AI Federation NetworkSAFE
This implementation follows the official MCP specification, including proper message framing, transport layer implementation, and complete protocol lifecycle management. It provides a foundation for building federated MCP systems that can scale across multiple servers while maintaining security and
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Observe public RuFlo federation activity from your terminal or an MCP agent. The adapter reads x.ruv.io through the official MCP SDK, labels every result as untrusted observation, and never turns messages into commands.
Install and use
Requires Node 24. Clone this repository, then:
npm ci --ignore-scripts --prefix modern
node modern/src/cli.mjs status
node modern/src/cli.mjs identity
node modern/src/cli.mjs channels
node modern/src/cli.mjs read '{"channel":"pub:ruflo-release","limit":10}'
node modern/src/cli.mjs mcpFor an MCP host, configure command node and arguments ["/absolute/path/federated-mcp/modern/src/server.mjs"]. Install dependencies before starting the host. No gateway admin token is needed or accepted. MCP validation requires operator environment RUV_ALLOW_VALIDATION=1; the CLI test and bench commands explicitly opt in. Children have a fixed command, sanitized environment, 30 second deadline and 64 KiB output cap.
npm test node modern/src/cli.mjs test node modern/src/cli.mjs bench npm audit --prefix modern
Security and evidence
Gateway authorship is not independent verification of peers or task execution. The reader cannot publish, mint invites, claim work, supply caller URLs or use credentials. Public content stays inert. The gateway identity can change; in
ddef22532d96OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add fireflies-webhook -- uvx fireflies-webhook
{
"mcpServers": {
"fireflies-webhook": {
"command": "uvx",
"args": [
"fireflies-webhook"
]
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
CLOUDFLARE_ACCOUNT_ID | read | Your Cloudflare account ID |
CLOUDFLARE_API_TOKEN | read | Your Cloudflare API token |
FLY_API_TOKEN | read | Your Fly.io API token |
FLY_APP_NAME | read | Your Fly.io application name |
SUPABASE_ACCESS_TOKEN | read | Your Supabase access token |
SUPABASE_PROJECT_ID | read | Your Supabase project ID |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (10 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
const root = resolve(base, '../../..');
for (const channel of ['prv:1234567890abcdef', 'pub:', 'https://evil.test', 'pub:x/../../']) assert.throws(() => validateCall('channel_sync', { channel }));import { SupabaseDeployer } from "../../../packages/edge/supabase-deploy.ts";const envPath = '../../.env';
import { ServerInfo } from "../../../packages/core/types.ts";for (const control of ['ws://127.0.0.1:3000', 'wss://example.com', 'http://169.254.169.254/latest/meta-data']) {['federation_sync', []], ['federation_identity', { endpoint: 'http://127.0.0.1' }]]) {for (const control of ['ws://127.0.0.1:3000', 'wss://example.com', 'http://169.254.169.254/latest/meta-data']) {fastify, @fastify/websocket, jsonwebtoken, @modelcontextprotocol/typescript-sdk, @types/node, @types/jest, @types/jsonwebtoken, @types/ws
supabase
Acceptance: actual SDK client subprocess discovery/read/write denial, JSON and SSE fixtures, oversized/stalled streams and bounded CLI tests. Benchmarks report fixture overhead only. Rollback via Git
// Load secret from environment variable
export $(cat .env | xargs) && deno run --allow-net --allow-env --allow-read --allow-write --allow-run apps/deno/server.ts
curl -fsSL https://deno.land/x/install/install.sh | sh
curl -fsSL https://deno.land/x/install/install.sh | sh
curl -fsSL https://cli.supabase.com/install.sh | sh
curl -fsSL https://deno.land/x/install/install.sh | sh
Gates applied: no_behavioural_pass.
ddef22532d96full audit observations/trust-audit/mcp-server/ruvnet__ai-federation-network.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ddef22532d96 | SAFE | B | 89 | first audit |
Questions
What is the AI Federation Network MCP server?
This implementation follows the official MCP specification, including proper message framing, transport layer implementation, and complete protocol lifecycle management. It provides a foundation for building federated MCP systems that can scale across multiple servers while maintaining security and
What tools does AI Federation Network expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is AI Federation Network safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does AI Federation Network need?
No credential environment variables were found in its source, so it appears to need none.
How does AI Federation Network run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as fireflies-webhook.
How current is this page?
The grade is for one exact copy of the source (ddef22532d96), read on 2026-10-07. The repository is watched and re-audited when it changes.