One MCPBLOCK
A unified Model Context Protocol server implementation that aggregates multiple MCP servers into one.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@1mcp/agent) [](https://www.npmjs.com/package/@1mcp/agent) [](https://github.com/1mcp-app/agent/actions/workflows/github-code-scanning/codeql) [](https://github.com/1mcp-app/agent/stargazers) [](https://docs.1mcp.app) [](https://deepwiki.com/1mcp-app/agent) [](https://www.npmjs.com/package/@1mcp/agent)
1MCP is the unified MCP runtime. 1mcp serve aggregates your MCP servers, and CLI mode adds a thinner agent-facing workflow for Codex, Claude, Cursor, and similar tool-using agents.
Why 1MCP
Most MCP setups eventually hit two kinds of sprawl:
- Configuration sprawl: every client needs its own MCP wiring, auth choices, and filtering rules.
- Agent sprawl: autonomous sessions carry too many tools and schemas into context up front.
1MCP addresses both:
1mcp servegives you one aggregated runtime in front of many MCP servers.- CLI mode lets agents discover tools progressively with
instructions,inspect, andrun. - Static servers can load at startup, while template servers are created from per-client or per-session context.
- Presets, filters, and instruction aggregation keep the same runtime adaptable across clients and projects.
34c42eb9a7a5OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add conformance-typescript-fixtures --env API_KEY=${API_KEY} --env CONTEXT7_API_KEY=${CONTEXT7_API_KEY} --env HTTP_AUTH_TOKEN=${HTTP_AUTH_TOKEN} --env OAUTH_AUTHENTICATED=${OAUTH_AUTHENTICATED} -- npx -y @1mcp/[email protected]{
"mcpServers": {
"conformance-typescript-fixtures": {
"command": "npx",
"args": [
"-y",
"@1mcp/[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"CONTEXT7_API_KEY": "${CONTEXT7_API_KEY}",
"HTTP_AUTH_TOKEN": "${HTTP_AUTH_TOKEN}",
"OAUTH_AUTHENTICATED": "${OAUTH_AUTHENTICATED}"
}
}
}
}Exposed tools (187)
173 read · 11 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
API_KEY | read | API key |
COMMON_VAR | read | Common variable from package 1 |
COMPLEX_VAR | read | Variable with complex value |
MIXED_CASE_VAR | read | Variable with mixed case |
MIXED_ENV | read | Environment variable |
NODE_ENV | read | Node environment |
NO_DEFAULT_VAR | read | Variable without default |
NO_VALUE_VAR | read | Variable without value field |
PORT | read | Server port |
SPECIAL_VAR | read | Variable with special characters |
UPPERCASE_VAR | read | Variable with uppercase value |
VALID_VAR | read | Valid variable |
VAR1 | read | Variable from package 1 |
VAR2 | read | Variable from package 2 |
VAR3 | read | Another variable from package 2 |
a.b | read | Read documents |
add_numbers | write | Add two numbers. |
alpha | read | Original description |
alpha.late | read | Needle on the second upstream page |
alpha_one | read | First |
alpha_three | read | Third |
alpha_tool | read | Alpha tool |
alpha_two | read | Second |
analyze | read | Analyze data with context |
another_tool | read | Another tool description |
arg1 | read | Argument from package 1 |
arg2 | read | Argument from package 2 |
arg3 | read | Another argument from package 2 |
axb | read | Other |
basic-server | read | Basic MCP server |
beta | read | Other description |
beta_tool | read | Beta tool |
capability_info | read | Get server capability information |
capability_test | read | Test prompt for capability demonstration |
common | read | Common |
common-arg | read | Common argument from package 1 |
complex-arg | read | Complex argument |
complex-preset | read | Complex tag query preset |
context | read | Context for the prompt |
context7_1mcp_query-docs | read | Query docs |
copy_file | read | Copy file |
crash_after_delay | read | Crashes after a specified delay |
crash_immediately | read | Crashes the server immediately |
create_resource | write | Create a new dynamic resource |
custom_tool | read | Custom tool description |
data | read | Data to analyze |
database | read | Database query tools |
database-connector | read | Database integration and query management |
database-server | read | A database integration server |
database_1mcp_prompt2 | read | DB prompt |
database_1mcp_query | read | Query databases through database server |
debug | write | Enable debug mode |
delete_file | destructive | Delete file |
delete_resource | destructive | Delete a dynamic resource |
deprecated-test | read | Deprecated test server |
dev | read | Development preset |
dev-preset | read | Development servers preset |
development | read | Development servers with database |
echo | read | Echo back the provided arguments |
echo_args | read | Echo message payloads for testing. |
emit_text | read | Emit the provided text exactly |
empty-default-arg | read | Argument with empty default |
empty-preset | read | Preset that matches no servers |
env | read | Environment |
fail_tool | read | Return an MCP tool error result |
fallback-tool | read | A tool to test fallback estimation |
file-manager | read | Comprehensive file management system with advanced features |
file-search | read | Search files and metadata across a workspace |
file-server | read | File management server |
filesystem | read | File system access for local project files |
filesystem_1mcp_prompt1 | read | FS prompt |
filesystem_1mcp_read_file | read | Read files through filesystem server |
find_symbol | read | Find symbol |
first_tool | read | First instance |
fixture_echo | read | Return a synthetic receipt. |
flag-arg | read | Flag argument |
format | read | Output format |
git | read | Git repository tools |
grep | read | Grep |
healthy | read | Healthy |
hello | read | Hello tool |
hidden | read | Needle disabled tool |
hidden_1mcp_secret | read | Secret tool |
host | read | Server host |
infinite_loop | read | Enters an infinite loop |
input | read | Input for the prompt |
interactive-preset | read | Interactive description |
internal_error | read | Throws internal server error |
invalid_params | read | Always returns invalid params error |
issues | read | List repository issues |
legacy-files | read | Old file system utilities (deprecated) |
level | read | Log level |
list_memories | read | List memories |
log-level | read | Logging level |
long-arg | read | Argument with long default value |
make_dir | read | Make dir |
mcp_disable | write | Disable an MCP server |
mcp_edit | write | Edit MCP server configuration |
mcp_enable | write | Enable an MCP server |
mcp_info | read | Get detailed information about a specific MCP server |
mcp_install | write | Install a new MCP server. Use package+command+args for direct package installation (e.g., npm packages), or just name for registry-based installation |
mcp_list | read | List MCP servers |
mcp_registry_info | read | Get detailed registry information |
mcp_registry_list | read | List available registries |
mcp_registry_status | read | Check registry availability and performance |
mcp_reload | read | Reload MCP server or configuration |
mcp_search | read | Search for MCP servers in the registry |
mcp_status | read | Get MCP server status |
mcp_uninstall | destructive | Remove an MCP server |
mcp_update | write | Update an MCP server |
memory_bomb | read | Consumes excessive memory |
message | read | A test message |
method_not_found | read | Calls non-existent method internally |
minimal-server | read | Minimal description |
mixed-arg | read | Runtime argument |
move_file | write | Move file |
name | read | Server name |
no-default-arg | read | Argument without default |
no-packages-server | read | Server without packages |
number-arg | read | Number argument |
oauth-protected-tool | read | A tool that was only available after OAuth authentication |
only_one | read | One |
optional | read | Optional arg |
password | read | Password |
port | read | Server port |
preset1 | read | First preset - updated |
preset2 | read | Second preset - updated |
prod-preset | read | Production servers preset |
production | read | Production servers - updated description |
progressive_delay | read | Operation that gets progressively slower |
prompt_0 | read | Prompt 0 |
prompt_1 | read | Prompt 1 |
query | read | Query database |
query-docs | read | Query docs |
read | read | |
read_dir | read | Read dir |
read_file | read | Read file |
recovered | read | Recovered |
required | read | Required arg |
runner_1mcp_echo_args | read | Echo message payloads for testing. |
runtime_status | read | Runtime status |
search | read | Search for information |
second_tool | read | Second instance |
serena_1mcp_find_symbol | read | Find symbol |
server_1mcp_read | read | original |
slow_operation | read | Performs a slow operation with configurable delay |
some_tool | read | Test |
source | read | Source description |
special-arg | read | Argument with special characters |
static_tool | read | A tool from static server |
status_check | read | Returns server status and crash configuration |
summarize | read | Summarize text input. |
summarizer_1mcp_summarize | read | Summarize text |
template_tool | read | Template tool |
test | read | Test |
test-prompt | read | A test prompt for demonstration |
test-registry | read | Registry fixture server for protocol tests |
test-server | read | Test server description |
test-server_1mcp_test-tool | read | Operator description |
test-tool | read | A test tool for demonstration |
test_tool | read | Test |
throw_exception | read | Throws an unhandled exception |
timeout | read | Timeout in seconds |
timeout_simulation | read | Hangs to simulate timeout |
timeout_test | read | Test operation that can exceed timeout limits |
tool1 | read | Tool 1 |
tool2 | read | Tool 2 |
tool_0 | read | Tool 0 |
tool_1 | read | Tool 1 |
tool_2 | read | Tool 2 |
tool_3 | read | Tool 3 |
tool_4 | read | Tool 4 |
tool_a | read | session A |
tool_b | read | session B |
tool_invoke | write | Execute any tool on any MCP server with proper argument validation |
tool_list | read | List all available MCP tools with names and descriptions. Use for tool discovery. |
tool_schema | read | Get the full schema for a specific tool including input validation rules |
topic | read | Topic to generate prompt about |
unicode-arg | read | Argument with unicode characters |
upstream_web_search | read | search |
user-data-tool | read | Access user-specific data (OAuth protected) |
valid-arg | read | Argument with default |
valid-preset | read | |
verbose | read | Verbose output |
wait | read | Audited slow lifecycle fixture |
web_1mcp_search | read | Search the web through web server |
write_file | write | Write file |
Trust audit
BLOCKgrade F · trust 30/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
1. Preserve the server/tool identity and sanitized error evidence. Inspect the same server with `1mcp inspect`, retaining the failed invocation's Runtime Target Context, local Runtime Scope, and Reque
'Runtime target URL must use https unless non-loopback HTTP is explicitly accepted with --insecure-skip-verify',
`proxy --url <url>` is an ephemeral connection. It does not load or attach saved credentials, so it remains credentialless. Stdio clients still do not receive an interactive OAuth browser flow; use a
logger.info(`Exchanged authorization code for access token`, {logger.info(`Revoked access token for client ${client.client_id}`, {- ONE_MCP_EXTERNAL_URL=http://127.0.0.1:3050
- ONE_MCP_EXTERNAL_URL=http://127.0.0.1:3050
🔗 URL: http://127.0.0.1:3050/mcp?preset=development
<#
# Test suite for install-windows-task.ps1
expect(redactSensitiveValue('AKIA1234567890ABCDEF')).toBe('[REDACTED]');expect(await validateToolArgs({ secret: 'private-schema-value' }, schema, 'server/tool')).toEqual({ valid: true });const secret = 'hidden-diagnostic-secret';
const secret = 'cyclic-diagnostic-secret';
const secret = 'oauth-client-graph-secret';
const secret = 'spoofed-oauth-secret';
expect(redactSensitiveValue('ghp_1234567890abcdef1234567890abcdef123456')).toBe('[REDACTED]');expect(redactSensitiveValue('gho_1234567890abcdef1234567890abcdef123456')).toBe('[REDACTED]');'ghp_1234567890abcdef1234567890abcdef123456',
'-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA0base64secretkeypayload...\n-----END RSA PRIVATE KEY-----';
const unterminatedPem = '-----BEGIN RSA PRIVATE KEY-----\nUNTERMINATED_PRIVATE_BODY_123';
delete_file, delete_resource, mcp_uninstall
.1mcprc.example
.node-version
.prettierignore
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
34c42eb9a7a5full audit observations/trust-audit/mcp-server/1mcp-app__one-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 34c42eb9a7a5 | BLOCK | F | 30 | first audit |
Questions
What is the One MCP MCP server?
A unified Model Context Protocol server implementation that aggregates multiple MCP servers into one.
What tools does One MCP expose?
187 in total: 173 read-only, 11 that write, and 3 that can delete or overwrite (delete_file, delete_resource, mcp_uninstall). Every one is listed on this page with its risk.
Is One MCP safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (30/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does One MCP need?
It reads API_KEY, CONTEXT7_API_KEY, HTTP_AUTH_TOKEN, OAUTH_AUTHENTICATED, OAUTH_SERVER_NAME, OFFICIAL_RUNNER_PARENT_SECRET, RUNTIME_SCOPE_TOKEN, TEST_API_KEY and WIRE_TEST_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does One MCP run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @1mcp/conformance-typescript-fixtures at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (34c42eb9a7a5), read on 2026-09-30. The repository is watched and re-audited when it changes.