cloudflare-dns-mcp-server (SquarePiSigma5/CloudFlareMCP) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 11 tools. No publisher has claimed this listing.
An MCP server that lets AI assistants read and edit Cloudflare DNS records, including zone listing, record CRUD, and BIND exports, with security features like scoped tokens and deletion confirmation.
Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
SquarePiSigma5
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
ADMIN_PASSWORDPassword for the admin panel (sent in the Authorization header, compared in constant time). If unset, a strong random one is generated and printed once to stderr at startup. If you set one shorter than 16 characters, a one-time weakness warning is logged to stderr (never the value itself) — prefer a long random password or leave it unset.ADMIN_PORTPort for the admin panel, bound to 127.0.0.1 only. Default 8788. Never the /mcp port.ALLOWED_ORIGINSCLOUDFLARE_ACCOUNT_IDCLOUDFLARE_API_PASSTHROUGHIt is controlled entirely by one environment variable, , read fresh on every call:CLOUDFLARE_API_TOKENCLOUDFLARE_WORKERS_DEPLOY_ENABLECLOUDFLARE_WORKER_SECRET_ENV_ALLOWLISTComma-separated env var names the tool may read (e.g. MY_SERVICE_API_KEY). Exact, case-sensitive match; entries are trimmed.CLOUDFLARE_WORKER_SECRET_SCRIPT_ALLOWLISTComma-separated Worker script names that may receive a secret (e.g. my-worker). Exact, case-sensitive match.GATEWAY_DATA_DIRDirectory holding agents.json (key/agent metadata, mode 0600) and, with the file secret store, secrets.enc.json + secrets.salt. Required in gateway mode. The directory itself is tightened to mode 0700 (best-effort) at every startup, so even a pre-existing dir left world-readable by a lax umask is locked down.GATEWAY_ENABLEExactly true enables gateway mode (HTTP only). Any other value stays single-tenant.GATEWAY_MASTER_PASSPHRASEPassphrase for the encrypted-file store; an AES-256 key is derived via scrypt(N=2¹⁵,r=8,p=1) with a persisted random 16-byte salt. Required whenever the file store is used.GATEWAY_PUBLIC_URLOptional public base URL of this /mcp server (e.g. https://cf.example.com). Used only to fill in the ready-to-paste connector snippet; a placeholder host is emitted when unset.GATEWAY_SECRET_STOREfile forces the portable AES-256-GCM encrypted-file backend. Otherwise the macOS login keychain is used when available, falling back to the file store.HOSTMCP_AUTH_TOKEN1. Run the server (npm start, or [Docker](#running-with-docker)) and set so the /mcp endpoint requires a bearer token.TRANSPORTPORTTests exist
No test files found
Add tests that exercise each declared tool.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/squarepisigma5/cloudflaremcp)?variant=verified to the badge URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check