mcptoonBLOCK
One zero-dependency CLI for all your MCP tools and agent skills. 99.2% fewer tokens on tool discovery, one config for every agent, nothing pre-installed. | 一个零依赖 CLI,管所有 MCP 工具和 Agent 技能。工具发现省 99.2% token,一份配置通吃所有 Agent,原生不预装。227KB,纯 Python 标准库。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Install 1,000 skills and 1,000 MCP tools locally — and don't worry about the token context. mcptoon manages it all.
Its own compact format cuts the tool context by ~90% (99.2% on a 255-tool sample; run `mcptoon status` for your own number); no line of config to write for any desktop or command-line agent.
Connects to a 17,000+ MCP tool registry and searches skills on demand — nothing pre-installed, you pick what goes in.
It's just a 322KB native CLI — delete it anytime; keep it, and you never have to configure tools or skills for any agent again.
[](https://github.com/activeing123/mcptoon/stargazers) [](https://pypi.org/project/mcptoon/) [](https://github.com/activeing123/mcptoon/actions/workflows/ci.yml) [](#contributing) [](#what-it-does) [](https://modelcontextprotocol.io/specification/2026-07-28) [](https://github.com/activeing123/mcptoon/blob/main/LICENSE) [](https://allmcps.com/mcp/mcptoon?verify=7eb0d0d6-5d4e-41a3-a048-2fe3c91a36ed) [![MCPVault
0ff7ec9a3819OBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcptoon -- None mcptoon==0.8.7
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
"cat ~/.ssh",
"show your token", "read your env", "~/.ssh", "/etc/passwd",
~/.ssh ... wget
"exfiltrate",
"send this", "post this", "upload this", "upload to", "exfiltrate",
if text.startswith(""):"-----BEGIN RSA PRIVATE KEY-----\nMIIE...\n-----END RSA PRIVATE KEY-----"
.pre-commit-config.yaml
digest = hashlib.sha1(f"{server}:{tool}:{blob}".encode()).hexdigest()print(f'Token length: {len(token)}', file=sys.stderr)print(f'Token starts with pypi-: {token.startswith(\"pypi-\")}', file=sys.stderr)self.assertIsNone(ccr.retrieve("../../etc/passwd"))"https://api.example.com/mcp/v1", "https://127.0.0.1:8080",
result = _probe_endpoint("http://127.0.0.1:59999/mcp", timeout=0.1)result = probe_http_endpoint("http://127.0.0.1:59999/mcp", timeout=0.1)with patch.dict(os.environ, {"MCP_HTTP_URL": "http://127.0.0.1:59999/mcp"}):"url": "http://127.0.0.1:8080/sse"}},
content = base64.b64decode(data['content']).decode('utf-8')**How to read a result:** the index mixes official `@modelcontextprotocol/*` servers with packages individuals publish. A `✓` means the registry verified the entry — your cue to read the source before
- **Tool poisoning guard** — Detects prompt injection patterns in MCP tool results (e.g., "ignore previous instructions", hidden `<!-- assistant:` directives, `[INST]` tags). Returns `TOOL_POISONING`
| 提示词注入 | 工具输出里埋的 `"ignore previous instructions"` |
| **Prompt-injection guard** | results are scanned for injection patterns like "ignore previous instructions" and blocked |
| **提示注入防护** | 扫描结果里的注入模式(如 "ignore previous instructions")并拦截 |
curl -fsSL https://raw.githubusercontent.com/activeing123/mcptoon/main/install.sh | bash
Gates applied: no_behavioural_pass.
0ff7ec9a3819full audit observations/trust-audit/mcp-server/activeing123__mcptoon.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | 0ff7ec9a3819 | BLOCK | D | 69 | first audit |
Questions
What is the mcptoon MCP server?
One zero-dependency CLI for all your MCP tools and agent skills. 99.2% fewer tokens on tool discovery, one config for every agent, nothing pre-installed. | 一个零依赖 CLI,管所有 MCP 工具和 Agent 技能。工具发现省 99.2% token,一份配置通吃所有 Agent,原生不预装。227KB,纯 Python 标准库。
Is mcptoon safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does mcptoon need?
It reads MCPTOON_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does mcptoon run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcptoon.
How current is this page?
The grade is for one exact copy of the source (0ff7ec9a3819), read on 2026-10-02. The repository is watched and re-audited when it changes.