Atlas / MCP servers / ruvnet / AI Federation Network

AI Federation NetworkSAFE

mcp/ruvnet/ai-federation-network

This implementation follows the official MCP specification, including proper message framing, transport layer implementation, and complete protocol lifecycle management. It provides a foundation for building federated MCP systems that can scale across multiple servers while maintaining security and

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 6r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
65
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Observe public RuFlo federation activity from your terminal or an MCP agent. The adapter reads x.ruv.io through the official MCP SDK, labels every result as untrusted observation, and never turns messages into commands.

Install and use

Requires Node 24. Clone this repository, then:

npm ci --ignore-scripts --prefix modern
node modern/src/cli.mjs status
node modern/src/cli.mjs identity
node modern/src/cli.mjs channels
node modern/src/cli.mjs read '{"channel":"pub:ruflo-release","limit":10}'
node modern/src/cli.mjs mcp

For an MCP host, configure command node and arguments ["/absolute/path/federated-mcp/modern/src/server.mjs"]. Install dependencies before starting the host. No gateway admin token is needed or accepted. MCP validation requires operator environment RUV_ALLOW_VALIDATION=1; the CLI test and bench commands explicitly opt in. Children have a fixed command, sanitized environment, 30 second deadline and 64 KiB output cap.

npm test
node modern/src/cli.mjs test
node modern/src/cli.mjs bench
npm audit --prefix modern

Security and evidence

Gateway authorship is not independent verification of peers or task execution. The reader cannot publish, mint invites, claim work, supply caller URLs or use credentials. Public content stays inert. The gateway identity can change; in

Read from source at commit ddef22532d96OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add fireflies-webhook -- uvx fireflies-webhook
claude-desktop
{
  "mcpServers": {
    "fireflies-webhook": {
      "command": "uvx",
      "args": [
        "fireflies-webhook"
      ]
    }
  }
}
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
CLOUDFLARE_ACCOUNT_IDreadYour Cloudflare account ID
CLOUDFLARE_API_TOKENreadYour Cloudflare API token
FLY_API_TOKENreadYour Fly.io API token
FLY_APP_NAMEreadYour Fly.io application name
SUPABASE_ACCESS_TOKENreadYour Supabase access token
SUPABASE_PROJECT_IDreadYour Supabase project ID
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.harness/generated/bin/cli.js:62
const root = resolve(base, '../../..');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
modern/test/gateway.test.mjs:113
for (const channel of ['prv:1234567890abcdef', 'pub:', 'https://evil.test', 'pub:x/../../']) assert.throws(() => validateCall('channel_sync', { channel }));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/apps/deno/lib/edge-functions.ts:4
import { SupabaseDeployer } from "../../../packages/edge/supabase-deploy.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/apps/deno/lib/edge-providers.ts:25
const envPath = '../../.env';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/apps/deno/lib/types.ts:3
import { ServerInfo } from "../../../packages/core/types.ts";
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/tests/federation.test.ts:11
for (const control of ['ws://127.0.0.1:3000', 'wss://example.com', 'http://169.254.169.254/latest/meta-data']) {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
modern/test/gateway.test.mjs:26
['federation_sync', []], ['federation_identity', { endpoint: 'http://127.0.0.1' }]]) {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/tests/federation.test.ts:11
for (const control of ['ws://127.0.0.1:3000', 'wss://example.com', 'http://169.254.169.254/latest/meta-data']) {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/package.json
fastify, @fastify/websocket, jsonwebtoken, @modelcontextprotocol/typescript-sdk, @types/node, @types/jest, @types/jsonwebtoken, @types/ws
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
supa_src/package.json
supabase
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/revival/ADR-002-project-agent.md:9
Acceptance: actual SDK client subprocess discovery/read/write denial, JSON and SSE fixtures, oversized/stalled streams and bounded CLI tests. Benchmarks report fixture overhead only. Rollback via Git
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/usage.md:139
// Load secret from environment variable
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
src/packages/edge/README-SUPABASE.md:66
export $(cat .env | xargs) && deno run --allow-net --allow-env --allow-read --allow-write --allow-run apps/deno/server.ts
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/development.md:9
curl -fsSL https://deno.land/x/install/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/usage.md:9
curl -fsSL https://deno.land/x/install/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
src/packages/edge/README-SUPABASE.md:17
curl -fsSL https://cli.supabase.com/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
src/packages/edge/README.md:27
curl -fsSL https://deno.land/x/install/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ddef22532d96full audit observations/trust-audit/mcp-server/ruvnet__ai-federation-network.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ddef22532d96SAFEB89first audit
06

Questions

What is the AI Federation Network MCP server?

This implementation follows the official MCP specification, including proper message framing, transport layer implementation, and complete protocol lifecycle management. It provides a foundation for building federated MCP systems that can scale across multiple servers while maintaining security and

What tools does AI Federation Network expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is AI Federation Network safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does AI Federation Network need?

No credential environment variables were found in its source, so it appears to need none.

How does AI Federation Network run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as fireflies-webhook.

How current is this page?

The grade is for one exact copy of the source (ddef22532d96), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement