No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by YanxingLiu · MCP Server · ★ 280
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is dify-mcp-server safe to install? View the security audit →
Model Context Protocol (MCP) Server for dify workflows A simple implementation of an MCP server for using dify. It achieves the invocation of the Dify workflow by calling the tools of MCP. 📰 News [2025/4/15] zNow supports directly using environment variables to pass and , making it more convenient to use with cloud-hosted platforms. 🔨Installation The server can be installed via Smithery or manually. Step1: prepare config.yaml or enviroments You can configure the server using either environment variables or a file. Method 1: Using Environment Variables (Recommended for Cloud Platforms) Set the following environment variables: : The base URL for your Dify API. : A comma-separated list of your Dify App Secret Keys (SKs). Each SK typically corresponds to a different Dify workflow you want to make available via MCP. Method 2: Using Create a file to store your Dify base URL and App SKs. Example : : The base URL for your Dify API.
| Stars | 280 |
| Forks | 39 |
| Language | Python |
| Category | MCP Server |
| Quality Score | 65.6918449239429/100 |
| Open Issues | 3 |
| Last Updated | 2025-04-20 |
| Created | 2024-12-25 |
| Platforms | mcp, python |
| Est. Tokens | ~3k |
Explore other popular mcp server tools:
dify-mcp-server is Model Context Protocol (MCP) Server for dify workflows. It is categorized as a MCP Server with 280 GitHub stars.
dify-mcp-server is primarily written in Python.
You can find installation instructions and usage details in the dify-mcp-server GitHub repository at github.com/YanxingLiu/dify-mcp-server. The project has 280 stars and 39 forks, indicating an active community.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: