Skip to content

Documentation MCP Server

Flyto Core

Deterministic execution engine for AI agents with 412 modules across 78 categories (browser, file, Docker, data, crypto, scheduling). Features execution trace, evidence snapshots, replay from any step, and supports both STDIO and Streamable HTTP transport.

Scan found nothing by flytohub261Apache-2.0PythonIntermediatestdio
View on GitHub Install Guide

Install

Claude Code

claude mcp add flyto-core -- uvx flyto-core

Safety Report

43% Scan found nothing
Scanned 5 months ago
3 passed 4 warnings
Security
Authentication
details

Authentication detected: env_api_key_py, env_required, bearer_check, auth_header, connection_string, oauth

Pass
CORS Policy
details

No CORS-relevant transport detected (likely stdio)

N/A
Rate Limiting
details

Rate limiting detected: rate_limit_middleware, throttle

Pass
Known CVEs
details

2 deps with known issues (medium)

Warning
Code Quality
Dependency Audit
details

2 deps with known issues (medium)

Warning
Dangerous Patterns
details

Dangerous patterns detected: eval_call

Warning
License
details

License: Apache-2.0

Pass
Community
Maintenance Status
details

Last commit 5 months ago

Warning

Learn about our security methodology →

Compatibility

Claude CodeFull support
Tested
CursorFull support
Tested
VS CodeFull support via Copilot
Tested
WindsurfFull support
Tested
Claude DesktopFull support
Tested

Frequently Asked Questions

What is Flyto Core?

Deterministic execution engine for AI agents with 412 modules across 78 categories (browser, file, Docker, data, crypto, scheduling). Features execution trace, evidence snapshots, replay from any step, and supports both STDIO and Streamable HTTP transport.

Is Flyto Core safe to use?

We cannot tell you that, and nobody scanning at this scale can. What we did in March 2026 was shallow-clone Flyto Core and run five keyword searches over its source: auth identifiers, CORS configuration, rate-limit identifiers, the dependency manifest against a hardcoded list of 18 known-vulnerable packages, and unguarded eval/exec calls. None of them matched. A text search cannot follow a variable, judge intent, or tell you what a server does once it is running, so "nothing matched" is not "safe". What the scan does and does not cover is written out at /mcp/security.

What are alternatives to Flyto Core?

Similar MCP servers include Figma Context MCP, Git MCP, Firebase MCP. Each serves a similar purpose but may differ in features, language, and compatibility.

Similar MCP Servers

Figma Context MCP

Not scanned
by GLips

Provide coding agents direct access to Figma data to help them one-shot design implementation.

documentation TypeScript stdio
claude mcp add glips-figma-context-mcp -- npx -y figma-context-mcp
13.7k 2 tools
View

Git MCP

Not scanned
by idosal

gitmcp.io is a generic remote MCP server to connect to ANY GitHub repository or project for documentation

documentation TypeScript stdio
claude mcp add git-mcp -- npx -y git-mcp
7.8k 4 tools
View

Firebase MCP

Scan found nothing
by firebase

Gives AI development tools Firebase-specific capabilities and expertise.

documentation TypeScript stdio
claude mcp add firebase-tools -- npx -y firebase-mcp
4.4k 39 tools
View
Was this helpful?

Free AI writing tools

Check a draft for AI tells, then fix what the check finds.

Stay Updated on MCP Servers

New servers, safety alerts, and install guides — weekly.