Embeds a self-hosted VS Code workbench in an MCP App, enabling collaborative editing, terminals, diagnostics, and commands in a shared workspace.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
flujo-app
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
COMSPECMCP_VSCODE_BRIDGE_TOKENMCP_VSCODE_BRIDGE_URLMCP_VSCODE_DISABLE_PTYMCP_VSCODE_OPENVSCODE_ROOTPlatform runtime package or bundled runtime Override the OpenVSCode runtime directory. --openvscode-root takes precedence.MCP_VSCODE_REAL_RUNTIME_ROOTMCP_VSCODE_RENDER_MODEstream Only when =stream A reachable WebSocket allowed by connectDomains; no nested-frame grant Genuine OpenVSCode rendered by server-side Chromium and drawn as pixels in the MCP AppMCP_VSCODE_STREAM_BROWSERdiscovers an existing Microsoft Edge, Google Chrome, or Chromium installation, or uses ;MCP_VSCODE_STREAM_NO_SANDBOX1 weakens defense in depth and should not be the default answer to a container configuration problem.MCP_VSCODE_WORKSPACEProcess working directory Absolute workspace root. Prefer setting this explicitly. --workspace takes precedence.SHELLShell command execution
4 child_process/subprocess calls in production code — runs shell commands (src/core/process.ts:26, src/core/terminal.ts:77, src/runtime/openvscode.ts:122)
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Domain consistency
npm scope @mario.andreschak doesn't match GitHub owner flujo-app
Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/flujo-app-mcp-vscode-mcpapp-1jceyr)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check