io.github.flowpackplugin/flowpack

MCPcommunitylive
v2.0.0io.github.flowpackpluginUnknownUpdated 1mo ago

Flowpack: Shopify design catalog — badge/button/bar looks, honest-urgency presets, diagnosis.

Endpoint healthlive
checked 9 days ago · 478ms
100% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1mo agoLast update
Package
Authorio.github.flowpackplugin
LicenseUnknown
Version2.0.0
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface5 tools · none privileged
Security scan✓ Cleanvlive · 9d agoHow well does this scan work?
EvalsNone
IndexedAug 11, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

5 tools · none privileged
Observed live from the vendor's endpoint9d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://flowpack-mcp.flowpackplugin.workers.dev/mcp5 tools · 478ms
browseUniversal catalog reader. Routes by domain ('kits', 'presets', 'palettes', 'seasonal', 'settings', 'decorations', 'effects', 'diagnostics', 'anatomy', 'compatibility') with optional facet filter (e.g., 'button.hover') and free-text query. Returns paged items with id/name/description and metadata-on…

Universal catalog reader. Routes by domain ('kits', 'presets', 'palettes', 'seasonal', 'settings', 'decorations', 'effects', 'diagnostics', 'anatomy', 'compatibility') with optional facet filter (e.g., 'button.hover') and free-text query. Returns paged items with id/name/description and metadata-on…

ParameterTypeDescription
domain*string—
querystring—
facetstring—
pageinteger—
page_sizeinteger—
planMASTER KEY tool. Analyzes natural-language merchant intent ('make my buttons feel premium', 'wellness brand vibe', 'BFCM aggressive') and returns a structured plan of settings to change across Flowpack's Button + Cart + Badge + Variant + Frosty Pill kits. Handles single tweaks (one hover style) and…

MASTER KEY tool. Analyzes natural-language merchant intent ('make my buttons feel premium', 'wellness brand vibe', 'BFCM aggressive') and returns a structured plan of settings to change across Flowpack's Button + Cart + Badge + Variant + Frosty Pill kits. Handles single tweaks (one hover style) and…

ParameterTypeDescription
intent*stringNatural-language merchant intent
contextobject—
explainNatural-language explanation of a plan_id (what it does) or setting_path (what one setting controls). Audience: merchant (default), developer, or reviewer. Detail: brief (1-2 sentences) or deep (full context + related settings + a11y notes). Use when merchant asks 'what does this do' or 'why this p…

Natural-language explanation of a plan_id (what it does) or setting_path (what one setting controls). Audience: merchant (default), developer, or reviewer. Detail: brief (1-2 sentences) or deep (full context + related settings + a11y notes). Use when merchant asks 'what does this do' or 'why this p…

ParameterTypeDescription
plan_idstring—
setting_pathstring—
audiencestring—
detailstring—
recommendGoal-oriented recommendation engine. Scenarios: 'personalized_4_plans' (returns 4 diverse plans — safe / aspirational / seasonal / conversion-tested), 'preset_for_brand', 'color_palette_for_theme', 'touch_target_for_devices', 'motion_density_for_audience', 'seasonal_for_calendar', 'diagnostics_firs…

Goal-oriented recommendation engine. Scenarios: 'personalized_4_plans' (returns 4 diverse plans — safe / aspirational / seasonal / conversion-tested), 'preset_for_brand', 'color_palette_for_theme', 'touch_target_for_devices', 'motion_density_for_audience', 'seasonal_for_calendar', 'diagnostics_firs…

ParameterTypeDescription
scenario*string—
contextobject—
diagnoseRuntime + theme + settings harmony check. Free-text symptom (e.g., 'cart drawer feels slow', 'badges not appearing') OR kit-scoped check. Returns categorized issues (theme_compat / settings_conflict / runtime_error / a11y / performance) with severity and optional fix_plan_id callable via execute().…

Runtime + theme + settings harmony check. Free-text symptom (e.g., 'cart drawer feels slow', 'badges not appearing') OR kit-scoped check. Returns categorized issues (theme_compat / settings_conflict / runtime_error / a11y / performance) with severity and optional fix_plan_id callable via execute().…

ParameterTypeDescription
symptomstring—
kitstring—
deepbooleanRun full theme compat sweep (slower)

5 of 5 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Flowpack: Shopify design catalog — badge/button/bar looks, honest-urgency presets, diagnosis.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.