← Back to search

com.cloudflare.mcp/mcp

cloudflare streamable_http Apache-2.0 3,757 stars Scanned 13h ago

Cloudflare MCP servers

D
54.1 / 100

Versions

1.0.0 latest
May 19, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 102

r2_buckets_list
unchecked low

List r2 buckets in your Cloudflare account

r2_bucket_create
unchecked low

Create a new r2 bucket in your Cloudflare account

r2_bucket_get
unchecked low

Get details about a specific R2 bucket

r2_bucket_delete
unchecked low

Delete an R2 bucket

r2_metrics_list
unchecked low

List metrics for an R2 bucket

d1_databases_list
unchecked low

List all of the D1 databases in your Cloudflare account

d1_database_create
unchecked low

Create a new D1 database in your Cloudflare account

d1_database_delete
unchecked low

Delete a d1 database in your Cloudflare account

d1_database_get
unchecked low

Get a D1 database in your Cloudflare account

d1_database_query
unchecked low

Query a D1 database in your Cloudflare account

zones_list
unchecked low

List all zones under a Cloudflare account

zone_details
unchecked low

Get details for a specific Cloudflare zone

accounts_list
unchecked low

List all accounts in your Cloudflare account

set_active_account
unchecked low

Set active account to be used for tool calls that require accountId

workers_get_worker
unchecked low

Get the details of the Cloudflare Worker.

workers_get_worker_code
unchecked low

Get the source code of a Cloudflare Worker. Note: This may be a bundled version of the worker.

mcp_demo_day_info
unchecked low

Get information about Cloudflare

list_gateways
unchecked low

List Gateways

list_logs
unchecked low

List Logs

get_log_details
unchecked low

Get a single Log details

get_log_request_body
unchecked low

Get Log Request Body

get_log_response_body
unchecked low

Get Log Response Body

get_url_html_content
unchecked low

Get page HTML content

get_url_markdown
unchecked low

Get page converted into Markdown

get_url_screenshot
unchecked low

Get page screenshot

graphql_complete_schema
unchecked low

Fetch the complete Cloudflare GraphQL API schema (combines overview and important type details)

list_autonomous_systems
unchecked low

List Autonomous Systems

get_as_details
unchecked low

Get Autonomous System details by ASN

get_ip_details
unchecked low

Get IP address information including full ASN details (name, country, population estimates from APNIC).

get_traffic_anomalies
unchecked low

Get traffic anomalies and outages

get_internet_services_ranking
unchecked low

Get top Internet services

get_domains_ranking
unchecked low

Get top or trending domains

get_domain_rank_details
unchecked low

Get domain rank details

get_http_data
unchecked low

Retrieve HTTP traffic trends.

get_dns_queries_data
unchecked low

Retrieve trends in DNS queries to the 1.1.1.1 resolver.

get_l7_attack_data
unchecked low

Retrieve application layer (L7) attack trends.

get_l3_attack_data
unchecked low

Retrieve network layer (L3/DDoS) attack trends.

get_email_routing_data
unchecked low

Retrieve Email Routing trends.

get_email_security_data
unchecked low

Retrieve Email Security trends.

get_internet_speed_data
unchecked low

Retrieve summary of bandwidth, latency, jitter, and packet loss, from the previous 90 days of Cloudflare Speed Test.

get_internet_quality_data
unchecked low

Retrieves a summary or time series of bandwidth, latency, or DNS response time percentiles from the Radar Internet Quality Index (IQI).

get_ai_data
unchecked low

Retrieves AI-related data, including traffic from AI user agents, as well as popular models and model tasks specifically from Cloudflare Workers AI.

get_bgp_hijacks
unchecked low

Retrieve BGP hijack events. BGP hijacks occur when an AS announces routes it does not own, potentially redirecting traffic.

get_bgp_leaks
unchecked low

Retrieve BGP route leak events. Route leaks occur when an AS improperly announces routes learned from one peer to another.

get_bgp_route_stats
unchecked low

Retrieve BGP routing table statistics including number of routes, origin ASes, and more.

get_bots_data
unchecked low

Retrieve bot traffic data including trends by bot name, operator, category, and kind. Covers AI crawlers, search engines, monitoring bots, and more.

get_certificate_transparency_data
unchecked low

Retrieve Certificate Transparency (CT) log data. CT provides visibility into SSL/TLS certificates issued for domains, useful for security monitoring.

get_netflows_data
unchecked low

Retrieve NetFlows traffic data showing network traffic patterns. Supports filtering by ADM1 (administrative level 1, e.g., states/provinces) via geoId.

list_origins
unchecked low

List cloud provider origins (hyperscalers) available in Cloud Observatory. Returns Amazon (AWS), Google (GCP), Microsoft (Azure), and Oracle (OCI) with their available regions.

get_origin_details
unchecked low

Get details for a specific cloud provider origin, including all available regions.

get_origins_data
unchecked low

Retrieve cloud provider (AWS, GCP, Azure, OCI) performance metrics. Supports timeseries, summaries grouped by region/success_rate/percentile, and grouped timeseries.

get_robots_txt_data
unchecked low

Retrieve robots.txt analysis data. Shows how websites configure crawler access rules, particularly for AI crawlers. Useful for understanding web crawler policies across domains.

get_bots_crawlers_data
unchecked low

Retrieve web crawler HTTP request data. Shows crawler traffic patterns by client type, user agent, referrer, and industry. Useful for analyzing crawler behavior and traffic distribution.

list_bots
unchecked low

List known bots with their details. Includes AI crawlers, search engines, monitoring bots, and more. Filter by category, operator, kind, or verification status.

get_bot_details
unchecked low

Get detailed information about a specific bot by its slug identifier.

get_leaked_credentials_data
unchecked low

Retrieve trends in HTTP authentication requests and compromised credential detection. Shows distribution by compromised status and bot class.

get_as112_data
unchecked low

Retrieve AS112 DNS sink hole data. AS112 handles reverse DNS lookups for private IP addresses (RFC 1918). Useful for analyzing DNS misconfiguration patterns.

list_geolocations
unchecked low

List available geolocations (ADM1 - administrative divisions like states/provinces). Use this to find GeoNames IDs for filtering HTTP and NetFlows data by region.

get_geolocation_details
unchecked low

Get details for a specific geolocation by its GeoNames ID.

get_tcp_resets_timeouts_data
unchecked low

Retrieve TCP connection quality metrics including resets and timeouts. Useful for understanding connection reliability across networks and locations.

get_annotations
unchecked low

Retrieve annotations including Internet events, outages, and anomalies from various Cloudflare data sources.

get_outages
unchecked low

Retrieve Internet outages and anomalies. Provides information about detected connectivity issues across ASes and locations.

list_ct_authorities
unchecked low

List Certificate Authorities (CAs) tracked in Certificate Transparency logs.

get_ct_authority_details
unchecked low

Get details for a specific Certificate Authority by its SHA256 fingerprint.

list_ct_logs
unchecked low

List Certificate Transparency logs.

get_ct_log_details
unchecked low

Get details for a specific Certificate Transparency log by its slug.

get_bgp_timeseries
unchecked low

Retrieve BGP updates time series data. Shows BGP announcement and withdrawal patterns over time.

get_bgp_top_ases
unchecked low

Get top Autonomous Systems by BGP update count.

get_bgp_top_prefixes
unchecked low

Get top IP prefixes by BGP update count.

get_bgp_moas
unchecked low

Get Multi-Origin AS (MOAS) prefixes. MOAS occurs when a prefix is announced by multiple ASes, which can indicate hijacking or legitimate anycast.

get_bgp_pfx2as
unchecked low

Get prefix-to-ASN mapping. Useful for looking up which AS announces a given IP prefix.

get_bgp_ip_space_timeseries
unchecked low

Retrieve announced IP address space time series data. Shows the count of announced IPv4 /24s and IPv6 /48s over time. Essential for monitoring BGP route withdrawals, IPv6 address space changes, and detecting significant routing events by ASN or country.

get_bgp_routes_realtime
unchecked low

Get real-time BGP routes for a specific IP prefix using public route collectors (RouteViews and RIPE RIS). Shows current routing state including AS paths, RPKI validation status, and visibility across peers. Useful for troubleshooting routing issues and verifying route announcements.

get_as_set
unchecked low

Get IRR AS-SETs that an Autonomous System is a member of. AS-SETs are used in routing policies.

get_as_relationships
unchecked low

Get AS-level relationships for an Autonomous System. Shows peer, upstream, and downstream relationships with other ASes.

list_tlds
unchecked low

List top-level domains (TLDs) including generic, country-code, and sponsored TLDs. Filter by type or manager.

get_tld_details
unchecked low

Get detailed information about a specific top-level domain (TLD).

get_domains_ranking_timeseries
unchecked low

Get domain ranking timeseries data. Track how specific domains rank over time.

get_speed_histogram
unchecked low

Get speed test histogram data. Shows distribution of speed test results for bandwidth, latency, or jitter.

get_internet_services_timeseries
unchecked low

Track internet service ranking changes over time. Useful for monitoring how services like ChatGPT, Google, etc. rank over time.

get_outages_by_location
unchecked low

Get outage counts aggregated by location. Useful for identifying which countries have the most Internet outages.

get_traffic_anomalies_by_location
unchecked low

Get traffic anomalies aggregated by location. Shows which countries have the most detected outage signals, automatically detected by Radar.

get_bgp_routing_table_ases
unchecked low

List all ASes in global routing tables with routing statistics (prefix counts, IPv4/IPv6 address count, RPKI validation status). Data comes from public BGP MRT archives.

get_bgp_top_ases_by_prefixes
unchecked low

Get top ASes ordered by announced prefix count. Useful for understanding which networks have the largest routing footprint. Data comes from public BGP MRT archives and updates every 2 hours.

get_bgp_rpki_aspa_snapshot
unchecked low

Retrieve a snapshot of current or historical RPKI ASPA (Autonomous System Provider Authorization) objects. ASPA objects define which ASNs are authorized upstream providers for a customer ASN, helping prevent route leaks and hijacks.

get_bgp_rpki_aspa_changes
unchecked low

Retrieve RPKI ASPA changes over time, including additions, removals, and modifications of ASPA objects.

get_bgp_rpki_aspa_timeseries
unchecked low

Retrieve a timeseries of RPKI ASPA object counts over time.

search_url_scans
unchecked low

Search URL scans using ElasticSearch-like query syntax. Examples:

create_url_scan
unchecked low

Submit a URL to scan. Returns the scan UUID which can be used to retrieve results.

get_url_scan
unchecked low

Get the results of a URL scan by its UUID. Returns detailed information including verdicts, page info, requests, cookies, and more.

get_url_scan_screenshot
unchecked low

Get the screenshot URL for a completed scan.

get_url_scan_har
unchecked low

Get the HAR (HTTP Archive) data for a completed scan. Contains detailed network request/response information.

list_rags
unchecked low

List AutoRAGs (vector stores)

search
unchecked low

Search Documents using AutoRAG (vector store)

ai_search
unchecked low

AI Search Documents using AutoRAG (vector store)

container_file_delete
unchecked low

Delete file in the working directory

container_file_write
unchecked low

Create a new file with the provided contents in the working direcotry, overwriting the file if it already exists

container_files_list
unchecked low

List working directory file tree. This just reads the contents of the current working directory

container_file_read
unchecked low

Read a specific file or directory. Use this tool if you would like to read files or display them to the user. This allow you to get a displayable image for the user if there is an image file.

dns_report
unchecked low

Fetch the DNS Report for a given zone since a date

show_account_dns_settings
unchecked low

Show DNS settings for current account

show_zone_dns_settings
unchecked low

Show DNS settings for a zone

Permissions 3

network medium
network
shell high
shell
env_vars low
env_vars

Scan Findings 268

info
package.json metadata manifest_parser · 100%
info
Tool: r2_buckets_list manifest_parser · 70%
info
Tool: r2_bucket_create manifest_parser · 70%
info
Tool: r2_bucket_get manifest_parser · 70%
info
Tool: r2_bucket_delete manifest_parser · 70%
info
Tool: r2_metrics_list manifest_parser · 70%
info
Tool: d1_databases_list manifest_parser · 70%
info
Tool: d1_database_create manifest_parser · 70%
info
Tool: d1_database_delete manifest_parser · 70%
info
Tool: d1_database_get manifest_parser · 70%
info
Tool: d1_database_query manifest_parser · 70%
info
Tool: zones_list manifest_parser · 70%
info
Tool: zone_details manifest_parser · 70%
info
Tool: accounts_list manifest_parser · 70%
info
Tool: set_active_account manifest_parser · 70%
info
Tool: workers_get_worker manifest_parser · 70%
info
Tool: workers_get_worker_code manifest_parser · 70%
info
Tool: mcp_demo_day_info manifest_parser · 70%
info
Tool: list_gateways manifest_parser · 70%
info
Tool: list_logs manifest_parser · 70%
info
Tool: get_log_details manifest_parser · 70%
info
Tool: get_log_request_body manifest_parser · 70%
info
Tool: get_log_response_body manifest_parser · 70%
info
Tool: get_url_html_content manifest_parser · 70%
info
Tool: get_url_markdown manifest_parser · 70%
info
Tool: get_url_screenshot manifest_parser · 70%
info
Tool: graphql_complete_schema manifest_parser · 70%
info
Tool: list_autonomous_systems manifest_parser · 70%
info
Tool: get_as_details manifest_parser · 70%
info
Tool: get_ip_details manifest_parser · 70%
info
Tool: get_traffic_anomalies manifest_parser · 70%
info
Tool: get_internet_services_ranking manifest_parser · 70%
info
Tool: get_domains_ranking manifest_parser · 70%
info
Tool: get_domain_rank_details manifest_parser · 70%
info
Tool: get_http_data manifest_parser · 70%
info
Tool: get_dns_queries_data manifest_parser · 70%
info
Tool: get_l7_attack_data manifest_parser · 70%
info
Tool: get_l3_attack_data manifest_parser · 70%
info
Tool: get_email_routing_data manifest_parser · 70%
info
Tool: get_email_security_data manifest_parser · 70%
info
Tool: get_internet_speed_data manifest_parser · 70%
info
Tool: get_internet_quality_data manifest_parser · 70%
info
Tool: get_ai_data manifest_parser · 70%
info
Tool: get_bgp_hijacks manifest_parser · 70%
info
Tool: get_bgp_leaks manifest_parser · 70%
info
Tool: get_bgp_route_stats manifest_parser · 70%
info
Tool: get_bots_data manifest_parser · 70%
info
Tool: get_certificate_transparency_data manifest_parser · 70%
info
Tool: get_netflows_data manifest_parser · 70%
info
Tool: list_origins manifest_parser · 70%
info
Tool: get_origin_details manifest_parser · 70%
info
Tool: get_origins_data manifest_parser · 70%
info
Tool: get_robots_txt_data manifest_parser · 70%
info
Tool: get_bots_crawlers_data manifest_parser · 70%
info
Tool: list_bots manifest_parser · 70%
info
Tool: get_bot_details manifest_parser · 70%
info
Tool: get_leaked_credentials_data manifest_parser · 70%
info
Tool: get_as112_data manifest_parser · 70%
info
Tool: list_geolocations manifest_parser · 70%
info
Tool: get_geolocation_details manifest_parser · 70%
info
Tool: get_tcp_resets_timeouts_data manifest_parser · 70%
info
Tool: get_annotations manifest_parser · 70%
info
Tool: get_outages manifest_parser · 70%
info
Tool: list_ct_authorities manifest_parser · 70%
info
Tool: get_ct_authority_details manifest_parser · 70%
info
Tool: list_ct_logs manifest_parser · 70%
info
Tool: get_ct_log_details manifest_parser · 70%
info
Tool: get_bgp_timeseries manifest_parser · 70%
info
Tool: get_bgp_top_ases manifest_parser · 70%
info
Tool: get_bgp_top_prefixes manifest_parser · 70%
info
Tool: get_bgp_moas manifest_parser · 70%
info
Tool: get_bgp_pfx2as manifest_parser · 70%
info
Tool: get_bgp_ip_space_timeseries manifest_parser · 70%
info
Tool: get_bgp_routes_realtime manifest_parser · 70%
info
Tool: get_as_set manifest_parser · 70%
info
Tool: get_as_relationships manifest_parser · 70%
info
Tool: list_tlds manifest_parser · 70%
info
Tool: get_tld_details manifest_parser · 70%
info
Tool: get_domains_ranking_timeseries manifest_parser · 70%
info
Tool: get_speed_histogram manifest_parser · 70%
info
Tool: get_internet_services_timeseries manifest_parser · 70%
info
Tool: get_outages_by_location manifest_parser · 70%
info
Tool: get_traffic_anomalies_by_location manifest_parser · 70%
info
Tool: get_bgp_routing_table_ases manifest_parser · 70%
info
Tool: get_bgp_top_ases_by_prefixes manifest_parser · 70%
info
Tool: get_bgp_rpki_aspa_snapshot manifest_parser · 70%
info
Tool: get_bgp_rpki_aspa_changes manifest_parser · 70%
info
Tool: get_bgp_rpki_aspa_timeseries manifest_parser · 70%
info
Tool: search_url_scans manifest_parser · 70%
info
Tool: create_url_scan manifest_parser · 70%
info
Tool: get_url_scan manifest_parser · 70%
info
Tool: get_url_scan_screenshot manifest_parser · 70%
info
Tool: get_url_scan_har manifest_parser · 70%
info
Tool: list_rags manifest_parser · 70%
info
Tool: search manifest_parser · 70%
info
Tool: ai_search manifest_parser · 70%
info
Tool: container_file_delete manifest_parser · 70%
info
Tool: container_file_write manifest_parser · 70%
info
Tool: container_files_list manifest_parser · 70%
info
Tool: container_file_read manifest_parser · 70%
info
Tool: dns_report manifest_parser · 70%
info
Tool: show_account_dns_settings manifest_parser · 70%
info
Tool: show_zone_dns_settings manifest_parser · 70%
info
Transport: streamable-http manifest_parser · 80%
info
Required env vars (2) manifest_parser · 80%
low
Tool 'r2_buckets_list' has no annotations annotation_checker · 100%
low
Tool 'r2_bucket_create' has no annotations annotation_checker · 100%
low
Tool 'r2_bucket_get' has no annotations annotation_checker · 100%
low
Tool 'r2_bucket_delete' has no annotations annotation_checker · 100%
low
Tool 'r2_metrics_list' has no annotations annotation_checker · 100%
low
Tool 'd1_databases_list' has no annotations annotation_checker · 100%
low
Tool 'd1_database_create' has no annotations annotation_checker · 100%
low
Tool 'd1_database_delete' has no annotations annotation_checker · 100%
low
Tool 'd1_database_get' has no annotations annotation_checker · 100%
low
Tool 'd1_database_query' has no annotations annotation_checker · 100%
low
Tool 'zones_list' has no annotations annotation_checker · 100%
low
Tool 'zone_details' has no annotations annotation_checker · 100%
low
Tool 'accounts_list' has no annotations annotation_checker · 100%
low
Tool 'set_active_account' has no annotations annotation_checker · 100%
low
Tool 'workers_get_worker' has no annotations annotation_checker · 100%
low
Tool 'workers_get_worker_code' has no annotations annotation_checker · 100%
low
Tool 'mcp_demo_day_info' has no annotations annotation_checker · 100%
low
Tool 'list_gateways' has no annotations annotation_checker · 100%
low
Tool 'list_logs' has no annotations annotation_checker · 100%
low
Tool 'get_log_details' has no annotations annotation_checker · 100%
low
Tool 'get_log_request_body' has no annotations annotation_checker · 100%
low
Tool 'get_log_response_body' has no annotations annotation_checker · 100%
low
Tool 'get_url_html_content' has no annotations annotation_checker · 100%
low
Tool 'get_url_markdown' has no annotations annotation_checker · 100%
low
Tool 'get_url_screenshot' has no annotations annotation_checker · 100%
low
Tool 'graphql_complete_schema' has no annotations annotation_checker · 100%
low
Tool 'list_autonomous_systems' has no annotations annotation_checker · 100%
low
Tool 'get_as_details' has no annotations annotation_checker · 100%
low
Tool 'get_ip_details' has no annotations annotation_checker · 100%
low
Tool 'get_traffic_anomalies' has no annotations annotation_checker · 100%
low
Tool 'get_internet_services_ranking' has no annotations annotation_checker · 100%
low
Tool 'get_domains_ranking' has no annotations annotation_checker · 100%
low
Tool 'get_domain_rank_details' has no annotations annotation_checker · 100%
low
Tool 'get_http_data' has no annotations annotation_checker · 100%
low
Tool 'get_dns_queries_data' has no annotations annotation_checker · 100%
low
Tool 'get_l7_attack_data' has no annotations annotation_checker · 100%
low
Tool 'get_l3_attack_data' has no annotations annotation_checker · 100%
low
Tool 'get_email_routing_data' has no annotations annotation_checker · 100%
low
Tool 'get_email_security_data' has no annotations annotation_checker · 100%
low
Tool 'get_internet_speed_data' has no annotations annotation_checker · 100%
low
Tool 'get_internet_quality_data' has no annotations annotation_checker · 100%
low
Tool 'get_ai_data' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_hijacks' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_leaks' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_route_stats' has no annotations annotation_checker · 100%
low
Tool 'get_bots_data' has no annotations annotation_checker · 100%
low
Tool 'get_certificate_transparency_data' has no annotations annotation_checker · 100%
low
Tool 'get_netflows_data' has no annotations annotation_checker · 100%
low
Tool 'list_origins' has no annotations annotation_checker · 100%
low
Tool 'get_origin_details' has no annotations annotation_checker · 100%
low
Tool 'get_origins_data' has no annotations annotation_checker · 100%
low
Tool 'get_robots_txt_data' has no annotations annotation_checker · 100%
low
Tool 'get_bots_crawlers_data' has no annotations annotation_checker · 100%
low
Tool 'list_bots' has no annotations annotation_checker · 100%
low
Tool 'get_bot_details' has no annotations annotation_checker · 100%
low
Tool 'get_leaked_credentials_data' has no annotations annotation_checker · 100%
low
Tool 'get_as112_data' has no annotations annotation_checker · 100%
low
Tool 'list_geolocations' has no annotations annotation_checker · 100%
low
Tool 'get_geolocation_details' has no annotations annotation_checker · 100%
low
Tool 'get_tcp_resets_timeouts_data' has no annotations annotation_checker · 100%
low
Tool 'get_annotations' has no annotations annotation_checker · 100%
low
Tool 'get_outages' has no annotations annotation_checker · 100%
low
Tool 'list_ct_authorities' has no annotations annotation_checker · 100%
low
Tool 'get_ct_authority_details' has no annotations annotation_checker · 100%
low
Tool 'list_ct_logs' has no annotations annotation_checker · 100%
low
Tool 'get_ct_log_details' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_timeseries' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_top_ases' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_top_prefixes' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_moas' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_pfx2as' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_ip_space_timeseries' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_routes_realtime' has no annotations annotation_checker · 100%
low
Tool 'get_as_set' has no annotations annotation_checker · 100%
low
Tool 'get_as_relationships' has no annotations annotation_checker · 100%
low
Tool 'list_tlds' has no annotations annotation_checker · 100%
low
Tool 'get_tld_details' has no annotations annotation_checker · 100%
low
Tool 'get_domains_ranking_timeseries' has no annotations annotation_checker · 100%
low
Tool 'get_speed_histogram' has no annotations annotation_checker · 100%
low
Tool 'get_internet_services_timeseries' has no annotations annotation_checker · 100%
low
Tool 'get_outages_by_location' has no annotations annotation_checker · 100%
low
Tool 'get_traffic_anomalies_by_location' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_routing_table_ases' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_top_ases_by_prefixes' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_rpki_aspa_snapshot' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_rpki_aspa_changes' has no annotations annotation_checker · 100%
low
Tool 'get_bgp_rpki_aspa_timeseries' has no annotations annotation_checker · 100%
low
Tool 'search_url_scans' has no annotations annotation_checker · 100%
low
Tool 'create_url_scan' has no annotations annotation_checker · 100%
low
Tool 'get_url_scan' has no annotations annotation_checker · 100%
low
Tool 'get_url_scan_screenshot' has no annotations annotation_checker · 100%
low
Tool 'get_url_scan_har' has no annotations annotation_checker · 100%
low
Tool 'list_rags' has no annotations annotation_checker · 100%
low
Tool 'search' has no annotations annotation_checker · 100%
low
Tool 'ai_search' has no annotations annotation_checker · 100%
low
Tool 'container_file_delete' has no annotations annotation_checker · 100%
low
Tool 'container_file_write' has no annotations annotation_checker · 100%
low
Tool 'container_files_list' has no annotations annotation_checker · 100%
low
Tool 'container_file_read' has no annotations annotation_checker · 100%
low
Tool 'dns_report' has no annotations annotation_checker · 100%
low
Tool 'show_account_dns_settings' has no annotations annotation_checker · 100%
low
Tool 'show_zone_dns_settings' has no annotations annotation_checker · 100%
high
Hardcoded OAuth client secret in packages/mcp-common/src/cloudflare-oauth-handler.spec.ts auth_checker · 95%
high
Hardcoded OAuth client secret in packages/mcp-common/src/cloudflare-auth.spec.ts auth_checker · 95%
high
Hardcoded OAuth client secret in packages/mcp-common/src/sentry.spec.ts auth_checker · 95%
high
Hardcoded OAuth client secret in apps/dns-analytics/worker-configuration.d.ts auth_checker · 95%
medium
Permission: network access detected permission_analyzer · 70%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
medium
Excessive dependency count: 206 direct dependencies dependency_analyzer · 90%
medium
Vulnerable dependency: turbo@2.5.0 (GHSA-3qcw-2rhx-2726) dependency_analyzer · 95%
medium
Vulnerable dependency: turbo@2.5.0 (GHSA-hcf7-66rw-9f5r) dependency_analyzer · 95%
medium
Vulnerable dependency: zx@8.5.4 (GHSA-w87r-vg9q-crqm) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.20.2 (GHSA-w48q-cv73-mx4w) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-9vqf-7f2p-gf9v) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-26pp-8wgv-hjvm) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-q5qw-h33p-qvwr) dependency_analyzer · 95%
medium
Vulnerable dependency: agents@0.2.19 (GHSA-cvhv-6xm6-c3v4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-p77w-8qqv-26rm) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.20.2 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: agents@0.2.19 (GHSA-w5cr-2qhr-jqc5) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-q7jf-gf43-6x6p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-v8w9-8mx6-g223) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-xf4j-xp2r-rqqx) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-w332-q679-j88p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-458j-xx4x-4375) dependency_analyzer · 95%
medium
Vulnerable dependency: agents@0.2.19 (GHSA-r7x9-8ph7-w8cg) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-3vhc-576x-3qv4) dependency_analyzer · 95%
medium
Vulnerable dependency: @cloudflare/vite-plugin@1.1.0 (GHSA-4pfg-2mw5-f8jx) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@6.3.4 (GHSA-4w7w-66w2-5vf9) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@6.3.4 (GHSA-93m4-6634-74q7) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@6.3.4 (GHSA-g4jq-h2w9-997c) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@6.3.4 (GHSA-jqfw-vq24-v9c3) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@6.3.4 (GHSA-p9ff-h696-f583) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-wmmm-f939-6g9c) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-hm8q-7f3q-5f36) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-r5rp-j6wh-rvv4) dependency_analyzer · 95%
medium
Vulnerable dependency: wrangler@4.10.0 (GHSA-36p8-mvp6-cv38) dependency_analyzer · 95%
medium
Vulnerable dependency: ai@4.3.10 (GHSA-rwvc-j5jr-mgvh) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-m732-5p4w-x69g) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-5pq2-9x2x-5p6w) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-92vj-g62v-jqhh) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.20.2 (GHSA-8r9q-7v3j-jr4g) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-f67f-6cw9-8mq4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-p6xx-57qc-3wxr) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-r354-f388-2fhh) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-xpcf-pg52-r92g) dependency_analyzer · 95%
medium
Vulnerable dependency: @hono/node-server@1.13.8 (GHSA-92pp-h63x-v22m) dependency_analyzer · 95%
medium
Vulnerable dependency: @hono/node-server@1.13.8 (GHSA-wc8c-qw6v-h7f6) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-69xw-7hcm-h432) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-6wqw-2p9w-4vw4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-9r54-q6cx-xmh5) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-gq3j-xvxp-8hrf) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.6 (GHSA-qp7p-654g-cw7p) dependency_analyzer · 95%
high
Authorization Bearer Token found in apps/demo-day/frontend/script.js secret_scanner · 70%
high
Hardcoded Password found in apps/workers-bindings/evals/hyperdrive.eval.ts secret_scanner · 65%
info
SLSA Build Level 1 detected slsa_assessor · 85%
info
Could not connect to MCP server for output poisoning scan output_poisoning · 100%
info
Could not connect to MCP server for behavioral verification behavioral_verifier · 100%
info
SBOM generated: 69 components sbom_generator · 100%
info
MITRE ATLAS technique coverage summary atlas_annotator · 100%
info
ATLAS: Adversarial ML Supply Chain (AML.T0043) atlas_annotator · 100%
info
ATLAS: Poison Training Data (AML.T0020) atlas_annotator · 100%