ReshaprBLOCK
The open source, no-code MCP Server for AI-Native API Access
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/reshaprio/reshapr/actions) [](https://quay.io/repository/reshapr/reshapr-ctrl?tab=tags) []((https://central.sonatype.com/search?q=io.reshapr)) [](https://www.npmjs.com/package/@reshapr/reshapr-cli) [](https://www.npmjs.com/package/@reshapr/reshapr-cli) [](https://www.apache.org/licenses/LICENSE-2.0) [](https://discord.gg/KyDUdam34h) [](https://github.com/reshaprio/reshapr) [](https://github.com/reshaprio/reshapr/forks)
**Website** | **About** | **Docs** | **Blog** | **Community**
✨ What is reShapr?
reShapr is the open source, no-code MCP Server for AI-Native API Access. It bridges the gap between traditional REST/
13b72cb98ddcOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add reshapr-web-ui --env RESHAPR_ADMIN_API_KEY=${RESHAPR_ADMIN_API_KEY} -- npx -y @reshapr/[email protected]{
"mcpServers": {
"reshapr-web-ui": {
"command": "npx",
"args": [
"-y",
"@reshapr/[email protected]"
],
"env": {
"RESHAPR_ADMIN_API_KEY": "${RESHAPR_ADMIN_API_KEY}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
acme | read | Acme organization |
e2eorg | read | Organization for E2E tests |
Trust audit
BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
-----BEGIN PRIVATE KEY-----
.option('-k, --insecure', 'Skip SSL certificate validation')maven-wrapper.jar
maven-wrapper.jar
maven-wrapper.jar
maven-wrapper.jar
Logger.warn(`Your token has expired. Please login again using the \`${CLI_NAME} login\` command.`);Logger.error(`Creating API token failed: ${response.statusText}`);Logger.warn(`The API Token to register Gateway is: ${token.organizationId}-${token.token}`);Logger.error(`Failed to delete API token: ${response.statusText}`);Logger.info(`API token with ID ${tokenId} deleted successfully.`);reshapr.ctrl.api.key=${RESHAPR_CTRL_API_KEY:CzBuQ9B0i8qrUQe6WLiDLqR3gv4iCbxvjTJQP0z0CFGQbjgBHPZSusa9d1gZKwwjdoCsJ8ogRwRzc06GipJSjSDkFOy0BSOKvAa2EjU3As9I5UjgizTzxsJAVJIXtdo2xiXHhcry9KeJa0zRhDtGmm8WMujoSERVER_TOKEN=CzBuQ9B0i8qrUQe6WLiDLqR3gv4iCbxvjTJQP0z0CFGQbjgBHPZSusa9d1gZKwwjdoCsJ8ogRwRzc06GipJSjSDkFOy0BSOKvAa2EjU3As9I5UjgizTzxsJAVJIXtdo2xiXHhcry9KeJa0zRhDtGmm8WMujoXrlfj0ChlJKaHZiZsRthd4UHrWkKur9
SERVER_TOKEN=CzBuQ9B0i8qrUQe6WLiDLqR3gv4iCbxvjTJQP0z0CFGQbjgBHPZSusa9d1gZKwwjdoCsJ8ogRwRzc06GipJSjSDkFOy0BSOKvAa2EjU3As9I5UjgizTzxsJAVJIXtdo2xiXHhcry9KeJa0zRhDtGmm8WMujoXrlfj0ChlJKaHZiZsRthd4UHrWkKur9
SERVER_TOKEN=CzBuQ9B0i8qrUQe6WLiDLqR3gv4iCbxvjTJQP0z0CFGQbjgBHPZSusa9d1gZKwwjdoCsJ8ogRwRzc06GipJSjSDkFOy0BSOKvAa2EjU3As9I5UjgizTzxsJAVJIXtdo2xiXHhcry9KeJa0zRhDtGmm8WMujoXrlfj0ChlJKaHZiZsRthd4UHrWkKur9
maven-wrapper.jar
const CLI_ENTRY = path.resolve(import.meta.dirname, '../../dist/cli.js');
const COMPOSE_FILE = path.resolve(import.meta.dirname, '../../../install/docker-compose-all-in-one.yml');
const OPEN_METEO_SPEC = path.resolve(import.meta.dirname, '../../../dev/open-meteo-openapi.yml');
import { Context } from '../../utils/context.js';import { Logger } from '../../utils/logger.js';.setBackendEndpoint("http://127.0.0.1:" + bench.backendPort()).setBackendEndpoint("http://127.0.0.1:" + bench.backendPort()).setBackendEndpoint("http://127.0.0.1:" + backendPort)backendUri = URI.create("http://127.0.0.1:" + backend.port() + "/api/bench");Gates applied: critical_finding, no_behavioural_pass.
13b72cb98ddcfull audit observations/trust-audit/mcp-server/reshaprio__reshapr.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 13b72cb98ddc | BLOCK | F | 56 | first audit |
Questions
What is the Reshapr MCP server?
The open source, no-code MCP Server for AI-Native API Access
What tools does Reshapr expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Reshapr safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (56/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Reshapr need?
It reads RESHAPR_ADMIN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (13b72cb98ddc), read on 2026-10-07. The repository is watched and re-audited when it changes.