Mcp ToolboxSAFE
Maintenance of a set of tools to enhance LLM through MCP protocols.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://img.shields.io/github/v/release/ai-zerolab/mcp-toolbox) [](https://github.com/ai-zerolab/mcp-toolbox/actions/workflows/main.yml?query=branch%3Amain) [](https://codecov.io/gh/ai-zerolab/mcp-toolbox) [](https://img.shields.io/github/commit-activity/m/ai-zerolab/mcp-toolbox) [](https://img.shields.io/github/license/ai-zerolab/mcp-toolbox)
A comprehensive toolkit for enhancing LLM capabilities through the Model Context Protocol (MCP). This package provides a collection of tools that allow LLMs to interact with external services and APIs, extending their functionality beyond text generation.
- GitHub repository:
- (WIP)Documentation:
Features
\*nix is our main target, but Windows should work too.
- Command Line Execution: Execute any command line instruction through LLM
- Figma Integration: Access Figma files, components, styles, and more
- Extensible Architecture: Easily add new API integrations
- MCP Protocol Support: Compatible with Claude Desktop and other MCP-enabled LLMs
- Comprehensive Testing: Well-tested codebase with high test coverage
Installation
Using uv (Recommended)
We recommend using uv to manage your environment.
# Install uv curl -LsSf https://astral.sh/uv/install.sh | sh # For macOS/Linux # or powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex" # For Windows
Then you can use `uvx "mcp-t
06fb4434e523OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-toolbox --env BFL_API_KEY=${BFL_API_KEY} -- uvx mcp-toolbox{
"mcpServers": {
"mcp-toolbox": {
"command": "uvx",
"args": [
"mcp-toolbox"
],
"env": {
"BFL_API_KEY": "${BFL_API_KEY}"
}
}
}
}Exposed tools (11)
11 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
figma_get_comments | read | Get comments on a Figma file. |
figma_get_component | read | Get a component by key. |
figma_get_file_components | read | Get components from a file. |
figma_get_file_styles | read | Get styles from a file. |
figma_get_image_fills | read | Get URLs for images used in a Figma file. |
figma_get_style | read | Get a style by key. |
forget | read | memory: LocalMemory = get_current_session_memory() |
get_audio_length | read | Get the length of an audio file in seconds. |
get_html | read | try: |
get_session_id | read | memory: LocalMemory = get_current_session_memory() |
think | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
.pre-commit-config.yaml
curl -LsSf https://astral.sh/uv/install.sh | sh # For macOS/Linux
curl -LsSf https://astral.sh/uv/install.sh | sh # For macOS/Linux
Gates applied: no_behavioural_pass.
06fb4434e523full audit observations/trust-audit/mcp-server/ai-zerolab__mcp-toolbox.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 06fb4434e523 | SAFE | B | 89 | first audit |
Questions
What is the Mcp Toolbox MCP server?
Maintenance of a set of tools to enhance LLM through MCP protocols.
What tools does Mcp Toolbox expose?
11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mcp Toolbox safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Mcp Toolbox need?
It reads BFL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mcp Toolbox run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-toolbox.
How current is this page?
The grade is for one exact copy of the source (06fb4434e523), read on 2026-10-08. The repository is watched and re-audited when it changes.