ArchitectBLOCK
A powerful, self-extending MCP server for dynamic AI tool orchestration. Features sandboxed JS execution, capability-based security, automated rate limiting, marketplace integration, and a built-in monitoring dashboard. Built for the Model Context Protocol (MCP).
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The AI agent workshop that builds its own tools.
🚀 What is Architect?
AI agents are incredibly smart, but they hit a wall when they need a tool that doesn't exist yet. Architect MCP removes that wall.
Instead of giving your AI agent a fixed, rigid toolbox, you give it an entire workshop. If your agent needs to call an unconventional API, parse an obscure file format, or hook into a database, it simply writes a custom tool for it on the fly.
Once approved by you, that tool runs securely in an isolated sandbox. The next time your agent hits the same problem? The customized tool is already there, ready to go.
✨ Key Features
- Automated Tool Creation: Agents construct, test, and permanently save their own JavaScript tools on the fly.
- Ironclad Security & Sandboxing: Every custom tool is executed in a highly restricted sandbox. Network or file system access requires explicit user approval through granular capability scopes.
- Built-in Web Dashboard: A beautiful, real-time dashboard UI (running on port
3001out of the box). Manage your active tools, watch execution logs unfold in real time, monitor failures, and securely manage secrets. - Cron Scheduling: Not just for manual use! Agents can set up custom tools to run on cron schedules or build continuous background pipelines.
- Global Marketplace: Why build from scratch if someone else already did? Agents can search (
marketplace_browse), install (marketplace_install), and even share your creations (marketplace_publish) using a GitHub token. - Persistent Data Layer: Built-in, blazing-fast SQLite storage to manage tools, run logs, and execution states reliably.
🛠️ Getting Started
1. Simple Local Setup
You can get running in seconds if you have Node.js installed.
npm install npm run build npm start
Or once pub
191d84914476OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add architect-mcp-server --env DASHBOARD_SECRET=${DASHBOARD_SECRET} -- npx -y [email protected]{
"mcpServers": {
"architect-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"DASHBOARD_SECRET": "${DASHBOARD_SECRET}"
}
}
}
}Exposed tools (84)
62 read · 17 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
browser_auth_login | read | Login using saved credentials from the auth vault. |
browser_back | read | Go back in browser history. |
browser_check | read | Check a checkbox. |
browser_click | read | Click an element. Use @ref from browser_snapshot (e.g. @e2) or CSS/text selectors. |
browser_close | read | Close the browser and end the session. |
browser_connect | read | Connect to an existing Chrome browser via CDP (Chrome DevTools Protocol) port. |
browser_console | read | Read browser console messages (console.log, warn, error, info). |
browser_cookies_clear | destructive | Clear all cookies. |
browser_cookies_get | read | Get all cookies for the current session. |
browser_cookies_set | write | Set a cookie. |
browser_dblclick | read | Double-click an element. |
browser_dialog_accept | read | Accept (OK) a browser dialog (alert, confirm, prompt). |
browser_dialog_dismiss | read | Dismiss (Cancel) a browser dialog. |
browser_diff_screenshot | read | Visual pixel diff between current screenshot and a baseline image. |
browser_diff_snapshot | read | Compare the current accessibility tree snapshot against a previous one to detect page changes. |
browser_diff_url | read | Compare two URLs side-by-side via snapshot diff (and optionally screenshot diff). |
browser_drag | read | Drag an element from source to target. |
browser_eval | write | Execute JavaScript in the context of the current page and return the result. |
browser_fill | destructive | Clear and fill an input field. Preferred over browser_type for form inputs. |
browser_find | read | Find elements using semantic locators (by ARIA role, text, label, placeholder, alt, testid, nth). More robust than CSS selectors. |
browser_focus | read | Focus an element without clicking it. |
browser_forward | read | Go forward in browser history. |
browser_frame | read | Switch context to an iframe, or back to the main frame. |
browser_get_attr | read | Get the value of an HTML attribute on an element. |
browser_get_box | read | Get the bounding box (x, y, width, height) of an element. |
browser_get_count | read | Count how many elements match a selector. |
browser_get_html | read | Get the innerHTML of an element. |
browser_get_styles | read | Get the computed CSS styles of an element. |
browser_get_text | read | Get the visible text content of an element. |
browser_get_title | read | Get the current page title. |
browser_get_url | read | Get the current page URL. |
browser_get_value | read | Get the current value of an input element. |
browser_highlight | read | Visually highlight an element on the page (useful for debugging in headed mode). |
browser_hover | read | Hover over an element (useful for revealing tooltips or dropdown menus). |
browser_is_checked | read | Check whether a checkbox or radio button is checked. |
browser_is_enabled | read | Check whether an element is enabled (not disabled). |
browser_is_visible | read | Check whether an element is visible on the page. |
browser_keyboard_insert_text | write | Insert text without triggering key events (no element selector). Faster than keyboard_type. |
browser_keyboard_type | read | Type text using real keystrokes (no element selector, types at current focus). |
browser_keydown | read | Hold a key down. |
browser_keyup | read | Release a held key. |
browser_mouse_down | read | Press a mouse button down. |
browser_mouse_move | write | Move the mouse cursor to specific coordinates. |
browser_mouse_up | read | Release a pressed mouse button. |
browser_mouse_wheel | read | Scroll the mouse wheel. |
browser_network_requests | read | View tracked network requests made by the page. |
browser_network_route | read | Intercept, block, or mock network requests matching a URL pattern. |
browser_network_unroute | destructive | Remove a network route/intercept. |
browser_open | read | Navigate to a URL. Returns the page after load. Use browser_snapshot after to see interactive elements. |
browser_page_errors | read | Read uncaught JavaScript exceptions on the page. |
browser_pdf | write | Save the current page as a PDF file. |
browser_press | read | Press a keyboard key or shortcut (e.g. Enter, Tab, Control+a, Escape). |
browser_reload | read | Reload the current page. |
browser_screenshot | read | Take a screenshot. Use --annotate to get numbered labels matching @refs for visual+text workflows. |
browser_scroll | read | Scroll the page or a specific element in a direction. |
browser_scroll_into_view | read | Scroll a specific element into the viewport. |
browser_select | read | Select an option in a <select> dropdown. |
browser_session_list | read | List all active isolated browser sessions. |
browser_set_credentials | write | Set HTTP basic auth credentials. |
browser_set_device | write | Emulate a device (e.g. |
browser_set_geo | write | Set the browser |
browser_set_headers | write | Set global HTTP headers for all requests (all domains). |
browser_set_media | write | Emulate a CSS color scheme preference. |
browser_set_offline | write | Toggle offline mode on or off. |
browser_set_viewport | write | Set the browser viewport size. |
browser_snapshot | read | Get the current page accessibility tree with @ref handles for interacting with elements. Best first step after navigation. |
browser_state_clear | destructive | Clear saved browser auth state(s). |
browser_state_list | read | List all saved browser auth state files. |
browser_state_load | read | Load a previously saved browser auth state from a file. |
browser_state_save | write | Save current browser auth state (cookies, localStorage) to a file for reuse. |
browser_storage_clear | destructive | Clear all values from localStorage or sessionStorage. |
browser_storage_get | read | Get value(s) from localStorage or sessionStorage. |
browser_storage_set | write | Set a value in localStorage or sessionStorage. |
browser_tab_close | read | Close a browser tab. |
browser_tab_list | read | List all open browser tabs. |
browser_tab_new | read | Open a new browser tab, optionally navigating to a URL. |
browser_tab_switch | read | Switch to a tab by its index number. |
browser_trace_start | write | Start recording a Playwright trace for debugging and replay. |
browser_trace_stop | write | Stop and save the current Playwright trace. |
browser_type | read | Type text into an element (appends to existing content). |
browser_uncheck | read | Uncheck a checkbox. |
browser_upload | write | Upload one or more files to a file input element. |
browser_wait | read | Wait for an element, text, URL pattern, load state, or a time duration before continuing. |
browser_window_new | read | Open a new browser window. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
const condResult = new Function("ctx", `return ${step.condition}`)(context);const result = await exec(params.command, args);
browser_cookies_clear, browser_fill, browser_network_unroute, browser_state_clear, browser_storage_clear
const require = createRequire(path.resolve(__dirname, "../../node_modules"));
@hono/node-server, @modelcontextprotocol/sdk, better-sqlite3, cron-parser, hono, zod, @types/better-sqlite3, @types/node
The server will start and the dashboard will be at `http://localhost:3001`. The `npm run dev` command watches for changes and restarts automatically, so you don't need to rebuild manually while workin
Gates applied: no_behavioural_pass.
191d84914476full audit observations/trust-audit/mcp-server/ageborn-dev__architect-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 191d84914476 | BLOCK | D | 69 | first audit |
Questions
What is the Architect MCP server?
A powerful, self-extending MCP server for dynamic AI tool orchestration. Features sandboxed JS execution, capability-based security, automated rate limiting, marketplace integration, and a built-in monitoring dashboard. Built for the Model Context Protocol (MCP).
What tools does Architect expose?
84 in total: 62 read-only, 17 that write, and 5 that can delete or overwrite (browser_cookies_clear, browser_fill, browser_network_unroute, browser_state_clear, browser_storage_clear). Every one is listed on this page with its risk.
Is Architect safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Architect need?
It reads DASHBOARD_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Architect run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as architect-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (191d84914476), read on 2026-10-09. The repository is watched and re-audited when it changes.