Atlas / MCP servers / ruvnet / Flow Nexus

Flow NexusBLOCK

mcp/ruvnet/flow-nexus

Flow Nexus is the first competitive agentic platform built entirely on MCP. Deploy autonomous AI swarms, train neural networks, and compete in coding challenges while earning rUv credits. Transform agentic engineering mastery into lived experience through gamified cloud development where agents sp

Verdict
BLOCK
Grade
D
Trust score
67 /100
Exposed tools
3 3r · 0w · 0d
Transport
—
License
—
Stars
105
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🌐 flow-nexus.ruv.io

The First Competitive Agentic System

npx flow-nexus

🎁 New User Bonus: 256 rUv credits to start!

✨ Free Start • 🎮 Gamified Experience • 🚀 Instant Deploy • ♾️ Autonomous Operation

📖 Introduction

Flow Nexus: The first competitive agentic system that merges cloud elasticity with autonomous intelligence.

Agentic engineering is both a science to be mastered and an art to be practiced. Flow Nexus transforms that mastery into a lived experience: not just theory, but a challenge system where you learn by building, testing, and proving yourself in real-time. It feels less like documentation, more like a game; a path toward becoming a learned master of agents.

Using Claude Code/Desktop, OpenAI Codex, Cursor, GitHub Copilot, and other MCP-enabled tools, deploy autonomous agent swarms into cloud-hosted agentic sandboxes. Build, compete, and monetize your creations in the ultimate agentic playground. Earn rUv credits through epic code battles and algorithmic supremacy.

Flow Nexus combines the proven economics of cloud computing (pay-as-you-go, scale-on-demand) with the power of autonomous agent coordination. As the first agentic platform built entirely on the MCP (Model Context Protocol) standard, it delivers a unified interface where your IDE, agents, and infrastructure all speak the same language—enabling recursive intelligence where agents spawn agents, sandboxes cr

Read from source at commit 1451dc2170c0OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add agentic-marketing --env AUTO_AUTH_ACTION=${AUTO_AUTH_ACTION} --env AUTO_AUTH_EMAIL=${AUTO_AUTH_EMAIL} --env AUTO_AUTH_PASSWORD=${AUTO_AUTH_PASSWORD} --env FLOW_NEXUS_PASSWORD=${FLOW_NEXUS_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "agentic-marketing": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AUTO_AUTH_ACTION": "${AUTO_AUTH_ACTION}",
        "AUTO_AUTH_EMAIL": "${AUTO_AUTH_EMAIL}",
        "AUTO_AUTH_PASSWORD": "${AUTO_AUTH_PASSWORD}",
        "FLOW_NEXUS_PASSWORD": "${FLOW_NEXUS_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
anomaly-detectionreadAutomated spend anomaly detection and alerting
automated-campaign-optimizationreadDaily campaign performance analysis and budget optimization
campaign-optimizationreadAI-powered campaign optimization and budget reallocation
04

Trust audit

BLOCKgrade D · trust 67/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (13)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tutorials/agentic-marketing/src/DatabaseManager.js:414
exec(sql) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tutorials/agentic-marketing/src/FlowNexusMCPWrapper.js:32
const child = exec(fullCommand, {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
.claude/commands/flow-nexus/user-tools.md:136
token: "verification_token_from_email"
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
tutorials/agentic-marketing/package.json
chalk, commander, express, flow-nexus, inquirer, ora, sqlite3, nodemon
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:57
mcp__flow-nexus__user_register({ email: "[email protected]", password: "secure" })
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:58
mcp__flow-nexus__user_login({ email: "[email protected]", password: "secure" })
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:656
npx flow-nexus auth login -e [email protected] -p password
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
tutorials/agentic-marketing/README.md:149
-d '{"email":"[email protected]","password":"password"}'
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
tutorials/agentic-marketing/README.md:154
-d '{"email":"[email protected]","password":"password","fullName":"User"}'
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.claude/agents/core/coder.md:30
You are a senior software engineer specialized in writing clean, maintainable, and efficient code following best practices and design patterns.
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.claude/agents/core/reviewer.md:25
You are a senior code reviewer responsible for ensuring code quality, security, and maintainability through thorough review processes.
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.claude/agents/swarm/README.md:186
- **MCP Integration**: Full access to claude-flow's MCP tool ecosystem

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 1451dc2170c0full audit observations/trust-audit/mcp-server/ruvnet__flow-nexus.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-071451dc2170c0BLOCKD67first audit
06

Questions

What is the Flow Nexus MCP server?

Flow Nexus is the first competitive agentic platform built entirely on MCP. Deploy autonomous AI swarms, train neural networks, and compete in coding challenges while earning rUv credits. Transform agentic engineering mastery into lived experience through gamified cloud development where agents sp

What tools does Flow Nexus expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Flow Nexus safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (67/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Flow Nexus need?

It reads AUTO_AUTH_ACTION, AUTO_AUTH_EMAIL, AUTO_AUTH_PASSWORD and FLOW_NEXUS_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (1451dc2170c0), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement