Atlas / MCP servers / activeing123 / mcptoon

mcptoonBLOCK

mcp/activeing123/mcptoon

One zero-dependency CLI for all your MCP tools and agent skills. 99.2% fewer tokens on tool discovery, one config for every agent, nothing pre-installed. | 一个零依赖 CLI,管所有 MCP 工具和 Agent 技能。工具发现省 99.2% token,一份配置通吃所有 Agent,原生不预装。227KB,纯 Python 标准库。

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
—
Transport
stdio · streamable-http
License
Apache-2.0
Stars
206
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Install 1,000 skills and 1,000 MCP tools locally — and don't worry about the token context. mcptoon manages it all.

Its own compact format cuts the tool context by ~90% (99.2% on a 255-tool sample; run `mcptoon status` for your own number); no line of config to write for any desktop or command-line agent.

Connects to a 17,000+ MCP tool registry and searches skills on demand — nothing pre-installed, you pick what goes in.

It's just a 322KB native CLI — delete it anytime; keep it, and you never have to configure tools or skills for any agent again.

[](https://github.com/activeing123/mcptoon/stargazers) [](https://pypi.org/project/mcptoon/) [](https://github.com/activeing123/mcptoon/actions/workflows/ci.yml) [](#contributing) [](#what-it-does) [](https://modelcontextprotocol.io/specification/2026-07-28) [](https://github.com/activeing123/mcptoon/blob/main/LICENSE) [](https://allmcps.com/mcp/mcptoon?verify=7eb0d0d6-5d4e-41a3-a048-2fe3c91a36ed) [![MCPVault

Read from source at commit 0ff7ec9a3819OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add mcptoon -- None mcptoon==0.8.7
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/mcptoon/router.py:132
"cat ~/.ssh",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/mcptoon/router.py:180
"show your token", "read your env", "~/.ssh", "/etc/passwd",
Why it matters. touches a credential store
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
src/mcptoon/router.py:180
~/.ssh ... wget
Why it matters. reads secrets in the same file that sends data out
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/mcptoon/router.py:129
"exfiltrate",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/mcptoon/router.py:178
"send this", "post this", "upload this", "upload to", "exfiltrate",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/mcptoon/_toon/decoder.py:88
if text.startswith(""):
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_router.py:205
"-----BEGIN RSA PRIVATE KEY-----\nMIIE...\n-----END RSA PRIVATE KEY-----"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/mcptoon/ccr.py:78
digest = hashlib.sha1(f"{server}:{tool}:{blob}".encode()).hexdigest()
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
.github/workflows/publish.yml:57
print(f'Token length: {len(token)}', file=sys.stderr)
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
.github/workflows/publish.yml:58
print(f'Token starts with pypi-: {token.startswith(\"pypi-\")}', file=sys.stderr)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_ccr.py:54
self.assertIsNone(ccr.retrieve("../../etc/passwd"))
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_add_url_validation.py:36
"https://api.example.com/mcp/v1", "https://127.0.0.1:8080",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_discover.py:302
result = _probe_endpoint("http://127.0.0.1:59999/mcp", timeout=0.1)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_discover.py:307
result = probe_http_endpoint("http://127.0.0.1:59999/mcp", timeout=0.1)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_discover.py:336
with patch.dict(os.environ, {"MCP_HTTP_URL": "http://127.0.0.1:59999/mcp"}):
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_plugin_scan.py:114
"url": "http://127.0.0.1:8080/sse"}},
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/submit_awesome_mcp.py:11
content = base64.b64decode(data['content']).decode('utf-8')
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:306
**How to read a result:** the index mixes official `@modelcontextprotocol/*` servers with packages individuals publish. A `✓` means the registry verified the entry — your cue to read the source before
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
CHANGELOG.md:2462
- **Tool poisoning guard** — Detects prompt injection patterns in MCP tool results (e.g., "ignore previous instructions", hidden `<!-- assistant:` directives, `[INST]` tags). Returns `TOOL_POISONING` 
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
DEVELOPERS.md:166
| 提示词注入 | 工具输出里埋的 `"ignore previous instructions"` |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
README.md:542
| **Prompt-injection guard** | results are scanned for injection patterns like "ignore previous instructions" and blocked |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
README.zh-CN.md:482
| **提示注入防护** | 扫描结果里的注入模式(如 "ignore previous instructions")并拦截 |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CHANGELOG.md:1980
curl -fsSL https://raw.githubusercontent.com/activeing123/mcptoon/main/install.sh | bash
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha 0ff7ec9a3819full audit observations/trust-audit/mcp-server/activeing123__mcptoon.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-020ff7ec9a3819BLOCKD69first audit
05

Questions

What is the mcptoon MCP server?

One zero-dependency CLI for all your MCP tools and agent skills. 99.2% fewer tokens on tool discovery, one config for every agent, nothing pre-installed. | 一个零依赖 CLI,管所有 MCP 工具和 Agent 技能。工具发现省 99.2% token,一份配置通吃所有 Agent,原生不预装。227KB,纯 Python 标准库。

Is mcptoon safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does mcptoon need?

It reads MCPTOON_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does mcptoon run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcptoon.

How current is this page?

The grade is for one exact copy of the source (0ff7ec9a3819), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement