Atlas / MCP servers / superglue-ai / Superglue

SuperglueBLOCK

mcp/superglue-ai/superglue

superglue (YC W25) builds integrations and tools from natural language. Get production-grade tools for long tail and enterprise systems.

Verdict
BLOCK
Grade
F
Trust score
40 /100
Exposed tools
20 15r · 5w · 0d
Transport
streamable-http
License
NOASSERTION
Stars
2,062
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

superglue's AI agents connect, migrate and implement enterprise systems. Cloud-hosted or on your own infrastructure.

[](https://www.ycombinator.com/companies/superglue) [](https://www.npmjs.com/package/@superglue/client) [](https://hub.docker.com/r/superglueai/superglue) [](https://app.workweave.ai/reports/repository/org_0S2o9PLamHvNsTjHbszc38vC/914997268)

What is superglue?

superglue learns how your systems work from your company's knowledge. It performs the implementation that normally requires human coordination and engineering work.

  • Implement NetSuite, Sage Intacct, SAP, Business Central or Acumatica in days. Agents map and migrate legacy data, configure the system, and keep data in sync post go-live.
  • Connect ERP, CRM, databases, and internal systems to AI platforms like Claude. Create governed data access for AI agents and track data usage across your org.
  • Connect customer systems, import historical data and get new integrations live in hours. Let agents manage the entire implementation process end-to-end.

Some example usecases

Read from source at commit 862b45b37adcOBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add web --env AI_GATEWAY_API_KEY=${AI_GATEWAY_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AUTH_TOKEN=${AUTH_TOKEN} --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} -- npx -y @superglue/[email protected]
claude-desktop
{
  "mcpServers": {
    "web": {
      "command": "npx",
      "args": [
        "-y",
        "@superglue/[email protected]"
      ],
      "env": {
        "AI_GATEWAY_API_KEY": "${AI_GATEWAY_API_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "AUTH_TOKEN": "${AUTH_TOKEN}",
        "AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}"
      }
    }
  }
}
03

Exposed tools (20)

15 read · 5 write · 0 destructive.

ToolRiskDescription
AdminreadFull access to all tools and systems in OSS.
MemberreadStandard role placeholder kept for RBAC compatibility in OSS.
authenticate_oauthreadInitiates OAuth flow for a system. Credentials (client_id/secret) must already be stored on the system. On success, tokens are auto-saved.
build_toolreadBuilds a new superglue tool by accepting the full tool configuration JSON. Successful builds are auto-saved — use the returned toolId for all subsequent operations. In the tool playground, builds remain draft-only until explicitly saved.
create_systemwriteCreates and saves a new system. If credentials are provided, a confirmation UI appears that lets users review credentials you have provided and enter missing values. Leave empty for auth-free systems.
custom_toolreadA custom tool
edit_systemwriteEdits an existing system. Provide only the fields to change — omitted fields are preserved. Cannot remove existing documentation, only append via files field.
find_rolereadLook up a saved role by ID, or list all roles. Returns the persisted role configuration (not the current UI draft). Use inspect_role for the current draft state.
find_systemreadLook up an existing system by ID or search by query. Also returns system knowledge (OAuth config, documentation URL) for systems not yet created. Use
find_toolreadLook up an existing tool by ID or search for tools by query. Use
get_runswriteFetches recent run history for saved tools. Draft executions (build_tool, run_tool with draftId) do NOT create runs — errors are in the tool result directly. Set fetchResults=true only when investigating, not when listing runs.
inspect_systemreadInspect specific parts of the current system editor state in detail. Unlike find_system (which looks up the saved server-side system), this inspects the current unsaved system editor state in the sidebar.
limited_toolreadA tool with limited uses
load_skillreadLoads superglue skills into context. Available skills: ${skillIndexDescription} Some skills include additional tools that become available after loading.
run_toolwriteExecutes a tool — either a draft (by draftId) or a saved tool (by toolId), not both. Keep JSON payload data in payload and bind uploaded files separately in files. Set includeStepResults: true only when debugging wrong/empty output. Set returnFullConfig: true only when you need the full config.
save_toolwritePersists a draft tool to the database. Requires a draftId from build_tool. After saving, the tool can be executed by ID using run_tool with toolId.
search_documentationreadSearch documentation for specific information about API structure, endpoints, authentication patterns, etc. Use this when you need to understand how an API works, what endpoints are available, or how to authenticate. Returns relevant documentation excerpts matching your search query.
tool_areadTool A
tool_breadTool B
unlimited_toolreadNo limit
04

Trust audit

BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (18 observation(s))
Shell
declared (9 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
.env.example:110
#   VERTEX_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----\n"
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
packages/web/src/components/tools/hooks/use-payload-validation.ts
use-payload-validation.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/core/api/systems-documentation.ts:729
specData = yaml.load(specData) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/core/api/systems-documentation.ts:762
parsedResolved = yaml.load(resolved) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/core/deno-runtime/utils/files.ts:1052
return yaml.load(content);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/core/documentation/documentation-utils.ts:336
specData = yaml.load(specData) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
packages/core/documentation/strategies/openapi-direct.ts:37
parsedData = yaml.load(trimmedData) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/auth/access-rule-evaluator.ts:142
const fn = new Function("stepConfig", `return Boolean(${expression})`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/deno-runtime/strategies/http.ts:130
const fn = eval(code);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/core/deno-runtime/utils/transform.ts:75
fn = eval(wrappedCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/shared/utils/vm-helpers.ts:14
const fn = new Function("sourceData", wrappedCode);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/core/deno-runtime/utils/security.ts:119
if (raw === "metadata.google.internal" || raw === "metadata.goog") return true;
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
packages/core/deno/deno-worker.ts:19
"169.254.169.254",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/core/datastore/postgres.ts:86
: { rejectUnauthorized: false },
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/core/deno-runtime/strategies/ftp.ts:563
connectionInfo.protocol === "ftps" ? { rejectUnauthorized: false } : undefined,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/core/deno-runtime/strategies/postgres.ts:168
if (cs.includes("sslmode=")) return { rejectUnauthorized: false };
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/core/deno-runtime/strategies/postgres.ts:201
return supportsSSL ? { rejectUnauthorized: false } : false;
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/core/deno-runtime/strategies/postgres.ts:204
return { rejectUnauthorized: false };
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.secretlintrc.json:14
"postgres://<<postgres-lego_username>>:<<postgres-lego_password>>@<<postgres-lego_host>>:<<postgres-lego_port>>",
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.secretlintrc.json:15
"postgres://<<eval-postgres_username>>:<<eval-postgres_password>>@<<eval-postgres_host>>:<<eval-postgres_port>>",
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.secretlintrc.json:17
"postgres://testuser:testpass@localhost:5432/testdb",
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.secretlintrc.json:18
"postgres://user2:pass2@host2/db2",
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.secretlintrc.json:19
"postgres://testuser:testpass@localhost:5432/my-test_db$123"
MEDIUMInventory / provenance · inv.symlink · CWE-1104
packages/web/.env.local
packages/web/.env.local
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/decrypt-credentials.ts:52
console.log('Usage: npm run decrypt -- \'{"api_key":"enc:...","token":"enc:..."}\'');

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha 862b45b37adcfull audit observations/trust-audit/mcp-server/superglue-ai__superglue.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-23862b45b37adcBLOCKF40source changed, verdict held
06

Questions

What is the Superglue MCP server?

superglue (YC W25) builds integrations and tools from natural language. Get production-grade tools for long tail and enterprise systems.

What tools does Superglue expose?

20 in total: 15 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Superglue safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (40/100) and found 23 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Superglue need?

It reads AI_GATEWAY_API_KEY, ANTHROPIC_API_KEY, AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, AZURE_API_KEY, GEMINI_API_KEY, GOOGLE_APPLICATION_CREDENTIALS, MASTER_ENCRYPTION_KEY, MINIO_ROOT_PASSWORD and NEXT_PUBLIC_SUPERGLUE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Superglue run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @superglue/web at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (862b45b37adc), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement