Back to Browse

Agi Site MCP Server

Developer ToolsModerate6.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

BPJ startup cases, launch signals and validation plans. Free preview; member tools use scoped keys.

About

BPJ startup cases, launch signals and validation plans. Free preview; member tools use scoped keys.

Remote endpoints: streamable-http: https://baipiaoji.com/api/startup-mcp

Security Report

6.2
Moderate6.2Moderate Risk

This is a static site builder (baipiaoji) with multiple MCP servers as subprojects. The codebase demonstrates good security practices overall: no hardcoded credentials, proper use of environment variables for configuration, and careful data handling. However, there are several low-to-medium severity code quality concerns including broad exception handling, missing input validation in some contexts, and verbose inline scripts that could be optimized. Permissions are appropriate for a developer tools category project focused on site building and API integration. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

4 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

agi-site — one public monorepo, N sites

Public monorepo for the site fleet (owner decision 2026-08-19). Public repos get free GitHub Actions minutes, which ends the account-wide 2,000 min/month problem that froze every private-repo schedule on 2026-08-18.

SiteDirectoryDeploys toStatus
agiscorecard.comsites/agiscorecard/Cloudflare Worker agiscorecardlive from this repo (2026-08-19, deploy green)
baipiaoji.comsites/baipiaoji/Cloudflare Pages aiyangmaolive from this repo (2026-08-19, deploy green)
getecoback.comsites/getecoback/Cloudflare Workerlive from this repo (2026-08-19, deploy green)
thedollscout.comsites/thedollscout/Cloudflare Pages dollscoutlive from this repo (2026-08-19, deploy green)

Each site keeps its own CLAUDE.md, tooling and conventions inside its directory. Root workflows are path-filtered: a commit only deploys the site it touches. History note: each site was imported as a fresh snapshot; pre-import history lives in the original private repos (f-tiger/agiscorecard, f-tiger/aitools, f-tiger/rearchfuture, f-tiger/sexweb), which are archives now — do not push site content there.

Privacy rule for this PUBLIC repo: no owner personal archive (owner-identity*/owner-trajectory*), no subscriber addresses, no tokens/keys. See CLAUDE.md.

One practical workflow check

Compare coding assistants on a small CRM workflow: a free local exercise covering duplicate events, retries, credential errors and ambiguous timeouts. Synthetic data only; no account or API key required. For a task that remains stuck, use the linked public workflow-question form with a sanitized example. This is a technical help entry, not a checkout.

Owner TODO (one-time, optional but recommended)

  1. Cloudflare dashboard → Workers agiscorecard → disconnect the old git integration to f-tiger/agiscorecard (that repo is archived; a stray push there would roll the site back). Until then: simply never push there.
  2. CLOUDFLARE_API_TOKEN_ZONE configured 2026-08-19 — tds-traffic and tds-crawl-log schedules are live. Still open, optional (owner deferred GA4 on 2026-08-19; D1 is the primary channel):
    • bpj-growth-loop.yml: GA4_PROPERTY_ID_BPJ, GA4_SERVICE_ACCOUNT_JSON
    • GA4 steps inside tds-traffic.yml: GA4_PROPERTY_ID_TDS, GA4_SERVICE_ACCOUNT_JSON (they no-op gracefully until then)
    • optional senders: TELEGRAM_BOT_TOKEN/TELEGRAM_CHAT_ID (tds grow notify), RESEND_API_KEY/SUPABASE_SERVICE_KEY (eco heat-alert real sends), MCP_REGISTRY_PRIVATE_KEY (tds registry proof) Copy the values from the old private repos' Settings → Secrets (names unchanged).

Reviews

No reviews yet

Be the first to review this server!