Atlas / MCP servers / naveenraj-17 / Synapse

SynapseBLOCK

mcp/naveenraj-17/synapse-2

Build AI agents that actually do things. Synapse is an open-source platform for creating, connecting, and orchestrating AI agents powered by any LLM — local, cloud or CLIs.

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
8 7r · 0w · 1d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
327
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Build AI workflows that actually ship.

Wire agents, tools, and LLMs into deterministic pipelines — without the framework lock-in. Synapse is an open-source platform for creating, connecting, and orchestrating AI agents powered by any LLM — local or cloud. Agents use real tools: browsing the web, querying databases, executing code, reading files, managing emails, and anything else you can expose through an MCP server, a webhook, or a Pytho

Read from source at commit 1059c1bb9191OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add synapse-orch-ai --env AWS_BEARER_TOKEN_BEDROCK=${AWS_BEARER_TOKEN_BEDROCK} --env COPILOT_GITHUB_TOKEN=${COPILOT_GITHUB_TOKEN} --env GH_TOKEN=${GH_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "synapse-orch-ai": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AWS_BEARER_TOKEN_BEDROCK": "${AWS_BEARER_TOKEN_BEDROCK}",
        "COPILOT_GITHUB_TOKEN": "${COPILOT_GITHUB_TOKEN}",
        "GH_TOKEN": "${GH_TOKEN}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}"
      }
    }
  }
}
03

Exposed tools (8)

7 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
get_datetimeread
get_table_schemareadGet the detailed schema (columns, types, foreign keys) for specific table(s). Provide db_id when multiple databases are linked.
list_tablesreadList all tables in a database. Provide db_id when multiple databases are linked.
parse_pdfreadParse a PDF file from a URL. Extracts text and tables, formatting tables as Markdown.
parse_xlsxreadParse an Excel file (XLSX) from a URL. Extracts sheets and converts them to Markdown tables.
vault_deletedestructiveDelete a file from the vault. Returns confirmation.
vault_listreadList files in the vault, optionally filtered by extension or subdirectory.
vault_readreadRead a file from the vault by its path.
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (11 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
backend/core/orchestration/steps.py:1680
result = bool(eval(condition, eval_ns))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
backend/core/orchestration/steps.py:1724
value = eval(expression, eval_ns)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/bundle-frontend.js:46
exec(`cp -r "${staticSrc}" "${staticDest}"`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/bundle-frontend.js:50
exec(`cp -r "${publicSrc}" "${path.join(DEST_DIR, 'public')}"`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:36
# Default: postgres://postgres:password@localhost:5432/synapse
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:37
DATABASE_URL=postgres://postgres:root@localhost:5432/synapse
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
backend/core/messaging/manager.py:37
mod = importlib.import_module(module_path)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:10
# Default: http://127.0.0.1:11434
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:11
OLLAMA_BASE_URL=http://127.0.0.1:11434
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:27
# OPTIONAL — if omitted, auto-derived from SYNAPSE_BACKEND_PORT as http://127.0.0.1:<port>.
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
backend/core/llm_providers.py:133
return os.getenv("OLLAMA_BASE_URL", "http://127.0.0.1:11434")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
frontend/src/components/settings/McpServersTab.tsx:68
{ server_type: 'remote', name: 'Github', url: 'https://api.githubcopilot.com/mcp/', label: 'GitHub Copilot', token: 'GITHUB_PERSONAL_ACCESS_TOKEN' },
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
frontend/src/components/settings/McpServersTab.tsx:73
{ server_type: 'remote', name: 'Figma', url: 'https://mcp.figma.com/mcp', label: 'Figma', token: 'FIGMA_PERSONAL_ACCESS_TOKEN' },
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
vault_delete
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codacy.yaml
.codacy.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.docker
.env.docker
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
backend/tests/install/test_install_smoke.py:54
importlib.import_module(name)
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
backend/tests/install/test_mcp_sdk_contract.py:97
module = importlib.import_module(module_name)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
bin/synapse.js:191
return crypto.createHash('md5').update(fs.readFileSync(REQUIREMENTS)).digest('hex');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
backend/tests/api_app/test_edge_cases.py:46
msg = "read @[../../../../etc/passwd]"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
backend/tests/api_app/test_edge_cases.py:51
resp = await client.get("/api/vault/file", params={"path": "../../../../etc/passwd"})
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
frontend/scripts/load-env.js:21
const rootEnv = path.resolve(__dirname, "../../.env");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:131
**Frontend ↔ Backend:** The Next.js dev server proxies `/api/*` and `/auth/*` to `http://127.0.0.1:8765` via `next.config.ts` rewrites. Server-side API routes use the `BACKEND_URL` environment variabl
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
backend/core/llm_providers.py:1056
data=base64.b64decode(b64),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
backend/core/llm_providers.py:1618
blocks.append({"image": {"format": fmt, "source": {"bytes": base64.b64decode(b64)}}})

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 1059c1bb9191full audit observations/trust-audit/mcp-server/naveenraj-17__synapse-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-081059c1bb9191BLOCKF56first audit
06

Questions

What is the Synapse MCP server?

Build AI agents that actually do things. Synapse is an open-source platform for creating, connecting, and orchestrating AI agents powered by any LLM — local, cloud or CLIs.

What tools does Synapse expose?

8 in total: 7 read-only, 0 that write, and 1 that can delete or overwrite (vault_delete). Every one is listed on this page with its risk.

Is Synapse safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Synapse need?

It reads AWS_BEARER_TOKEN_BEDROCK, COPILOT_GITHUB_TOKEN, GH_TOKEN, GITHUB_TOKEN, METRICS_TOKEN, OAUTHLIB_RELAX_TOKEN_SCOPE, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY, SYNAPSE_INTERNAL_TOKEN and SYNAPSE_JWT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Synapse run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as synapse-orch-ai at 1.9.1.

How current is this page?

The grade is for one exact copy of the source (1059c1bb9191), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement