Atlas / MCP servers / ageborn-dev / Architect

ArchitectBLOCK

mcp/ageborn-dev/architect-1

A powerful, self-extending MCP server for dynamic AI tool orchestration. Features sandboxed JS execution, capability-based security, automated rate limiting, marketplace integration, and a built-in monitoring dashboard. Built for the Model Context Protocol (MCP).

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
84 62r · 17w · 5d
Transport
stdio
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The AI agent workshop that builds its own tools.

🚀 What is Architect?

AI agents are incredibly smart, but they hit a wall when they need a tool that doesn't exist yet. Architect MCP removes that wall.

Instead of giving your AI agent a fixed, rigid toolbox, you give it an entire workshop. If your agent needs to call an unconventional API, parse an obscure file format, or hook into a database, it simply writes a custom tool for it on the fly.

Once approved by you, that tool runs securely in an isolated sandbox. The next time your agent hits the same problem? The customized tool is already there, ready to go.

✨ Key Features

  • Automated Tool Creation: Agents construct, test, and permanently save their own JavaScript tools on the fly.
  • Ironclad Security & Sandboxing: Every custom tool is executed in a highly restricted sandbox. Network or file system access requires explicit user approval through granular capability scopes.
  • Built-in Web Dashboard: A beautiful, real-time dashboard UI (running on port 3001 out of the box). Manage your active tools, watch execution logs unfold in real time, monitor failures, and securely manage secrets.
  • Cron Scheduling: Not just for manual use! Agents can set up custom tools to run on cron schedules or build continuous background pipelines.
  • Global Marketplace: Why build from scratch if someone else already did? Agents can search (marketplace_browse), install (marketplace_install), and even share your creations (marketplace_publish) using a GitHub token.
  • Persistent Data Layer: Built-in, blazing-fast SQLite storage to manage tools, run logs, and execution states reliably.

🛠️ Getting Started

1. Simple Local Setup

You can get running in seconds if you have Node.js installed.

npm install
npm run build
npm start

Or once pub

Read from source at commit 191d84914476OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add architect-mcp-server --env DASHBOARD_SECRET=${DASHBOARD_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "architect-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DASHBOARD_SECRET": "${DASHBOARD_SECRET}"
      }
    }
  }
}
03

Exposed tools (84)

62 read · 17 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
browser_auth_loginreadLogin using saved credentials from the auth vault.
browser_backreadGo back in browser history.
browser_checkreadCheck a checkbox.
browser_clickreadClick an element. Use @ref from browser_snapshot (e.g. @e2) or CSS/text selectors.
browser_closereadClose the browser and end the session.
browser_connectreadConnect to an existing Chrome browser via CDP (Chrome DevTools Protocol) port.
browser_consolereadRead browser console messages (console.log, warn, error, info).
browser_cookies_cleardestructiveClear all cookies.
browser_cookies_getreadGet all cookies for the current session.
browser_cookies_setwriteSet a cookie.
browser_dblclickreadDouble-click an element.
browser_dialog_acceptreadAccept (OK) a browser dialog (alert, confirm, prompt).
browser_dialog_dismissreadDismiss (Cancel) a browser dialog.
browser_diff_screenshotreadVisual pixel diff between current screenshot and a baseline image.
browser_diff_snapshotreadCompare the current accessibility tree snapshot against a previous one to detect page changes.
browser_diff_urlreadCompare two URLs side-by-side via snapshot diff (and optionally screenshot diff).
browser_dragreadDrag an element from source to target.
browser_evalwriteExecute JavaScript in the context of the current page and return the result.
browser_filldestructiveClear and fill an input field. Preferred over browser_type for form inputs.
browser_findreadFind elements using semantic locators (by ARIA role, text, label, placeholder, alt, testid, nth). More robust than CSS selectors.
browser_focusreadFocus an element without clicking it.
browser_forwardreadGo forward in browser history.
browser_framereadSwitch context to an iframe, or back to the main frame.
browser_get_attrreadGet the value of an HTML attribute on an element.
browser_get_boxreadGet the bounding box (x, y, width, height) of an element.
browser_get_countreadCount how many elements match a selector.
browser_get_htmlreadGet the innerHTML of an element.
browser_get_stylesreadGet the computed CSS styles of an element.
browser_get_textreadGet the visible text content of an element.
browser_get_titlereadGet the current page title.
browser_get_urlreadGet the current page URL.
browser_get_valuereadGet the current value of an input element.
browser_highlightreadVisually highlight an element on the page (useful for debugging in headed mode).
browser_hoverreadHover over an element (useful for revealing tooltips or dropdown menus).
browser_is_checkedreadCheck whether a checkbox or radio button is checked.
browser_is_enabledreadCheck whether an element is enabled (not disabled).
browser_is_visiblereadCheck whether an element is visible on the page.
browser_keyboard_insert_textwriteInsert text without triggering key events (no element selector). Faster than keyboard_type.
browser_keyboard_typereadType text using real keystrokes (no element selector, types at current focus).
browser_keydownreadHold a key down.
browser_keyupreadRelease a held key.
browser_mouse_downreadPress a mouse button down.
browser_mouse_movewriteMove the mouse cursor to specific coordinates.
browser_mouse_upreadRelease a pressed mouse button.
browser_mouse_wheelreadScroll the mouse wheel.
browser_network_requestsreadView tracked network requests made by the page.
browser_network_routereadIntercept, block, or mock network requests matching a URL pattern.
browser_network_unroutedestructiveRemove a network route/intercept.
browser_openreadNavigate to a URL. Returns the page after load. Use browser_snapshot after to see interactive elements.
browser_page_errorsreadRead uncaught JavaScript exceptions on the page.
browser_pdfwriteSave the current page as a PDF file.
browser_pressreadPress a keyboard key or shortcut (e.g. Enter, Tab, Control+a, Escape).
browser_reloadreadReload the current page.
browser_screenshotreadTake a screenshot. Use --annotate to get numbered labels matching @refs for visual+text workflows.
browser_scrollreadScroll the page or a specific element in a direction.
browser_scroll_into_viewreadScroll a specific element into the viewport.
browser_selectreadSelect an option in a <select> dropdown.
browser_session_listreadList all active isolated browser sessions.
browser_set_credentialswriteSet HTTP basic auth credentials.
browser_set_devicewriteEmulate a device (e.g.
browser_set_geowriteSet the browser
browser_set_headerswriteSet global HTTP headers for all requests (all domains).
browser_set_mediawriteEmulate a CSS color scheme preference.
browser_set_offlinewriteToggle offline mode on or off.
browser_set_viewportwriteSet the browser viewport size.
browser_snapshotreadGet the current page accessibility tree with @ref handles for interacting with elements. Best first step after navigation.
browser_state_cleardestructiveClear saved browser auth state(s).
browser_state_listreadList all saved browser auth state files.
browser_state_loadreadLoad a previously saved browser auth state from a file.
browser_state_savewriteSave current browser auth state (cookies, localStorage) to a file for reuse.
browser_storage_cleardestructiveClear all values from localStorage or sessionStorage.
browser_storage_getreadGet value(s) from localStorage or sessionStorage.
browser_storage_setwriteSet a value in localStorage or sessionStorage.
browser_tab_closereadClose a browser tab.
browser_tab_listreadList all open browser tabs.
browser_tab_newreadOpen a new browser tab, optionally navigating to a URL.
browser_tab_switchreadSwitch to a tab by its index number.
browser_trace_startwriteStart recording a Playwright trace for debugging and replay.
browser_trace_stopwriteStop and save the current Playwright trace.
browser_typereadType text into an element (appends to existing content).
browser_uncheckreadUncheck a checkbox.
browser_uploadwriteUpload one or more files to a file input element.
browser_waitreadWait for an element, text, URL pattern, load state, or a time duration before continuing.
browser_window_newreadOpen a new browser window.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/execution/pipelines.ts:129
const condResult = new Function("ctx", `return ${step.condition}`)(context);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/tools/templates.ts:174
const result = await exec(params.command, args);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
browser_cookies_clear, browser_fill, browser_network_unroute, browser_state_clear, browser_storage_clear
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/sandbox-process.ts:43
const require = createRequire(path.resolve(__dirname, "../../node_modules"));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@hono/node-server, @modelcontextprotocol/sdk, better-sqlite3, cron-parser, hono, zod, @types/better-sqlite3, @types/node
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
CONTRIBUTING.md:35
The server will start and the dashboard will be at `http://localhost:3001`. The `npm run dev` command watches for changes and restarts automatically, so you don't need to rebuild manually while workin
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 191d84914476full audit observations/trust-audit/mcp-server/ageborn-dev__architect-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09191d84914476BLOCKD69first audit
06

Questions

What is the Architect MCP server?

A powerful, self-extending MCP server for dynamic AI tool orchestration. Features sandboxed JS execution, capability-based security, automated rate limiting, marketplace integration, and a built-in monitoring dashboard. Built for the Model Context Protocol (MCP).

What tools does Architect expose?

84 in total: 62 read-only, 17 that write, and 5 that can delete or overwrite (browser_cookies_clear, browser_fill, browser_network_unroute, browser_state_clear, browser_storage_clear). Every one is listed on this page with its risk.

Is Architect safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Architect need?

It reads DASHBOARD_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Architect run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as architect-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (191d84914476), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement