Find FlightsSAFE
An MCP server to search for flights.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP server for searching and retrieving flight information using Duffel API.
How it Works
Video Demo
https://github.com/user-attachments/assets/c111aa4c-9559-4d74-a2f6-60e322c273d4
Why This is Helpful
While tools like Google Flights work great for simple trips, this tool shines when dealing with complex travel plans. Here's why:
- Contextual Memory: Claude remembers all your previous flight searches in the chat, so you don't need to keep multiple tabs open to compare prices
- Flexible Date Search: Easily search across multiple days to find the best prices without manually checking each date
- Complex Itineraries: Perfect for multi-city trips, one-stop flights, or when you need to compare different route options you can just ask!
- Natural Conversation: Just describe what you're looking for - no more clicking through calendar interfaces or juggling search parameters down to parsing city names, dates, and times.
Think of it as having a travel agent in your chat who remembers everything you've discussed and can instantly search across dates and routes.
Features
- Search for flights between multiple destinations
- Support for one-way, round-trip, and multi-city flight queries
- Detailed flight offer information
- Flexible search parameters (departure times, cabin class, number of passengers)
- Automatic handling of flight connections
- Search for flights within multiple days to find the best flight for your trip (slower)
Prerequisites
- Python 3.x
- Duffel API Live Key
Getting Your Duffel API Key
Duffel requires account verification and payment information setup, but this MCP server only uses the API for searching flights - no actual bookings or charges will be made to your account.
Try using duffel_test first to see the power of this tool. If you end up liking it, you can go through the verification process below
83303d60a810OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add flights-mcp --env DUFFEL_API_KEY_LIVE=${DUFFEL_API_KEY_LIVE} -- uvx flights-mcp{
"mcpServers": {
"flights-mcp": {
"command": "uvx",
"args": [
"flights-mcp"
],
"env": {
"DUFFEL_API_KEY_LIVE": "${DUFFEL_API_KEY_LIVE}"
}
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_offer_details | read | Get detailed information about a specific flight offer. |
search_flights | read | Search for flights based on parameters. |
search_multi_city | read | Search for multi-city flights. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
83303d60a810full audit observations/trust-audit/mcp-server/ravinahp__find-flights.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 83303d60a810 | SAFE | B | 89 | first audit |
Questions
What is the Find Flights MCP server?
An MCP server to search for flights.
What tools does Find Flights expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Find Flights safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Find Flights need?
It reads DUFFEL_API_KEY_LIVE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Find Flights run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as flights-mcp.
How current is this page?
The grade is for one exact copy of the source (83303d60a810), read on 2026-10-06. The repository is watched and re-audited when it changes.