@cloudflare/mcp-server-cloudflare
MCP server for interacting with Cloudflare API
Installing this server brings 26 third-party packages inside your agent's trust boundary (8 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.
1 package in this tree runs a script at install time.
Findings (1)
- LOW
NO_REPO— @cloudflare/mcp-server-cloudflare has no linked source repository. Unverifiable source. Prefer packages with a public repo.
Embed this badge
[](https://vulnrable.com/mcp/cloudflare--mcp-server-cloudflare/) Automated registry-metadata scan; not a code audit. Rescanned on each site deploy.