原生 macOS AI 安全智能体:漏洞情报、知识图谱、多语言代码审计与报告交付 | SwiftUI + FastAPI + LangGraph
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
FuNianTongXue
Source: github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
SECFLOW_DEV_BACKEND_URLTAURI_ENV_DEBUGSECFLOW_CODE_SCAN_MCP_TOKENSECFLOW_CODE_SCAN_MCP_ALLOWED_TOOLSSECFLOW_CODE_SCAN_MCP_STARTUP_TIMEOUT_SECONDSSECFLOW_CODE_SCAN_MCP_READ_TIMEOUT_SECONDSSECFLOW_CODE_SCAN_MCP_TRANSPORTSECFLOW_CODE_SCAN_MCP_COMMANDSECFLOW_OSI_LICENSE_API_TIMEOUT_SECONDSWINDIRSECFLOW_TRANSLATION_MAX_TOKENSSECFLOW_SEMGREP_BIN应用内 CLI 开发环境覆盖 Semgrep 可执行文件路径SECFLOW_SEMGREP_VALIDATE_TIMEOUT_SECONDSSECFLOW_SEMGREP_TIMEOUT_SECONDS180 冻结评测和兼容调用的单次静态分析总超时;普通项目上传不应用SECFLOW_SEMGREP_RULE_TIMEOUT_SECONDS15 冻结评测和兼容调用的单规则单文件超时;普通项目上传使用 0(无限制)SECFLOW_SEMGREP_DISABLE_CLISECFLOW_BUNDLED_SEMGREP_BINSECFLOW_SCAN_TEMP_ROOTSECFLOW_SEMGREP_RULES内置规则目录 开发环境覆盖离线多语言规则目录或单个规则文件SECFLOW_STATIC_MAX_FINDINGSSECFLOW_CATALOG_TRANSLATION_BACKOFF_SECONDSSECFLOW_INFORMATION_REFRESH_WORKERSSECFLOW_WECHAT_RSS_HOST_CONCURRENCYSECFLOW_INFORMATION_CACHE_ITEMSSECFLOW_INFORMATION_TIMEOUT_RETRIESSECFLOW_INFORMATION_TIMEOUT_SECONDSSECFLOW_INFORMATION_CONNECT_TIMEOUT_SECONDSSECFLOW_INFORMATION_BACKOFF_SECONDSSECFLOW_INFORMATION_LOGO_PRECACHE_TOTALSECFLOW_INFORMATION_IMAGE_LOOKUPS_PER_SOURCESECFLOW_INFORMATION_IMAGE_LOOKUPS_TOTALSECFLOW_INFORMATION_IMAGE_TIMEOUT_SECONDSSECFLOW_INFORMATION_IMAGE_RETRY_SECONDSSECFLOW_INFORMATION_CACHE_SECONDSSECFLOW_VULNERABILITY_CATALOG_PATHSECFLOW_LEGACY_DATA_DIRSECFLOW_BACKGROUND_STARTUP_DELAY_SECONDSSECFLOW_ENABLE_LLM_SUMMARY_TRANSLATIONSECFLOW_DEPENDENCY_SECONDARY_ENRICHMENTSECFLOW_DEPENDENCY_RECORD_LIMITSECFLOW_DEPENDENCY_QUERY_LIMITSECFLOW_JAVA_FLOW_DISABLE_CHUNKINGSECFLOW_LLM_PROVIDER未设置时按密钥推断 LLM Provider 名称;内置 Sub2API,也支持 DeepSeek、OpenAI、Ollama、vLLM 等DEEPSEEK_API_KEYSECFLOW_LLM_API_KEY 空 LLM API Key,也可使用 或 OPENAI_API_KEYSECFLOW_LLM_API_KEY空 LLM API Key,也可使用 DEEPSEEK_API_KEY 或 OPENAI_API_KEYOPENAI_API_KEYSECFLOW_LLM_API_KEY 空 LLM API Key,也可使用 DEEPSEEK_API_KEY 或SECFLOW_LLM_ENDPOINT按 Provider 推断 OpenAI-compatible API Base URL,例如 https://api.deepseek.com/v1DEEPSEEK_BASE_URLOPENAI_BASE_URLSECFLOW_LLM_MODEL按 Provider 推断 模型名称;Sub2API 默认为 gpt-5.6-solDEEPSEEK_MODELOPENAI_MODELSECFLOW_LLM_NAMESECFLOW_LLM_MAX_TOKENS1800 单次回答最大 token 数SECFLOW_LLM_TEMPERATURE0.25 模型温度SECFLOW_LLM_TOP_PSECFLOW_LLM_TIMEOUT_MS60000 模型请求超时时间SECFLOW_LLM_WIRE_APIProvider 默认值 chat 或 responses;Sub2API 默认为 responsesSECFLOW_LLM_REASONING_EFFORTProvider 默认值 Responses 推理强度;Sub2API 默认为 xhighSECFLOW_LLM_DISABLE_RESPONSE_STORAGEfalse 设为 true 时向 Responses API 发送 store: falseSECFLOW_MEMORY_LOCAL_ONLYtrue 强制按用户使用本地 JSON 摘要记忆;设为 false 才允许 PostgreSQLSECFLOW_STORAGE_MASTER_KEYSECFLOW_DISABLE_DPAPISECFLOW_SECURITY_CLISECFLOW_DISABLE_KEYCHAINSECFLOW_KEYCHAIN_SERVICEcom.secflow.ai.mac.intelligence 本地加密主密钥使用的 macOS Keychain 服务名SECFLOW_STORAGE_KEY_FILESECFLOW_DATA_DIR/opt/secflow-knowledge/data \SECFLOW_APP_VERSIONSECFLOW_APP_RELEASE_CHANNELSECFLOW_PAYMENT_WEBHOOK_SECRET空 支付回调 HMAC-SHA256 验签密钥;未配置时回调接口返回不可用SECFLOW_TRIAL_REGISTRY_KEYSECFLOW_TRIAL_REGISTRY_VALUESECFLOW_TRIAL_ENABLED空 打包版内部开关;启用后由后端执行试用限制COMPUTERNAMESECFLOW_TRIAL_DURATION_HOURS72 试用时长;当前 Tauri 与兼容版试用构建脚本均固定写入 168(7 天)GITHUB_TOKENSECFLOW_TASK_EXECUTION_MODESECFLOW_TASK_STORE_PATHSECFLOW_TASK_WORKER_COUNTSECFLOW_ENABLE_LLM_CARD_TRANSLATIONSECFLOW_ENABLE_LLM_DESCRIPTION_TRANSLATIONSECFLOW_DISABLE_BATCH_SCHEDULERDATABASE_URLPOSTGRES_DSNTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
17/17 tools missing one or more hints — scan_language (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_scan_capabilities (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); build_component_vulnerability_detail (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +14 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
No eval / new Function
1 eval() or new Function() call — dynamic code execution
Replace eval / Function with explicit parsing or safer alternatives.
Readable source code
1 file appear obfuscated
Ship unminified, readable source.
Secrets not written to files
2 secret values written to files
Avoid persisting secrets to disk. Keep them in memory or your secret manager.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/funiantongxue-secflow-knowledge-security-assistant-brf9w7)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check