Magic CloudCAUTION
Instant SECURE Full Stack Apps and AI Agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Turn plain English into a working full-stack app — database, secure API, business logic, and frontend — running on your own hardware, with zero lock-in. An open-source alternative to Lovable, Bolt, and Replit that gives you the whole backend, plus an MCP server that turns every endpoint into a tool for Claude, Cursor, or Codex. Read more about Hyperlambda.
[](LICENSE) [](https://github.com/polterguy/magic/stargazers) [](https://dotnet.microsoft.com/) [](frontend/) [](https://hub.docker.com/r/servergardens/magic-backend) [](#contributing) []
Run it in 60 seconds
curl -fsSL https://hyperlambda.dev/docker-compose.yaml | docker compose -f - up
Then open `localhost:5555`, point it at `localhost:4444`, and log in with root / root.
Point the API Wizard at your database, and it generates a complete, secured REST API — then extend it in plain English, without a build or deploy step.
⭐ If this saves you time, star the repo — it's the main way other developers find it.
What you can build
- Full-stack business apps — CRM systems, admin panels, booking systems, internal tools; database, secure API and frontend generated from natural language
- Database-driven AI agents
26c6ef4c2b83OBSERVED · 2026-09-25Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add magic-aio:v23.5.10 -- docker run -i --rm docker.io/servergardens/magic-aio:v23.5.10:None
Trust audit
CAUTIONgrade C · trust 78/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
vector-arm64.dylib
vector-arm64.so
vector.dll
vector.dylib
vector.so
streamable-http
.config
.config
import { CopyIcon, TrashIcon } from '../../components/Icons';import { ChevronIcon } from '../../components/Icons';import { Modal } from '../../components/Dialogs';import { listFilesRecursively, uploadFile } from '../../lib/api';import { MenuIcon } from '../../components/Icons';const payload = JSON.parse(atob(parts[1].replace(/-/g, '+').replace(/_/g, '/')));
const payload = JSON.parse(atob(parts[1].replace(/-/g, '+').replace(/_/g, '/')));
const payload = JSON.parse(atob(parts[1].replace(/-/g, '+').replace(/_/g, '/')));
@codemirror/autocomplete, @codemirror/commands, @codemirror/lang-css, @codemirror/lang-html, @codemirror/lang-javascript, @codemirror/lang-json, @codemirror/lang-markdown, @codemirror/lang-sql
In this release we've released a BETA version of our Micro AI-SaaS solution allowing you to use the AI Expert System as your own foundation for a SaaS company selling access to a custom password prote
The dashboard signs in over OpenID Connect against **Google, GitHub, LinkedIn, Microsoft Entra ID, Okta, Auth0, Keycloak and Slack** — configured from the Configuration screen with a client ID (and, w
backend/files/misc/images/dark-blur-organic-flowerish.png
backend/files/misc/images/dark-green-waves.png
backend/files/misc/images/light-blue-organic-flower-on-black.png
backend/files/misc/images/light-blue-waves.png
backend/files/misc/images/organic-dark-blue-rock.png
Gates applied: no_behavioural_pass.
26c6ef4c2b83full audit observations/trust-audit/mcp-server/polterguy__magic-cloud.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | 26c6ef4c2b83 | CAUTION | C | 78 | first audit |
Questions
What is the Magic Cloud MCP server?
Instant SECURE Full Stack Apps and AI Agents
Is Magic Cloud safe to connect to an agent?
With care. The audit graded it C (78/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Magic Cloud need?
No credential environment variables were found in its source, so it appears to need none.
How does Magic Cloud run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as magic-frontend2 at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (26c6ef4c2b83), read on 2026-09-25. The repository is watched and re-audited when it changes.