓ · **Try FLUJO online →**
[](LICENSE) [](package.json)
FLUJO is too complicated? You are missing a feature or are stuck on something?Hop into the Discord, or create an Issue on Github! We can only improve if we know what's wrong.It really helps a lot!
[](https://flujo.com.co/short/) Click the preview to see FLUJO in motion.
⚡ Quick Install (recommended)
The installer sets up everything FLUJO needs (Git, Node.js, Python, uv, ripgrep), clones FLUJO, builds it, and creates a global flujo command. This is the recommended way to run FLUJO — MCP servers get all their runtimes too.
Windows installer (recommended) — click below to download the latest flujo-setup.exe:
[![Download Setup.exe
1ac9def42990OBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add flujo-ai --env CODEX_API_KEY=${CODEX_API_KEY} --env FAKE_SECRET=${FAKE_SECRET} --env FLUJO_SNAPSHOT_CONTROL_TOKEN=${FLUJO_SNAPSHOT_CONTROL_TOKEN} --env FLUJO_WORKER_SNAPSHOT_KEY=${FLUJO_WORKER_SNAPSHOT_KEY} -- npx -y [email protected]{
"mcpServers": {
"flujo-ai": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CODEX_API_KEY": "${CODEX_API_KEY}",
"FAKE_SECRET": "${FAKE_SECRET}",
"FLUJO_SNAPSHOT_CONTROL_TOKEN": "${FLUJO_SNAPSHOT_CONTROL_TOKEN}",
"FLUJO_WORKER_SNAPSHOT_KEY": "${FLUJO_WORKER_SNAPSHOT_KEY}"
}
}
}
}Exposed tools (185)
139 read · 36 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
API_TOKEN | read | API token |
Ada | read | A product-facing description. |
Alpha | read | hello |
Existing | read | already here |
Flow_Generator | read | Experimental editable multi-stage Flow Generator: architecture, capability discovery, validation, repair, and unsaved drafting. |
Jim | read | Research carefully. |
Models | read | CRUD for model configurations and provider model discovery. API keys are encrypted at rest and never returned to the browser in clear text. |
Primary | read | Main development behavior. |
REPOSITORY_URL | read | Repository URL |
Summarizer | read | Summarizes text |
Tickets | read | Workspace-scoped messages and follow-up tasks left by agents. |
Workspaces | read | Installation-wide workspace administration. Logical workspaces are not separate user accounts. |
Writer | read | Drafts polished copy |
add_step | write | Add one visible AI task to a draft agent. FLUJO returns real connected-tool and saved-agent suggestions for this step; decide them before adding another step. |
alpha_read | read | Read another record |
apply_tools_to_flow_step | write | Apply an EXPLICITLY APPROVED list of connected MCP tools to one Process step of an UNSAVED Flow draft. Idempotent and does not save. |
browser_back | read | Navigate an existing browser session backward in its page history. |
browser_capture_element_metrics | read | Query per-selector layout metrics (bounding box, computed style, overflow/clipping flags, viewport visibility) without taking a screenshot. |
browser_capture_page | read | Capture a page as PNG. source may be a remote URL, localhost URL, local path, file:// URL, or inline HTML; omit source to capture the active session. Resolution presets such as 720p, 1080p, and 4k are accepted and safely adjusted when necessary. |
browser_capture_region | read | Capture a rectangular page region as PNG. source accepts remote URLs, localhost, or local paths; omit it to use the active session. Missing or out-of-range coordinates are safely normalized. |
browser_click | read | Click either the first element matching a selector or viewport coordinates in an existing browser session. |
browser_close | read | Close the session tab. Sandbox state is discarded; trusted-mode cookies and profile state remain in the dedicated persistent profile. |
browser_diagnostics | read | Report configured/actual browser mode, channel, headless state, persistence, locale, service-worker policy, and the active page fingerprint without opening a destination site. |
browser_extensions | read | List extensions installed in FLUJO\ |
browser_forward | read | Navigate an existing browser session forward in its page history. |
browser_list_sessions | read | List this caller owner scope\ |
browser_navigate | read | Navigate the active browser to a remote URL, bare hostname, localhost address, or local file path. Only executable/non-browser URL schemes are rejected. |
browser_open | read | Open a new browser session, or open/reuse the exact sessionId supplied. url may be remote, localhost, a bare hostname, or a local file path. |
browser_press | read | Press a keyboard key or shortcut in the currently focused page element. |
browser_record_start | write | Start a sturdy browser recording and immediately return a sessionId. Optionally load source first and auto-stop after durationMs. Unsupported resolutions fall back automatically and are reported in warnings/effectiveResolution. |
browser_record_status | read | Report recording, finalizing, or recently completed state. Completed status includes the artifact and embeds the video as MCP media when small enough. |
browser_record_stop | write | Stop and finalize a recording, or retrieve one that just auto-stopped. Returns usable artifact paths, recovery warnings, and the video itself as MCP media when small enough. |
browser_release_owner | read | Close every browser session owned by this authoritative caller scope. Idempotent. |
browser_reload | read | Reload the current page in an existing browser session. |
browser_screenshot | read | Capture an immutable PNG screenshot with artifact ID, SHA-256, geometry, and an optional safe no-overwrite outputPath. |
browser_scroll | read | Scroll the current page by viewport-relative pixel deltas. |
browser_snapshot | read | Read the current page title, URL, and bounded visible body text without exposing cookies or storage. |
browser_type | read | Fill an element matching a selector, or type into the currently focused page element; optionally press Enter afterward. |
call_mcp_tool | read | Call a tool on any configured MCP server by server name + tool name. This lets you use servers that are not bound to the current flow. Check the tool\ |
check_flow_plausibility | read | Analyze a Flow and its subflows; returns issues, deterministic repair patches, and unsaved repaired previews. Read-only; consent is required to apply them. |
correct | read | Propose a correction to an existing memory. A model-issued correction stays candidate until reviewed. |
create_agent | write | Create the root draft agent or a new nested helper agent. A helper must name its parent agent and the parent process step that will call it. |
create_flow | write | authoring |
create_issue | write | Create issue |
create_planned_execution | write | Create a new planned execution: bind a flow to a trigger so it runs headlessly. Provide |
create_record | write | Create one record. |
create_ticket_for_human | write | Create a dashboard ticket for the human operator. Use a concise plain-text message and optional comma-separated labels. Pass conversation_id or flow_id when known so the human can navigate back to the related work. |
decide_suggestions | read | Accept or reject the exact tool and saved-agent suggestions returned by add_step. Omitted suggestions are treated as rejected. |
delete_flow | destructive | PERMANENTLY delete a FLUJO flow (by name or id). This cannot be undone — the flow\ |
delete_issue | destructive | Delete an issue. |
delete_planned_execution | destructive | Permanently delete a planned execution (by id or name, see list_planned_executions), along with its run history. This cannot be undone. |
delete_record | destructive | Delete one record. |
demo | read | Demo |
demo-skill | read | Demonstrate Skills |
demo_read | read | |
demo_search | read | search |
discover_capabilities | read | Search FLUJO flows and tools exposed by configured MCP servers in one call. Returns exact invocation recipes and downstream input schemas, so you do not need to guess names or arguments. Use this before execute_flow or call_mcp_tool when you know the goal but not the capability. |
docs.group.conversations.name | read | docs.group.conversations.description |
docs.group.env.name | read | docs.group.env.description |
docs.group.flow.name | read | docs.group.flow.description |
docs.group.mcp.name | read | docs.group.mcp.description |
docs.group.mcpFlows.name | read | docs.group.mcpFlows.description |
docs.group.model.name | read | docs.group.model.description |
docs.group.oauth.name | read | docs.group.oauth.description |
docs.group.openai.name | read | docs.group.openai.description |
docs.group.planned.name | read | docs.group.planned.description |
docs.group.proxy.name | read | docs.group.proxy.description |
docs.group.storage.name | read | docs.group.storage.description |
docs.group.system.name | read | docs.group.system.description |
draft_flow | read | Compile and validate a flow WITHOUT saving and return the complete draft bundle for review or opening in the Flow Builder. |
draft_generated_flow | read | Harden a complete advanced FlowSpec through the production Flow Generator pipeline and return the UNSAVED draft plus the hardened spec. |
echo | read | |
execute_flow | write | Run another FLUJO flow (by name or id) with the given input and return its final output. The run is ephemeral (no chat conversation is created). Use list_flows or discover_capabilities to find a flow. Nested runs are limited in depth — a flow cannot recurse through itself indefinitely. |
explain_flow | read | Explain one compiled FLUJO flow in natural language: its ordered steps, control connections and conditions, model/MCP capabilities, Subflow child-job queues, signal emissions, and how planned executions connect it to trigger Waves. Read-only and deterministic. |
export | read | Export data. |
f | read | d |
file | read | |
find_best_mcp_server | read | Research and rank MCP servers for a natural-language capability request without installing anything. |
find_mcp_server | read | Search the public MCP server registry. The registry matches the query against server NAMES only (substring), so use short single terms ( |
finish_agent | read | Mark one agent ready after its steps, suggestion decisions, routes, and child agents are complete. |
finish_session | read | Compile and validate the entire visible draft hierarchy. If errors are returned, repair them with update_step/set_routes and call finish_session again. |
forget | destructive | Forget one Persona memory and remove it from core memory. Enable this authored tool only where policy/approval permits destructive memory changes. |
get_flow_authoring_guide | read | Fetch the flow-authoring contract only when needed. The simple guide is compact; the advanced guide contains the complete FlowSpec reference. |
get_weather | read | Get weather |
handoff_to_finish | read | Finish |
handoff_to_finish_node | read | Finish the flow |
identity | read | Returns the fixture process identity. |
install_best_mcp_server | write | AI-assisted install from a natural-language capability request; preferred when no specific server name is known. DOWNLOADS AND MAY RUN third-party code. |
install_mcp_server | write | Install an exact MCP registry result after the user enabled connector installation for this visual generation session. |
journey_receipt | read | Return a deterministic receipt from the disposable local journey fixture. |
kill | destructive | Kill a background session (and its whole process tree). Returns { sessionId, killed }. |
kv_get | read | Read a value from FLUJO\ |
kv_set | write | Write a value to FLUJO\ |
leaky_flow | read | reads a variable nobody captures |
legacy_tool | read | Has no behavior annotations. |
list_conversations | read | List lightweight chat-conversation summaries with status, flow, activity, planned-execution and hierarchy filters. Defaults to the 50 most recently active conversations. Use read_conversation to get a transcript. |
list_flow_building_blocks | read | List models, MCP server/tool references, and existing flows available to a new flow. |
list_flow_versions | read | List a flow\ |
list_flows | read | HTTP test |
list_issues | read | List repository issues. |
list_mcp_server_tools | read | List the tools of one configured MCP server (name, description, input schema). Use together with call_mcp_tool for servers that are not bound to this flow. |
list_mcp_servers | read | List the MCP servers configured in this FLUJO instance with their transport, enabled/disabled state and live connection status. Config details (env vars, headers, credentials) are never included. |
list_models | read | List the models configured in this FLUJO instance (id, name, display name, description, provider, base URL, context window). API keys are never included. Reference models by id or name in FlowSpecs. |
list_planned_executions | read | List the planned (scheduled/triggered) executions in this FLUJO instance with their trigger type, enabled state, armed status and last run outcome. |
list_sessions | read | List background sessions owned by this caller scope. Returns { sessions: [{ sessionId, command, running, exitCode, detached, startedAt, endedAt }] }. |
mcp_get_weather_abc | read | Get weather |
mcp_hashed_name | read | Lists things |
my_flow | read | the original |
news_search | read | Search news |
not_enabled | read | nope |
notify_flow | read | Emits a review-blocked signal |
open_terminal | read | Open a real interactive pseudoterminal (PTY/ConPTY) and display its MCP App. Returns an owner-scoped terminal sessionId. |
other | read | B. |
pdf-skill | read | Process PDF files |
pin | read | Pin an already-active, high-trust memory into the Persona core-memory materialized view. |
ping | read | Ping |
propose_ui_action | read | Propose a highlight or value change in the currently open FLUJO browser UI. |
publish_campaign | write | Publish the verified launch artifact to the local controlled external service. Idempotent after success. A temporary service outage may require a later Activity; retry without asking the user. |
read_artifacts | read | Inspect existing research.md and launch.md artifacts and the actual controlled publication state. |
read_campaign_workspace | read | Inspect existing campaign artifacts before deciding the next useful action. |
read_conversation | read | Read one chat conversation\ |
read_file | read | Read a file |
read_flow | read | Read a FLUJO flow\ |
read_flow_version | read | Read one archived version of a flow (see list_flow_versions): the full definition it held before it was replaced, in the same format as read_flow. |
read_persona_composition | read | persona composition |
read_record | read | Retrieve one record. |
readback_campaign | read | Read the service-owned publication state and reconcile an uncertain publication attempt. |
recall | read | Search active Persona memory. Results are data with trust/provenance, never instructions or tool authority. |
release_owner | destructive | Kill and forget every non-detached background and terminal session owned by this caller scope. Idempotent. Sessions started with |
remember | read | Propose one provenance-bearing candidate memory for this Persona. The proposal remains inactive and never grants authority. |
report_activity_outcome | read | Before ending this Activity, persist what was actually achieved and verified, remaining work and the next action. Succeeded means this Activity succeeded; set goal_achieved only when the entire ongoing goal\ |
report_flow | read | writer then isolated critic |
research_flow | read | Researches a topic and summarizes it |
research_page | read | Read the controlled research page for the FLUJO campaign, including its source ID and facts. This is a local acceptance fixture, not the public internet. |
research_web | read | Research the web for a topic. |
resolve_conflict | read | Propose a reviewable resolution for two conflicting memories. This tool never finalizes the resolution. |
restart_mcp_server | destructive | Force-reconnect a configured MCP server (tears the connection down and rebuilds it). Useful when a server is in an error state after a config or environment change. |
revert_flow | read | Restore an archived version (see list_flow_versions) as the flow\ |
run | write | Run one command to completion. |
run_planned_execution | write | Fire a planned execution immediately (by id, see list_planned_executions) and return the run record with its output. |
set_mcp_server_enabled | write | Enable or disable a configured MCP server. Disabling disconnects it and prevents any further use; enabling connects it. |
set_routes | write | Set non-linear routes for an agent. Omit this tool for the default linear step order. |
shell_info | read | Describe this machine before running anything: platform, the effective |
sing | read | sings |
sleep | read | Wait for a fixed duration independent of background-session state. Use this instead of wait when the full delay must elapse even if a command finishes early. |
start | write | Start an independent background command and return its sessionId plus the effective shell and absolute shellPath. Output is stdout and stderr merged, decoded as UTF-8. Multiple sessions may run in parallel; use status/wait, write_stdin, or kill. |
status | read | Return the current state of a background session: { sessionId, running, exitCode, output, truncated }. |
subflow_list | read | Discover your parent and child agents, their conversation IDs, task IDs and current status. Use these IDs with subflow_send_message. Available automatically inside subflows and to their orchestrators. |
subflow_send_message | write | Send a progress update, question, or steering instruction to your parent (target: |
subflow_task_cancel | read | Cancel a working detached subflow task. |
subflow_task_get | read | Get the status and terminal result of a detached subflow task. |
subflow_wait | read | Wait for an incoming agent message or for a selected child to finish (up to 60 seconds). The tool returns before the message is folded into your context. Omit target to watch all children and incoming messages; use |
suggest_improvement | read | After completing work, propose one reusable instruction-only Behavior improvement when concrete Activity evidence shows it would help future work. The change is validated, shown in Improvements, and follows the user-selected review rule. |
suggest_tools_for_flow_step | read | Suggest tools for ONE Process step from already-connected MCP servers using a selected model. Read-only: it never changes or saves the flow. |
terminal | write | Execute a general command in the isolated campaign workspace. Shell: ${process.platform === |
terminal_close | read | Close an owner-scoped interactive terminal PTY. |
terminal_list | read | List interactive terminal PTY sessions owned by this MCP App scope. |
terminal_read | read | Read incremental ANSI/VT output from an owner-scoped interactive terminal session. |
terminal_resize | read | Resize an owner-scoped interactive terminal PTY. |
terminal_write | write | Write raw keyboard or pasted input to an owner-scoped interactive terminal PTY. |
test | read | |
test__delete | destructive | Deletes something |
test__lookup | read | Looks something up |
tool_a | read | does a |
toolbar_flow | read | Toolbar regression fixture |
unpin | destructive | Remove a memory from the Persona core-memory materialized view without changing its record. |
update_flow | write | REPLACE an existing FLUJO flow\ |
update_persona_composition | write | Atomically update the Persona name, Core Flow, Behaviors, or core Memories after validating them in the active workspace. Apps are changed through Persona App grants. Requires the expected_updated_at concurrency token. |
update_planned_execution | write | Modify an existing planned execution (by id or name, see list_planned_executions). Patch any of: |
update_step | write | Revise a visible step after validation feedback. Supply only fields that should change. |
validate_flow_spec | read | Compile and validate a guided flow without saving. Returns a compact summary and issues. Use draft_flow when the caller needs the complete unsaved draft. |
wait | read | Wait until a background session completes or the maximum timeout elapses, sending new output as live progress when supported. |
web_search | read | Search the web |
work_item_complete | read | Complete one durable Persona WorkItem after all dependencies are completed. |
work_item_create | write | Create a durable task. During ongoing-goal work it automatically belongs to that goal and runs when ready; outside an ongoing goal it is saved for assignment. List existing tasks first to avoid duplicates. Run todos remain scratch-scoped unless promoted separately. |
work_item_list | read | Read this Persona\ |
work_item_promote_todo | write | Explicitly promote one pending/in-progress run todo into a durable Persona WorkItem. The scratch todo is not changed. |
work_item_update | write | Update a durable Persona WorkItem, including status, priority, dependencies, deadline, and next action. |
write | write | Write a record |
write_artifact | write | Write research.md or launch.md. Include the exact source ID, audience and benefit from research_page. At most one artifact should be authored per Activity; report progress and continue in the next Activity. |
write_campaign_artifact | write | Write a useful sourced research.md, launch.md or backlog.md campaign artifact. Content is independently hashed and checked against the service facts. |
write_file | write | Write a file |
write_resource | write | Write an artifact |
write_stdin | write | Write UTF-8 text to a running background session\ |
zeta_read | read | Read a record |
Trust audit
CAUTIONgrade F · trust 45/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
lifecycleCoordinator.ts
deriveSecrets.ts
secretProposal.ts
token: 'webhook-secret-value',
const secret = 'eyJhbGciOiJIUzI1NiJ9.registry-access-token.signature';
const secret = 'sk-test-bare-ciphertext-path';
ApiKey: 'test-key-never-resolved',
ApiKey: 'benchmark-never-resolved',
delete_flow, delete_issue, delete_planned_execution, delete_record, forget, kill, release_owner, restart_mcp_server, test__delete, unpin
exec(`e${index + 1}`, `f${index + 1}`, onExecution(`e${index}`)),expect(() => new Function(source)).not.toThrow();
expect(() => new Function(appScript!)).not.toThrow();
expect(() => new Function(viewScript!)).not.toThrow();
.createHash('sha1')const accept = createHash('sha1')return createHash('sha1').update(value).digest('hex').slice(0, 8);const hash = crypto.createHash('sha1').update(abs).digest('hex').slice(0, 16);} from '../../enduringAgents/personaProcessBoundaryHarness';
expect(parseSubflowTaskUri(`${SUBFLOW_TASK_SCHEME}../../evil`)).toBeNull();expect(() => buildSubflowTaskUri('../../evil')).toThrow(/Unsafe collection item id/);await expect(getTask('../../etc/passwd')).resolves.toBeNull();await expect(patchTask('../../etc/passwd', { status: 'failed' })).resolves.toBeNull();describe('GET /api/env origin guard (secret exfiltration)', () => {{ type: 'image_url', image_url: { url: 'http://169.254.169.254/latest/meta-data' } },node scripts/smoke-mcp-artifacts.mjs --proxy-only http://127.0.0.1:4200
Gates applied: no_behavioural_pass.
1ac9def42990full audit observations/trust-audit/mcp-server/mario-andreschak__flujo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | 1ac9def42990 | CAUTION | F | 45 | first audit |
Questions
What is the FLUJO MCP server?
Multi-Agent + Automation Harness: Graph-based Workflows, MCP, Self-Improving Agents. NextJs+React
What tools does FLUJO expose?
185 in total: 139 read-only, 36 that write, and 10 that can delete or overwrite (delete_flow, delete_issue, delete_planned_execution, delete_record, forget). Every one is listed on this page with its risk.
Is FLUJO safe to connect to an agent?
With care. The audit graded it F (45/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does FLUJO need?
It reads CODEX_API_KEY, FAKE_SECRET, FLUJO_SNAPSHOT_CONTROL_TOKEN, FLUJO_WORKER_SNAPSHOT_KEY, GITHUB_TOKEN, OPENAI_API_KEY and PERSONA_GOAL_ENDURANCE_FIXTURE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does FLUJO run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as flujo-ai at 3.46.1.
How current is this page?
The grade is for one exact copy of the source (1ac9def42990), read on 2026-10-02. The repository is watched and re-audited when it changes.