Atlas / MCP servers / minipuft / Claude Prompts

Claude PromptsBLOCK

mcp/minipuft/claude-prompts

MCP server for reusable prompt templates, multi-step workflow chains, and quality gates. Compose agentic workflows with an operator syntax; export as native skills to Claude Code, Cursor, OpenCode, and Gemini CLI.

Verdict
BLOCK
Grade
F
Trust score
47 /100
Exposed tools
120 116r · 3w · 1d
Transport
sse · stdio · streamable-http
License
MIT
Stars
187
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Claude Prompts

The portable workflow layer beside your AI coding harness.

Your client executes with its own tools, agents, and context. Claude Prompts adds reusable prompt resources, composable chains, validation gates, and client-native skill export.

Quick Start · What You Get · Compose Workflows · Run Anywhere · Docs

What your AI client gives you — and what this server adds

Read from source at commit 1852bc931df4OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add claude-prompts -- npx -y [email protected]
03

Exposed tools (120)

116 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AnalysisreadAnalytical prompts
AnalyticalreadStructured style
AnalyzereadUnderstand the problem
AnalyzerreadAnalyzes content
Authoringread
BADEXITreadInvalid exit argument
CAGEERFreadContext-Analysis-Goals framework
Clobberreadshould not land either
ConverterreadConverts data
Demoread
DesignreadPlan the solution
DocsreadEnsure documentation
DraftreadDraft from prior work
EscapedreadShould never be written
FormatterreadFormats content
G1readD
GeneralreadGeneral prompts
ImplementreadBuild the solution
Inlineread
MinimalreadA minimal gate
NOPERMreadCommand not executable (check permissions)
NOTFOUNDreadCommand not found (check PATH or spelling)
Onereadfirst
P1readonly phase
Plainreadsecond step
PlanreadLay out the steps
PreviewreadPreview test
ProbereadThe only phase
Promptreaddesc
ReACTreadTest
ResearchreadResearch a topic
ReviewwriteReview the whole run
SCAMPERreadCreative framework
SIGABRTreadAbort
SIGALRMreadAlarm
SIGFPEreadFloating-point exception
SIGHUPreadHangup
SIGILLreadIllegal instruction
SIGINTreadInterrupt (Ctrl+C)
SIGKILLreadKilled (likely OOM)
SIGPIPEreadBroken pipe
SIGQUITreadQuit
SIGSEGVreadSegmentation fault
SIGTERMreadTerminated
SIGXCPUreadCPU time limit exceeded
Samplereadtest
Scriptedreadcarries a prompt-local tool
Sharedreadregistry description
SummarizereadSummarize content
SummarizerreadSummarize findings
SynthesizereadSynthesize from a named output
TestreadTest
ValidatorreadValidates input
Workflowread
argreadtest arg
c1read
c2read
chain_promptreada chain prompt
contentreadContent
custom-checkreadVerify edge cases
datareadInput
demoreadDemo prompt
draftreaddraft step
gc_chainreade2e chain whose own prompt includes gp-y and whose category supplies gp-cat
gc_chain_ownreade2e chain whose own prompt includes gp-y and whose last step includes gp-x
gc_nestreade2e chain whose second step is the chain gc_chain
gj-blockreadblocking e2e gate
gj_chainreade2e chain with a blocking gate on every step
gp-catreadblocking e2e gate a category supplies
gp_breade2e step whose prompt includes gp-x
gp_chainreade2e chain whose own prompt includes gp-y
gp_kreade2e step whose category supplies gp-cat
gr-reqreadblocking e2e gate a request names
hr_chainwritee2e held-run chain
inputreadOther input
json_promptreadJSON payloads
last_chainreade2e chain with an advisory gate on its last step
multireadAllow multi-line payloads
not_a_real_argumentreadx
p288-blockreadblocking e2e gate
p288_areada step with an authored system message
p288_breada step with no system message
p288_b_firstreada chain whose gated first step has no system message
p288_chainreada chain whose every step carries a blocking gate
p87-plainreadblocking, no retry_config: opens the single prompt a session
production-readyreadInclude tests and error handling
prompt_engineread
qk203readQK-203
red-teamreadConfirm exfil path
referencesreadEnsure references included
rq203readd
single_promptreada single prompt
snippetready
sv-blockreadblocking e2e gate
sv-dropdestructiveblocking e2e gate on a step a replace remainder drops
sv_areadd
sv_a148readstep carrying a chain-scoped inline definition
sv_a164readstep carrying a chain-scoped inline definition
sv_bigreade2e chain as long as the node cap
sv_chainreade2e chain with a blocking gate on every step
sv_chain148readchain whose steps carry a chain-scoped gate
sv_chain164readchain whose steps carry a chain-scoped gate
sv_chain_otherreada second chain the claiming server runs
sv_dpairreade2e ungated chain of default-gated steps
sv_late271reade2e chain gated on its last step only
sv_outreade2e step reading a named output
sv_p193readstep for P6.193
sv_p193_chainreadtwo steps
sv_p672reade2e chain of default-gated steps, the first blocking-gated
sv_pairreade2e ungated two-step chain
target_thingreadwhat to act on
taskwriteWork to execute
teamreadTeam or org name
testreadtest prompt
test-coveragereadInclude unit tests
textreadText to analyze
thingreadthe thing
topicreadoptional, undefaulted
unused_argreaddeclared, never used
work_kindreadkind of work
04

Trust audit

BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (11 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
server/scripts/generate-gate-index.js:34
const data = yaml.load(readFileSync(yamlPath, 'utf-8'));
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
server/scripts/lib/semantic-module-descriptors.ts:199
parsed = yaml.load(readFileSync(descriptorPath, 'utf8'));
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
server/scripts/validate-activation-categories.js:132
const parsed = yaml.load(readFileSync(absolute, 'utf8'));
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
server/scripts/validate-authoring-contracts.ts:96
const manifest = yaml.load(readFileSync(path.join(dir, 'tool.yaml'), 'utf8')) as {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
server/scripts/validate-authoring-contracts.ts:327
const prompt = yaml.load(readFileSync(path.join(tool.promptDir, 'prompt.yaml'), 'utf8')) as {
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/hook-harness.mjs:167
/^sh -c 'echo "[^"]*" >> \S+; export CLAUDE_PLUGIN_DATA="[^"]*"; exec (.*)'$/;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
server/src/modules/chains/manager.ts:1367
this.logger.info(`[Handoff] Minted token for session ${sessionId} (${session.chainId})`);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
server/src/mcp/metadata/definitions/prompt-engine.ts:122
'    { "name": "red-team", "description": "Confirm exfil path" },  // Simple check',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server/scripts/capture-tool-schemas.mjs:357
const baseUrl = `http://127.0.0.1:${port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server/scripts/verify-handoff.mjs:148
await waitHealth(`http://127.0.0.1:${PORT_A}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server/scripts/verify-handoff.mjs:150
await waitHealth(`http://127.0.0.1:${PORT_B}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server/scripts/verify-handoff.mjs:151
const a = client(`http://127.0.0.1:${PORT_A}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
server/scripts/verify-handoff.mjs:152
const b = client(`http://127.0.0.1:${PORT_B}`);
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/codex-server.test.mjs:21
secret = "sentinel-do-not-print"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
sv-drop
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.delivery-contract.json
.delivery-contract.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ignore
.ignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/tests/integration/database/sqlite-wal-checkpoint.test.ts:97
const rawDb = (engine as unknown as { db: { exec(sql: string): void } }).db;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/tests/unit/scripts/pr-conventions-merge-settings.test.ts:76
return new Function(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/request-renovate-run.js:44
.createHash("sha1")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/tests/integration/category-directory-rule.test.ts:19
const CLI = join(__dirname, '../../dist/cpm.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/tests/integration/cli.test.ts:7
const CLI = join(__dirname, '../../dist/cpm.js');

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 1852bc931df4full audit observations/trust-audit/mcp-server/minipuft__claude-prompts.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-071852bc931df4BLOCKF47first audit
06

Questions

What is the Claude Prompts MCP server?

MCP server for reusable prompt templates, multi-step workflow chains, and quality gates. Compose agentic workflows with an operator syntax; export as native skills to Claude Code, Cursor, OpenCode, and Gemini CLI.

What tools does Claude Prompts expose?

120 in total: 116 read-only, 3 that write, and 1 that can delete or overwrite (sv-drop). Every one is listed on this page with its risk.

Is Claude Prompts safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (47/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Claude Prompts need?

It reads AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN and MY_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claude Prompts run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as claude-prompts at 5.1.1.

How current is this page?

The grade is for one exact copy of the source (1852bc931df4), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement