| Tool | What it does |
|---|---|
optimize_prompt | Optimize a prompt with deterministic, verified transforms (duplicates, filler, optional sections). Every candidate is checked to preserve all sentences, requirements, code, and variables; the original is kept if nothing is better. Returns the selected prompt, token savings, quality score, and what changed. |
optimize_prompt_pipeline | Run the optimization pipeline and return per-stage results plus token and estimated cost metrics, in the result shape used by the PromptFlow VS Code extension. |
compress_prompt | Remove exact duplicate sentences and extra whitespace without rewriting any wording. |
validate_prompt | Check a prompt for missing objective or output format, ambiguity, conflicting instructions, duplicates, prompt-injection patterns, secrets, and undelimited variables. isValid is false only when a critical issue exists. |
estimate_tokens | Count tokens and estimate input cost for a model. "exact" is true only for OpenAI models with a loaded tokenizer; other providers are approximate. Costs are estimates from a reference price table. |
analyze_prompt | Detect intent, task type, technical domain, requested output, requirements, and entities (languages, frameworks, file paths, identifiers). |
extract_entities | Extract languages, frameworks, libraries, cloud platforms, services, technologies, file paths, identifiers, URLs, and commands. |
summarize_context | Extractive summary: the first N unique, non-empty sentences of a context block, in order. Does not rank or rewrite. |
score_prompt | Score prompt quality 0-100: 100 minus a penalty per issue (critical 30, warning 10, info 3; capped at 50 with any critical issue), with per-dimension scores and suggestions. |
evaluate_prompt | Full quality report: overall score, grade, eight quality dimensions with the checks that failed, and every finding with why it matters and how to fix it. |
compare_prompts | Compare two prompts: token and estimated cost delta, quality delta per dimension, and which findings were resolved or introduced. |
scan_prompt_security | Prompt-injection risk (0-100, signature-based, with threat ids), sensitive-data counts by category, undelimited template variables, and destructive operations. Never returns detected secret values. |
scan_sensitive_data | Scan text for credentials, cloud secrets, and PII with local deterministic detectors. Returns offsets and per-category counts, never the sensitive values. |
sanitize_prompt | Replace detected sensitive data with placeholders such as [REDACTED_API_KEY]. Returns the sanitized text and counts, never the original values. Use before sending a prompt to an external model. |
restructure_prompt | Turn a loosely written request into a sectioned engineering prompt: Role, Objective, Context, Requirements, Constraints, Edge cases, Testing, Acceptance criteria, Expected output. Only sections with content appear. The author's clauses are kept and reordered; for software tasks, fixed engineering guidance chosen by intent and topic is added, and every line is labeled "prompt" or "engine" so additions can be reviewed. Set scaffold=false to reorganize without adding guidance. |
Agent integration
MCP server for prompt analysis
Connect PromptFlowEngine with AI agents and MCP-compatible workflows. Your assistant can analyze, restructure, optimize, and sanitize a prompt as a step in its own work.
- stdio transport
- Read-only tools
- Build from source
What it does
The Model Context Protocol is a standard way for an AI application to call external tools. PromptFlowEngine ships an MCP server that exposes the engine as tools, so an agent in GitHub Copilot, Claude Desktop, Claude Code, Cursor, or your own client can use it without custom glue.
The server runs on your machine as a child process of the client and talks JSON-RPC over stdio. It reads only the arguments it is given, makes no network calls, and has no file or shell tools. Every tool is annotated read-only and idempotent.
There is no hosted endpoint and no authentication to set up. The npm package is not published yet, so you build the server from the repository and point your client at the built file. For remote use, call the HTTP API.
Practical example
The tools your agent gets
This list is rendered from the server's own tool registry when the page is built, so it matches what a client sees after connecting.
{
"servers": {
"promptflow": {
"type": "stdio",
"command": "node",
"args": ["/absolute/path/to/checkout/packages/mcp-server/dist/bin.js"]
}
}
}Use promptflow to restructure this before you start:
"fix login issue and make google login work and don't break anything"15 tools, all read-only. Other clients use the same command under an mcpServers key.
Key benefits
One configuration, many clients
The same server entry works in any client that supports stdio MCP servers.
Safe to give an agent
No file, shell, or network access, so a prompt-injected agent cannot use it to reach anything.
Deterministic tool results
An agent that calls a tool twice with the same arguments gets the same answer.
Errors agents can act on
Bad arguments return a tool error with the reason, so the agent can correct and retry.
Features
Prompt tools
Analyze, validate, optimize, restructure, compare, estimate tokens, scan, and sanitize.
Resources
The rule catalogue and the model catalogue are readable as MCP resources.
A review prompt
A built-in MCP prompt asks the assistant to evaluate and optimize a prompt passed as data.
Size limits
A configurable cap on the characters accepted per argument.
Content-free logging
Debug logs record tool name, input size, outcome, and duration, never the text.
Bundled in VS Code
The VS Code extension registers the server for you on activation.
Who it is for
- Developers using coding agentsHave the agent restructure a vague task into a specification before it starts editing files.
- People building agentsGive an agent a deterministic way to check and sanitize prompts it writes for sub-agents or other models.
- Teams standardizing on MCPAdd prompt quality and secret detection to every MCP client with one server entry.
Use cases
- 01
Specify before coding
Ask the agent to restructure the task with promptflow first, then implement against the acceptance criteria.
- 02
Sanitize before delegating
Have an orchestrating agent sanitize context before passing it to another model or tool.
- 03
Check generated prompts
When an agent writes a prompt for a sub-task, validate it and fix critical findings automatically.
- 04
Budget tokens
Let the agent estimate tokens for a draft before it decides how much context to include.
Frequently asked questions
What is an MCP server?
An MCP server is a program that offers tools, resources, and prompts to an AI application over the Model Context Protocol. The AI application, called the client, decides when to call them.
Which MCP clients does it work with?
Any client that can start a local stdio server, including GitHub Copilot agent mode in VS Code, Claude Desktop, Claude Code, and Cursor.
Is there a hosted or remote MCP endpoint?
No. The transport is stdio only and the server runs on your machine. For remote access, use the HTTP API.
Can the server read my files?
No. It has no file, shell, or network tools. It processes only the text passed to a tool as an argument.
Related PromptFlowEngine capabilities
Every product runs the same engine, so they combine without surprises.
- IntegrationHTTP APIIntegrate prompt analysis and optimization directly into your applications.
- IntegrationVS Code ExtensionBring PromptFlowEngine prompt optimization directly into your development workflow.
- ToolPrompt SecurityDetect injection phrases, leaked secrets, and personal data, then redact them.
- DocumentationMCP client documentationReference and setup details.
- DocumentationVS Code extensionReference and setup details.
Learn the technique behind it
Guides from the prompt engineering knowledge center that explain the ideas this product applies.
- GuideWhat is MCP? The Model Context Protocol explainedHow MCP connects AI applications to tools and data, its building blocks, and its security model.
- GuidePrompts for AI agents: instructions, tools, and workflowsAgent instructions, tool descriptions, context management, and when a workflow beats an agent.
- GuideReAct prompting: reasoning and acting with toolsHow the reason, act, observe loop works, with a prompt example and the usual failure modes.
One engine, wherever you work with AI.
Free, deterministic, and private. No sign-up.