# Nexus Flow

> Runner shim: fetch, verify (sha256 + minisign), cache, and exec the signed nxs binary as an MCP server for hosts where nxs is not installed.

## Facts
- Page: https://tashan.sh/capability/pkg-nexus-flow-mcp
- tashan id: pkg:@nexus-flow/mcp
- npm: https://www.npmjs.com/package/@nexus-flow/mcp
- Type: npm
- Category: other
- tashan score: 69.0 / 100
- Adoption: 45.0
- Upkeep: 72.0
- Freshness: 96.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- npm downloads: 1,607/week
- License: Apache-2.0 OR MIT
- Official: no

## Install

```sh
claude mcp add nexus-flow-mcp -- npx -y @nexus-flow/mcp
```

## Security audit
- Known advisories: 0
- Install-time script: none declared
- Build provenance: not attested

Permissions are read from DECLARED dependencies only. Nothing is executed, so an empty result means "nothing declared", never "nothing possible".

---
Measured 2026-09-12 by tashan (https://tashan.sh) from public evidence. Scorer s5.
