AIfra — temporary static previews MCP server
48-hour HTTPS previews of prebuilt static sites and HTML slides. No server builds or backends.
53 downloads/wk
Reviews
Write oneNobody has reviewed AIfra — temporary static previews yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
AIfra — temporary static previews tools (6, 4 write)
write = sends, deletes, buys or postscreate_previewwrite actionFreePrepare a new temporary static preview. Supply exactly one of small files, ZIP archive_base64, or an allowed provider ZIP file reference. No backend/build. Requires explicit consent; returns an approval link, not a published URL. User must confirm in their browser.
delete_previewwrite actionFreePrepare deletion of an existing preview. Does not delete until its owner confirms in the browser holding the management key.
get_deploy_instructionswrite actionFreeExplain remote browser-confirmed AIfra publication of ready static files, limits and current terms.
get_operation_statusFreeRead whether a prepared operation is pending, complete, failed or uncertain. Returns no file content or management key. Never assume pending means published.
get_preview_statusFreeRead public status, URL and original expiry of an existing preview.
update_previewwrite actionFreePrepare replacement of an existing temporary static preview. Supply exactly one of small files, ZIP archive_base64, or an allowed provider ZIP file reference. No backend/build. Requires explicit consent; returns an approval link, not a published URL. User must confirm in their browser. Requires the browser holding the existing management key; expiry is unchanged.
Public scan report
scanner v0.1.5 · 2026-09-19 · same rubric, same numbers if you re-run it
- Code scan4 source files scanned15/25
- Live reliabilityremote reachable in 2880ms17/20
- Tool poisoning6 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 4 write-action tools with no auth3/15
- Maintenanceno repository listed3/15
- Maintainer identityno repository or website to verify2/10
Findings (4)
- highWrite-action tools reachable without authentication
auth.open-write - mediumeval / new Function used
exec.evalaifra.cjs: …ode, sch); const makeValidate = new Function(`${names_1.default.self}`, `${names_1.de… - mediumHeavily hex-escaped string (obfuscation)
obf.hex-densityaifra.cjs: …]^_`abcdefghijklmnopqrstuvwxyz{|}~\u2302\xC7\xFC\xE9\xE2\xE4\xE0\xE5\xE7\xEA\xEB\xE8\xEF\xEE\xEC\xC4\xC5\xC9\xE6\xC6\xF4\xF6\xF2\xFB\xF9\xFF\xD6\xDC\xA2\xA3\xA5\u20A7\u0192\xE1\xED\xF3\xFA\xF1\xD1\xAA… - lowNo source repository listed
maint.no-repo
Grade history
- 2026-09-19restoreD → Cscore 55: Write-action tools reachable without authentication; eval / new Function used; Heavily hex-escaped string (obfuscation)
- 2026-09-19downgradeC → Dscore 49: eval / new Function used; Heavily hex-escaped string (obfuscation); No source repository listed
Install directly
claude mcp add --transport http aifra https://api.aifra.ru/mcp
AIfra — temporary static previews: common questions
- Is AIfra — temporary static previews MCP server safe?
- With care: it is graded C, so read the findings first (55/100). Read the AIfra — temporary static previews safety report
- How do I install AIfra — temporary static previews?
- It runs remotely at api.aifra.ru. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does AIfra — temporary static previews need an API key?
- No secret keys are declared. It reads 2 settings from the environment.
- Is AIfra — temporary static previews maintained?
- The latest release is v0.2.0-beta.3.
- Is AIfra — temporary static previews up?
- 100% of our last 6 checks got an answer. We check remote servers about four times a day.