spiceflow — security grade SAFE, quality 67/100

Security audit verdict: SAFE · quality 67/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by remorses · MCP Server · ★ 167

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is spiceflow safe to install? View the security audit →

About spiceflow

spiceflow type safe API and React Server Components framework for Node, Bun, and Cloudflare Spiceflow is a type-safe API framework and full-stack React RSC framework focused on absolute simplicity. It works across all JavaScript runtimes: Node.js, Bun, and Cloudflare Workers. Read the source code on GitHub. Features Full-stack React framework with React Server Components (RSC), server actions, layouts, and automatic client code splitting Works everywhere: Node.js, Bun, and Cloudflare Workers with the same code Type safe schema based validation via Zod Type safe fetch client with full inference on path params, query, body, and response Simple and intuitive API using web standard Request and Response Can easily generate OpenAPI spec based on your routes Support for Model Context Protocol to easily wire your app with LLMs Supports async generators for streaming via server sent events Modular design with for mounting sub-apps Built-in OpenTelemetry tracing with zero overhead when disabled Installation [!IMPORTANT] Spiceflow is still in pre-release. Install with , not . AI Agents To let your AI coding agent know how to use spiceflow

honomcpreactrscvite

Quick Facts

Stars167
Forks7
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score66.5835020163023/100
Open Issues7
Last Updated2026-09-20
Created2023-07-24
Platformscli, mcp, node
Est. Tokens~26k

spiceflow alternative? Top 6 similar tools

Looking for a spiceflow alternative? If you're comparing spiceflow with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • mcp-manager by amxv · ⭐ 291

    simple web ui to manage mcp (model context protocol) servers in the claude app

  • excalimate by excalimate · ⭐ 67

    Create keyframe animations from hand-drawn Excalidraw diagrams — timeline editor, camera animation, sequence r

  • context-space by context-space · ⭐ 812

    Ultimate Context Engineering Infrastructure, starting from MCPs and Integrations

  • opencode-studio by Microck · ⭐ 789

    web GUI for securely managing local OpenCode configuration

  • vibe by mondaycom · ⭐ 675

    🎨 Vibe Design System - Official monday.com UI resources for application development in React.js

  • ethora by dappros · ⭐ 542

    Open-source engine for chat 💬, AI assistants 🤖 & wallets 🪪. React, Typescript, Python, XMPP. Build future a

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is spiceflow?

spiceflow is Minimal API & React framework, fully type safe, OpenAPI, RSC, MCP, type safe client, streaming with SSE. It is categorized as a MCP Server with 167 GitHub stars.

What programming language is spiceflow written in?

spiceflow is primarily written in TypeScript. It covers topics such as hono, mcp, react.

How do I install or use spiceflow?

You can find installation instructions and usage details in the spiceflow GitHub repository at github.com/remorses/spiceflow. The project has 167 stars and 7 forks, indicating an active community.

What license does spiceflow use?

spiceflow is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to spiceflow?

The top alternatives to spiceflow on Agent Skills Hub include mcp-manager, excalimate, context-space. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools