Atlas / MCP servers / reddotrocket / AgentUp

AgentUpBLOCK

mcp/reddotrocket/agentup

Portable , scalable , secure AI Agents

Verdict
BLOCK
Grade
F
Trust score
48 /100
Exposed tools
12 11r · 0w · 1d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
127
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 简体中文

🚀 Active Development

🏃♂️ We are moving fast, things will break!

Why AgentUp?

Just as Docker made applications immutable, reproducible, and ops-friendly, AgentUp does the same for AI agen

Read from source at commit d98a69999bfeOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add agentup --env AGENTUP_API_KEY=${AGENTUP_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env MCP_API_KEY=${MCP_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx agentup
claude-desktop
{
  "mcpServers": {
    "agentup": {
      "command": "uvx",
      "args": [
        "agentup"
      ],
      "env": {
        "AGENTUP_API_KEY": "${AGENTUP_API_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "MCP_API_KEY": "${MCP_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (12)

11 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
delete_everythingdestructiveDeletes everything
get_alertsreadGet weather alerts for a US state.
get_forecastreadGet weather forecast for a location.
highreadHigh security
lowreadLow security
mediumreadMedium security
publicreadPublic tool
testreadTest
test_functionreadA test function for MCP
test_toolreadTest tool
tool1readTool 1
tool2readTool 2
04

Trust audit

BLOCKgrade F · trust 48/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (7 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/agent/mcp_support/mcp_server.py:163
exec(func_source, restricted_globals, local_vars)  # nosec
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/agent/push/notifier.py:269
"169.254.169.254",  # AWS/Azure metadata
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/agent/push/notifier.py:270
"metadata.google.internal",  # GCP metadata
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/agent/capabilities/__init__.py:38
importlib.import_module(f".{module_name}", package=__name__)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/agent/utils/helpers.py:18
module = importlib.import_module(module_name)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/agent/mcp_support/mcp_http_server.py:182
if not (origin.startswith("http://localhost") or origin.startswith("http://127.0.0.1")):
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/integrations/crewai.md:168
api_key="crew-integration-key",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/integrations/crewai.md:206
api_key="crew-integration-key"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/security/api-keys.md:81
api_key: "sk-8K2mNx9P7qR4sV5yA3bC6dE9fH2jK5lM8nP1qS4t"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/security/api-keys.md:142
api_key: "sk-your-strong-api-key-here"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/security/api-keys.md:326
api_key: "sk-prod-key-strong-and-secure"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_everything
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.bandit
.bandit
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/agent/templates/.env.j2
.env.j2
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/agent/templates/.gitignore.j2
.gitignore.j2
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/agent/templates/plugins/.gitignore.j2
.gitignore.j2
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/agent/a2a/agentcard.py:43
# Bandit issue: B324 - Using hashlib.md5() is acceptable here for caching purposes
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/agent/a2a/agentcard.py:44
current_config_hash = hashlib.md5(config_str.encode()).hexdigest()  # nosec
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/agent/mcp_support/mcp_client.py:602
return hashlib.md5(cache_input.encode()).hexdigest()  # nosec
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/test_streaming.py:311
print(f"Auth Token: {'Provided' if args.token else 'None'}")
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/agent/integrations/examples/basic_crew.py:200
print(f"API Key: {'***' if api_key else 'None'}")
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/agent/integrations/examples/multi_agent_flow.py:379
print(f"API Key: {'***' if api_key else 'None'}")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/getting-started/first-agent.md:128
INFO:     Uvicorn running on http://127.0.0.1:8000 (Press CTRL+C to quit)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/security/github_oauth2_setup.md:103
INFO:     Uvicorn running on http://0.0.0.0:8000 (Press CTRL+C to quit)

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d98a69999bfefull audit observations/trust-audit/mcp-server/reddotrocket__agentup.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d98a69999bfeBLOCKF48first audit
06

Questions

What is the AgentUp MCP server?

Portable , scalable , secure AI Agents

What tools does AgentUp expose?

12 in total: 11 read-only, 0 that write, and 1 that can delete or overwrite (delete_everything). Every one is listed on this page with its risk.

Is AgentUp safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (48/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does AgentUp need?

It reads AGENTUP_API_KEY, ANTHROPIC_API_KEY, MCP_API_KEY, OPENAI_API_KEY and VALKEY_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AgentUp run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as agentup.

How current is this page?

The grade is for one exact copy of the source (d98a69999bfe), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement