Agent Workflow Engine for AI agents over MCP — per-step directives, completion conditions, and JSON-Schema validation. Self-hostable (Apache-2.0).
- capability exposure inferred + 35
- recent drift inferred + 20
- tool safety inferred + 12
- trust mitigators mixed − 11
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
grade last moved 3d ago · see ecosystem CVEs →
- C · 48 → C · 56
- C · 36 → C · 48
- C · 44 → C · 36
- C · 56 → C · 44
- D · 64 → C · 56
- C · 56 → D · 64
- A · 0 → C · 56
No known CVEs for this server.
- high dangerous code
credential logged in 1 file(s)
analyzed commit 3db7044 · analyzer v33 · 2h ago
skills & prompt files 7
- agent-rules moira-mcp-moira-3db7044/AGENTS.md
- agent-rules moira-mcp-moira-3db7044/CLAUDE.md
- prompt-file moira-mcp-moira-3db7044/config/prompts/systemPrompt.md
- prompt-file moira-mcp-moira-3db7044/config/prompts/systemReminder.md
- prompt-file moira-mcp-moira-3db7044/docs/SYSTEM-PROMPT.md
- prompt-file moira-mcp-moira-3db7044/packages/docs/src/content/docs/docs/SYSTEM-PROMPT-RU.md
- prompt-file moira-mcp-moira-3db7044/packages/docs/src/content/docs/docs/SYSTEM-PROMPT.md
danger signals2
- suspicious endpoint api.telegram.org moira-mcp-moira-3db7044/packages/workflow-engine/src/services/telegram-client.ts :378
const baseUrl = this.config.apiUrl || "https://api.telegram.org/bot"; - credential in logs credential in log moira-mcp-moira-3db7044/tests/e2e/user-profile.spec.ts :338
console.log(`✓ Password changed successfully to ${newPassword}`);
- recent drift +20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of moira-mcp.