Synapse AIBLOCK
Build AI agents that actually do things. Synapse is an open-source platform for creating, connecting, and orchestrating AI agents powered by any LLM — local, cloud or CLIs.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Build AI workflows that actually ship.
Wire agents, tools, and LLMs into deterministic pipelines — without the framework lock-in. Synapse is an open-source platform for creating, connecting, and orchestrating AI agents powered by any LLM — local or cloud. Agents use real tools: browsing the web, querying databases, executing code, reading files, managing emails, and anything else you can expose through an MCP server, a webhook, or a Pytho
1059c1bb9191OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add synapse-orch-ai --env AWS_BEARER_TOKEN_BEDROCK=${AWS_BEARER_TOKEN_BEDROCK} --env COPILOT_GITHUB_TOKEN=${COPILOT_GITHUB_TOKEN} --env GH_TOKEN=${GH_TOKEN} --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"synapse-orch-ai": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"AWS_BEARER_TOKEN_BEDROCK": "${AWS_BEARER_TOKEN_BEDROCK}",
"COPILOT_GITHUB_TOKEN": "${COPILOT_GITHUB_TOKEN}",
"GH_TOKEN": "${GH_TOKEN}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
}
}Exposed tools (8)
7 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
get_datetime | read | |
get_table_schema | read | Get the detailed schema (columns, types, foreign keys) for specific table(s). Provide db_id when multiple databases are linked. |
list_tables | read | List all tables in a database. Provide db_id when multiple databases are linked. |
parse_pdf | read | Parse a PDF file from a URL. Extracts text and tables, formatting tables as Markdown. |
parse_xlsx | read | Parse an Excel file (XLSX) from a URL. Extracts sheets and converts them to Markdown tables. |
vault_delete | destructive | Delete a file from the vault. Returns confirmation. |
vault_list | read | List files in the vault, optionally filtered by extension or subdirectory. |
vault_read | read | Read a file from the vault by its path. |
Trust audit
BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
result = bool(eval(condition, eval_ns))
value = eval(expression, eval_ns)
exec(`cp -r "${staticSrc}" "${staticDest}"`);exec(`cp -r "${publicSrc}" "${path.join(DEST_DIR, 'public')}"`);# Default: postgres://postgres:password@localhost:5432/synapse
DATABASE_URL=postgres://postgres:root@localhost:5432/synapse
mod = importlib.import_module(module_path)
# Default: http://127.0.0.1:11434
OLLAMA_BASE_URL=http://127.0.0.1:11434
# OPTIONAL — if omitted, auto-derived from SYNAPSE_BACKEND_PORT as http://127.0.0.1:<port>.
return os.getenv("OLLAMA_BASE_URL", "http://127.0.0.1:11434"){ server_type: 'remote', name: 'Github', url: 'https://api.githubcopilot.com/mcp/', label: 'GitHub Copilot', token: 'GITHUB_PERSONAL_ACCESS_TOKEN' },{ server_type: 'remote', name: 'Figma', url: 'https://mcp.figma.com/mcp', label: 'Figma', token: 'FIGMA_PERSONAL_ACCESS_TOKEN' },vault_delete
.codacy.yaml
.env.docker
importlib.import_module(name)
module = importlib.import_module(module_name)
return crypto.createHash('md5').update(fs.readFileSync(REQUIREMENTS)).digest('hex');msg = "read @[../../../../etc/passwd]"
resp = await client.get("/api/vault/file", params={"path": "../../../../etc/passwd"})const rootEnv = path.resolve(__dirname, "../../.env");
**Frontend ↔ Backend:** The Next.js dev server proxies `/api/*` and `/auth/*` to `http://127.0.0.1:8765` via `next.config.ts` rewrites. Server-side API routes use the `BACKEND_URL` environment variabl
data=base64.b64decode(b64),
blocks.append({"image": {"format": fmt, "source": {"bytes": base64.b64decode(b64)}}})Gates applied: no_behavioural_pass.
1059c1bb9191full audit observations/trust-audit/mcp-server/synapseorch-ai__synapse-ai.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 1059c1bb9191 | BLOCK | F | 55 | first audit |
Questions
What is the Synapse AI MCP server?
Build AI agents that actually do things. Synapse is an open-source platform for creating, connecting, and orchestrating AI agents powered by any LLM — local, cloud or CLIs.
What tools does Synapse AI expose?
8 in total: 7 read-only, 0 that write, and 1 that can delete or overwrite (vault_delete). Every one is listed on this page with its risk.
Is Synapse AI safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (55/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Synapse AI need?
It reads AWS_BEARER_TOKEN_BEDROCK, COPILOT_GITHUB_TOKEN, GH_TOKEN, GITHUB_TOKEN, METRICS_TOKEN, OAUTHLIB_RELAX_TOKEN_SCOPE, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY, SYNAPSE_INTERNAL_TOKEN and SYNAPSE_JWT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Synapse AI run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as synapse-orch-ai at 1.9.1.
How current is this page?
The grade is for one exact copy of the source (1059c1bb9191), read on 2026-10-03. The repository is watched and re-audited when it changes.