SuperglueBLOCK
superglue (YC W25) builds integrations and tools from natural language. Get production-grade tools for long tail and enterprise systems.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
superglue's AI agents connect, migrate and implement enterprise systems. Cloud-hosted or on your own infrastructure.
[](https://www.ycombinator.com/companies/superglue) [](https://www.npmjs.com/package/@superglue/client) [](https://hub.docker.com/r/superglueai/superglue) [](https://app.workweave.ai/reports/repository/org_0S2o9PLamHvNsTjHbszc38vC/914997268)
What is superglue?
superglue learns how your systems work from your company's knowledge. It performs the implementation that normally requires human coordination and engineering work.
- Implement NetSuite, Sage Intacct, SAP, Business Central or Acumatica in days. Agents map and migrate legacy data, configure the system, and keep data in sync post go-live.
- Connect ERP, CRM, databases, and internal systems to AI platforms like Claude. Create governed data access for AI agents and track data usage across your org.
- Connect customer systems, import historical data and get new integrations live in hours. Let agents manage the entire implementation process end-to-end.
Some example usecases
862b45b37adcOBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add web --env AI_GATEWAY_API_KEY=${AI_GATEWAY_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} -- npx -y @superglue/[email protected]{
"mcpServers": {
"web": {
"command": "npx",
"args": [
"-y",
"@superglue/[email protected]"
],
"env": {
"AI_GATEWAY_API_KEY": "${AI_GATEWAY_API_KEY}",
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"AUTH_TOKEN": "${AUTH_TOKEN}",
"AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}"
}
}
}
}Exposed tools (20)
15 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Admin | read | Full access to all tools and systems in OSS. |
Member | read | Standard role placeholder kept for RBAC compatibility in OSS. |
authenticate_oauth | read | Initiates OAuth flow for a system. Credentials (client_id/secret) must already be stored on the system. On success, tokens are auto-saved. |
build_tool | read | Builds a new superglue tool by accepting the full tool configuration JSON. Successful builds are auto-saved — use the returned toolId for all subsequent operations. In the tool playground, builds remain draft-only until explicitly saved. |
create_system | write | Creates and saves a new system. If credentials are provided, a confirmation UI appears that lets users review credentials you have provided and enter missing values. Leave empty for auth-free systems. |
custom_tool | read | A custom tool |
edit_system | write | Edits an existing system. Provide only the fields to change — omitted fields are preserved. Cannot remove existing documentation, only append via files field. |
find_role | read | Look up a saved role by ID, or list all roles. Returns the persisted role configuration (not the current UI draft). Use inspect_role for the current draft state. |
find_system | read | Look up an existing system by ID or search by query. Also returns system knowledge (OAuth config, documentation URL) for systems not yet created. Use |
find_tool | read | Look up an existing tool by ID or search for tools by query. Use |
get_runs | write | Fetches recent run history for saved tools. Draft executions (build_tool, run_tool with draftId) do NOT create runs — errors are in the tool result directly. Set fetchResults=true only when investigating, not when listing runs. |
inspect_system | read | Inspect specific parts of the current system editor state in detail. Unlike find_system (which looks up the saved server-side system), this inspects the current unsaved system editor state in the sidebar. |
limited_tool | read | A tool with limited uses |
load_skill | read | Loads superglue skills into context. Available skills: ${skillIndexDescription} Some skills include additional tools that become available after loading. |
run_tool | write | Executes a tool — either a draft (by draftId) or a saved tool (by toolId), not both. Keep JSON payload data in payload and bind uploaded files separately in files. Set includeStepResults: true only when debugging wrong/empty output. Set returnFullConfig: true only when you need the full config. |
save_tool | write | Persists a draft tool to the database. Requires a draftId from build_tool. After saving, the tool can be executed by ID using run_tool with toolId. |
search_documentation | read | Search documentation for specific information about API structure, endpoints, authentication patterns, etc. Use this when you need to understand how an API works, what endpoints are available, or how to authenticate. Returns relevant documentation excerpts matching your search query. |
tool_a | read | Tool A |
tool_b | read | Tool B |
unlimited_tool | read | No limit |
Trust audit
BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (18 observation(s))
- Shell
- declared (9 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
# VERTEX_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----\n"
use-payload-validation.ts
specData = yaml.load(specData) as any;
parsedResolved = yaml.load(resolved) as any;
return yaml.load(content);
specData = yaml.load(specData) as any;
parsedData = yaml.load(trimmedData) as any;
const fn = new Function("stepConfig", `return Boolean(${expression})`);const fn = eval(code);
fn = eval(wrappedCode);
const fn = new Function("sourceData", wrappedCode);if (raw === "metadata.google.internal" || raw === "metadata.goog") return true;
"169.254.169.254",
: { rejectUnauthorized: false },connectionInfo.protocol === "ftps" ? { rejectUnauthorized: false } : undefined,if (cs.includes("sslmode=")) return { rejectUnauthorized: false };return supportsSSL ? { rejectUnauthorized: false } : false;return { rejectUnauthorized: false };"postgres://<<postgres-lego_username>>:<<postgres-lego_password>>@<<postgres-lego_host>>:<<postgres-lego_port>>",
"postgres://<<eval-postgres_username>>:<<eval-postgres_password>>@<<eval-postgres_host>>:<<eval-postgres_port>>",
"postgres://testuser:testpass@localhost:5432/testdb",
"postgres://user2:pass2@host2/db2",
"postgres://testuser:testpass@localhost:5432/my-test_db$123"
packages/web/.env.local
console.log('Usage: npm run decrypt -- \'{"api_key":"enc:...","token":"enc:..."}\'');Gates applied: critical_finding, no_behavioural_pass.
862b45b37adcfull audit observations/trust-audit/mcp-server/superglue-ai__superglue.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 862b45b37adc | BLOCK | F | 40 | source changed, verdict held |
Questions
What is the Superglue MCP server?
superglue (YC W25) builds integrations and tools from natural language. Get production-grade tools for long tail and enterprise systems.
What tools does Superglue expose?
20 in total: 15 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Superglue safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (40/100) and found 23 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Superglue need?
It reads AI_GATEWAY_API_KEY, ANTHROPIC_API_KEY, AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, AZURE_API_KEY, GEMINI_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, MASTER_ENCRYPTION_KEY, MINIO_ROOT_PASSWORD and NEXT_PUBLIC_SUPERGLUE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Superglue run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @superglue/web at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (862b45b37adc), read on 2026-09-23. The repository is watched and re-audited when it changes.