github re-analysis due unconfirmed MCP

corespeed-io/zypher-agent

github

A minimal yet powerful framework for creating AI agents with full control over tools, providers, and execution flow.

maintainer
corespeed-io
license
Apache-2.0
first seen
2026-06-01
last seen
2026-06-04
releases · 30d
0
short id

Drift inferred · capture-to-capture

No drift recorded — single capability capture; advisories appear once its surface changes.

capabilities 0 tools
transport counts 0 tools · 0 res · 0 prompts permission surface via code analysis

no tools enumerated yet for this server.

skills & danger signals github-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed commit 02526a0 · analyzer v17 · 2d ago

skills & prompt files 1

code evidence vui/v0.3.3 · github-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

shell / exec 1

  • shell corespeed-io-zypher-agent-02526a0/packages/agent/tools/run_terminal_cmd_tool.ts :8 import { exec, spawn } from "node:child_process";

network 1

  • net corespeed-io-zypher-agent-02526a0/packages/ui/task_api_client.ts :185 const response = await fetch(`${this.#options.baseUrl}/messages`, {

secrets 1

  • secrets corespeed-io-zypher-agent-02526a0/packages/agent/llm/cloudflare.ts :97 * apiToken: process.env.CF_AIG_API_TOKEN,

declared dependencies 17

  • @ag-ui/client@^0.0.42
  • @copilotkit/react-core@^1.50.1
  • @copilotkit/react-ui@^1.50.1
  • @copilotkit/runtime@^1.50.1
  • next@16.1.1
  • react@^19.2.3
  • react-dom@^19.2.3
  • zod@^4.3.4
  • @tailwindcss/postcss@^4.1.18
  • @types/node@^25.0.3
  • @types/react@^19.2.7
  • @types/react-dom@^19.2.3
  • concurrently@^9.2.1
  • eslint@^9.39.2
  • eslint-config-next@16.1.1
  • tailwindcss@^4.1.18
  • typescript@^5.9.3