Atlas / MCP servers / 1mcp-app / One MCP

One MCPBLOCK

mcp/1mcp-app/one-mcp

A unified Model Context Protocol server implementation that aggregates multiple MCP servers into one.

Verdict
BLOCK
Grade
F
Trust score
30 /100
Exposed tools
187 173r · 11w · 3d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
509
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@1mcp/agent) [](https://www.npmjs.com/package/@1mcp/agent) [](https://github.com/1mcp-app/agent/actions/workflows/github-code-scanning/codeql) [](https://github.com/1mcp-app/agent/stargazers) [](https://docs.1mcp.app) [](https://deepwiki.com/1mcp-app/agent) [](https://www.npmjs.com/package/@1mcp/agent)

1MCP is the unified MCP runtime. 1mcp serve aggregates your MCP servers, and CLI mode adds a thinner agent-facing workflow for Codex, Claude, Cursor, and similar tool-using agents.

Why 1MCP

Most MCP setups eventually hit two kinds of sprawl:

  • Configuration sprawl: every client needs its own MCP wiring, auth choices, and filtering rules.
  • Agent sprawl: autonomous sessions carry too many tools and schemas into context up front.

1MCP addresses both:

  • 1mcp serve gives you one aggregated runtime in front of many MCP servers.
  • CLI mode lets agents discover tools progressively with instructions, inspect, and run.
  • Static servers can load at startup, while template servers are created from per-client or per-session context.
  • Presets, filters, and instruction aggregation keep the same runtime adaptable across clients and projects.
Read from source at commit 34c42eb9a7a5OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add conformance-typescript-fixtures --env API_KEY=${API_KEY} --env CONTEXT7_API_KEY=${CONTEXT7_API_KEY} --env HTTP_AUTH_TOKEN=${HTTP_AUTH_TOKEN} --env OAUTH_AUTHENTICATED=${OAUTH_AUTHENTICATED} -- npx -y @1mcp/[email protected]
claude-desktop
{
  "mcpServers": {
    "conformance-typescript-fixtures": {
      "command": "npx",
      "args": [
        "-y",
        "@1mcp/[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "CONTEXT7_API_KEY": "${CONTEXT7_API_KEY}",
        "HTTP_AUTH_TOKEN": "${HTTP_AUTH_TOKEN}",
        "OAUTH_AUTHENTICATED": "${OAUTH_AUTHENTICATED}"
      }
    }
  }
}
03

Exposed tools (187)

173 read · 11 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
API_KEYreadAPI key
COMMON_VARreadCommon variable from package 1
COMPLEX_VARreadVariable with complex value
MIXED_CASE_VARreadVariable with mixed case
MIXED_ENVreadEnvironment variable
NODE_ENVreadNode environment
NO_DEFAULT_VARreadVariable without default
NO_VALUE_VARreadVariable without value field
PORTreadServer port
SPECIAL_VARreadVariable with special characters
UPPERCASE_VARreadVariable with uppercase value
VALID_VARreadValid variable
VAR1readVariable from package 1
VAR2readVariable from package 2
VAR3readAnother variable from package 2
a.breadRead documents
add_numberswriteAdd two numbers.
alphareadOriginal description
alpha.latereadNeedle on the second upstream page
alpha_onereadFirst
alpha_threereadThird
alpha_toolreadAlpha tool
alpha_tworeadSecond
analyzereadAnalyze data with context
another_toolreadAnother tool description
arg1readArgument from package 1
arg2readArgument from package 2
arg3readAnother argument from package 2
axbreadOther
basic-serverreadBasic MCP server
betareadOther description
beta_toolreadBeta tool
capability_inforeadGet server capability information
capability_testreadTest prompt for capability demonstration
commonreadCommon
common-argreadCommon argument from package 1
complex-argreadComplex argument
complex-presetreadComplex tag query preset
contextreadContext for the prompt
context7_1mcp_query-docsreadQuery docs
copy_filereadCopy file
crash_after_delayreadCrashes after a specified delay
crash_immediatelyreadCrashes the server immediately
create_resourcewriteCreate a new dynamic resource
custom_toolreadCustom tool description
datareadData to analyze
databasereadDatabase query tools
database-connectorreadDatabase integration and query management
database-serverreadA database integration server
database_1mcp_prompt2readDB prompt
database_1mcp_queryreadQuery databases through database server
debugwriteEnable debug mode
delete_filedestructiveDelete file
delete_resourcedestructiveDelete a dynamic resource
deprecated-testreadDeprecated test server
devreadDevelopment preset
dev-presetreadDevelopment servers preset
developmentreadDevelopment servers with database
echoreadEcho back the provided arguments
echo_argsreadEcho message payloads for testing.
emit_textreadEmit the provided text exactly
empty-default-argreadArgument with empty default
empty-presetreadPreset that matches no servers
envreadEnvironment
fail_toolreadReturn an MCP tool error result
fallback-toolreadA tool to test fallback estimation
file-managerreadComprehensive file management system with advanced features
file-searchreadSearch files and metadata across a workspace
file-serverreadFile management server
filesystemreadFile system access for local project files
filesystem_1mcp_prompt1readFS prompt
filesystem_1mcp_read_filereadRead files through filesystem server
find_symbolreadFind symbol
first_toolreadFirst instance
fixture_echoreadReturn a synthetic receipt.
flag-argreadFlag argument
formatreadOutput format
gitreadGit repository tools
grepreadGrep
healthyreadHealthy
helloreadHello tool
hiddenreadNeedle disabled tool
hidden_1mcp_secretreadSecret tool
hostreadServer host
infinite_loopreadEnters an infinite loop
inputreadInput for the prompt
interactive-presetreadInteractive description
internal_errorreadThrows internal server error
invalid_paramsreadAlways returns invalid params error
issuesreadList repository issues
legacy-filesreadOld file system utilities (deprecated)
levelreadLog level
list_memoriesreadList memories
log-levelreadLogging level
long-argreadArgument with long default value
make_dirreadMake dir
mcp_disablewriteDisable an MCP server
mcp_editwriteEdit MCP server configuration
mcp_enablewriteEnable an MCP server
mcp_inforeadGet detailed information about a specific MCP server
mcp_installwriteInstall a new MCP server. Use package+command+args for direct package installation (e.g., npm packages), or just name for registry-based installation
mcp_listreadList MCP servers
mcp_registry_inforeadGet detailed registry information
mcp_registry_listreadList available registries
mcp_registry_statusreadCheck registry availability and performance
mcp_reloadreadReload MCP server or configuration
mcp_searchreadSearch for MCP servers in the registry
mcp_statusreadGet MCP server status
mcp_uninstalldestructiveRemove an MCP server
mcp_updatewriteUpdate an MCP server
memory_bombreadConsumes excessive memory
messagereadA test message
method_not_foundreadCalls non-existent method internally
minimal-serverreadMinimal description
mixed-argreadRuntime argument
move_filewriteMove file
namereadServer name
no-default-argreadArgument without default
no-packages-serverreadServer without packages
number-argreadNumber argument
oauth-protected-toolreadA tool that was only available after OAuth authentication
only_onereadOne
optionalreadOptional arg
passwordreadPassword
portreadServer port
preset1readFirst preset - updated
preset2readSecond preset - updated
prod-presetreadProduction servers preset
productionreadProduction servers - updated description
progressive_delayreadOperation that gets progressively slower
prompt_0readPrompt 0
prompt_1readPrompt 1
queryreadQuery database
query-docsreadQuery docs
readread
read_dirreadRead dir
read_filereadRead file
recoveredreadRecovered
requiredreadRequired arg
runner_1mcp_echo_argsreadEcho message payloads for testing.
runtime_statusreadRuntime status
searchreadSearch for information
second_toolreadSecond instance
serena_1mcp_find_symbolreadFind symbol
server_1mcp_readreadoriginal
slow_operationreadPerforms a slow operation with configurable delay
some_toolreadTest
sourcereadSource description
special-argreadArgument with special characters
static_toolreadA tool from static server
status_checkreadReturns server status and crash configuration
summarizereadSummarize text input.
summarizer_1mcp_summarizereadSummarize text
template_toolreadTemplate tool
testreadTest
test-promptreadA test prompt for demonstration
test-registryreadRegistry fixture server for protocol tests
test-serverreadTest server description
test-server_1mcp_test-toolreadOperator description
test-toolreadA test tool for demonstration
test_toolreadTest
throw_exceptionreadThrows an unhandled exception
timeoutreadTimeout in seconds
timeout_simulationreadHangs to simulate timeout
timeout_testreadTest operation that can exceed timeout limits
tool1readTool 1
tool2readTool 2
tool_0readTool 0
tool_1readTool 1
tool_2readTool 2
tool_3readTool 3
tool_4readTool 4
tool_areadsession A
tool_breadsession B
tool_invokewriteExecute any tool on any MCP server with proper argument validation
tool_listreadList all available MCP tools with names and descriptions. Use for tool discovery.
tool_schemareadGet the full schema for a specific tool including input validation rules
topicreadTopic to generate prompt about
unicode-argreadArgument with unicode characters
upstream_web_searchreadsearch
user-data-toolreadAccess user-specific data (OAuth protected)
valid-argreadArgument with default
valid-presetread
verbosereadVerbose output
waitreadAudited slow lifecycle fixture
web_1mcp_searchreadSearch the web through web server
write_filewriteWrite file
04

Trust audit

BLOCKgrade F · trust 30/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (8 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/en/commands/run.md:125
1. Preserve the server/tool identity and sanitized error evidence. Inspect the same server with `1mcp inspect`, retaining the failed invocation's Runtime Target Context, local Runtime Scope, and Reque
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/domains/runtime-targets/runtimeTargetStore.ts:1553
'Runtime target URL must use https unless non-loopback HTTP is explicitly accepted with --insecure-skip-verify',
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/en/commands/proxy.md:173
`proxy --url <url>` is an ephemeral connection. It does not load or attach saved credentials, so it remains credentialless. Stdio clients still do not receive an interactive OAuth browser flow; use a 
Why it matters. asks the agent to read credentials
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/sdk/legacy/auth/sdkOAuthServerProvider.ts:465
logger.info(`Exchanged authorization code for access token`, {
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/sdk/legacy/auth/sdkOAuthServerProvider.ts:607
logger.info(`Revoked access token for client ${client.client_id}`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
docker-compose.dev.yml:23
- ONE_MCP_EXTERNAL_URL=http://127.0.0.1:3050
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
docker-compose.yml:11
- ONE_MCP_EXTERNAL_URL=http://127.0.0.1:3050
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/en/commands/preset/edit.md:97
🔗 URL: http://127.0.0.1:3050/mcp?preset=development
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/install-windows-task.ps1:1
<#
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/test-install-windows-task.ps1:1
# Test suite for install-windows-task.ps1
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
src/utils/validation/sanitization.test.ts:459
expect(redactSensitiveValue('AKIA1234567890ABCDEF')).toBe('[REDACTED]');
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/commands/run/runUtils.schema.test.ts:12
expect(await validateToolArgs({ secret: 'private-schema-value' }, schema, 'server/tool')).toEqual({ valid: true });
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/config/runtimeScopeEnv.test.ts:72
const secret = 'hidden-diagnostic-secret';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/config/runtimeScopeEnv.test.ts:92
const secret = 'cyclic-diagnostic-secret';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/config/runtimeScopeEnv.test.ts:144
const secret = 'oauth-client-graph-secret';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/config/runtimeScopeEnv.test.ts:164
const secret = 'spoofed-oauth-secret';
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/utils/validation/sanitization.test.ts:454
expect(redactSensitiveValue('ghp_1234567890abcdef1234567890abcdef123456')).toBe('[REDACTED]');
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/utils/validation/sanitization.test.ts:455
expect(redactSensitiveValue('gho_1234567890abcdef1234567890abcdef123456')).toBe('[REDACTED]');
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/utils/validation/sanitization.test.ts:538
'ghp_1234567890abcdef1234567890abcdef123456',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/logger/secureLogger.test.ts:257
'-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA0base64secretkeypayload...\n-----END RSA PRIVATE KEY-----';
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/logger/secureLogger.test.ts:264
const unterminatedPem = '-----BEGIN RSA PRIVATE KEY-----\nUNTERMINATED_PRIVATE_BODY_123';
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file, delete_resource, mcp_uninstall
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.1mcprc.example
.1mcprc.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-09-30 · audit v0.4.1 · source sha 34c42eb9a7a5full audit observations/trust-audit/mcp-server/1mcp-app__one-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-3034c42eb9a7a5BLOCKF30first audit
06

Questions

What is the One MCP MCP server?

A unified Model Context Protocol server implementation that aggregates multiple MCP servers into one.

What tools does One MCP expose?

187 in total: 173 read-only, 11 that write, and 3 that can delete or overwrite (delete_file, delete_resource, mcp_uninstall). Every one is listed on this page with its risk.

Is One MCP safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (30/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does One MCP need?

It reads API_KEY, CONTEXT7_API_KEY, HTTP_AUTH_TOKEN, OAUTH_AUTHENTICATED, OAUTH_SERVER_NAME, OFFICIAL_RUNNER_PARENT_SECRET, RUNTIME_SCOPE_TOKEN, TEST_API_KEY and WIRE_TEST_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does One MCP run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @1mcp/conformance-typescript-fixtures at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (34c42eb9a7a5), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement