Atlas / MCP servers / matthewhand / Mcp-Flowise

Mcp-FlowiseSAFE

mcp/matthewhand/mcp-flowise
Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 3r · 1w · 0d
Transport
stdio
License
MIT
Stars
55
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@matthewhand/mcp-flowise)

mcp-flowise is a Python package implementing a Model Context Protocol (MCP) server that integrates with the Flowise API. It provides a standardized and flexible way to list chatflows, create predictions, and dynamically register tools for Flowise chatflows or assistants.

It supports two operation modes:

  • LowLevel Mode (Default): Dynamically registers tools for all chatflows retrieved from the Flowise API.
  • FastMCP Mode: Provides static tools for listing chatflows and creating predictions, suitable for simpler configurations.

Features

  • Dynamic Tool Exposure: LowLevel mode dynamically creates tools for each chatflow or assistant.
  • Simpler Configuration: FastMCP mode exposes list_chatflows and create_prediction tools for minimal setup.
  • Flexible Filtering: Both modes support filtering chatflows via whitelists and blacklists by IDs or names (regex).
  • MCP Integration: Integrates seamlessly into MCP workflows.

Installation

Installing via Smithery

To install mcp-flowise for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install @matthewhand/mcp-flowise --client claude

Prerequisites

  • Python 3.12 or higher
  • uvx package manager

Install and Run via uvx

Confirm you can run the server directly from the GitHub repository using uvx:

uvx --from git+https://github.com/matthewhand/mcp-flowise mcp-flowise

Adding to MCP Ecosystem (mcpServers Configuration)

You can integrate mcp-flowise into your MCP ecosystem by adding it to the mcpServers configuration. Example:

{
"mcpServers": {
"mcp-flowi
Read from source at commit 4143e3d85d09OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-flowise --env FLOWISE_API_KEY=${FLOWISE_API_KEY} -- uvx mcp-flowise
claude-desktop
{
  "mcpServers": {
    "mcp-flowise": {
      "command": "uvx",
      "args": [
        "mcp-flowise"
      ],
      "env": {
        "FLOWISE_API_KEY": "${FLOWISE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (4)

3 read · 1 write · 0 destructive.

ToolRiskDescription
create_predictionwrite
list_chatflowsread
test_chatflow_1readTest Chatflow 1
test_chatflow_2readTest Chatflow 2
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4143e3d85d09full audit observations/trust-audit/mcp-server/matthewhand__mcp-flowise.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084143e3d85d09SAFEB89first audit
06

Questions

What tools does Mcp-Flowise expose?

4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mcp-Flowise safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Mcp-Flowise need?

It reads FLOWISE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcp-Flowise run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-flowise.

How current is this page?

The grade is for one exact copy of the source (4143e3d85d09), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement