Atlas / MCP servers / ai-zerolab / Mcp Toolbox

Mcp ToolboxSAFE

mcp/ai-zerolab/mcp-toolbox

Maintenance of a set of tools to enhance LLM through MCP protocols.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
11 11r · 0w · 0d
Transport
sse · stdio
License
Apache-2.0
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://img.shields.io/github/v/release/ai-zerolab/mcp-toolbox) [](https://github.com/ai-zerolab/mcp-toolbox/actions/workflows/main.yml?query=branch%3Amain) [](https://codecov.io/gh/ai-zerolab/mcp-toolbox) [](https://img.shields.io/github/commit-activity/m/ai-zerolab/mcp-toolbox) [](https://img.shields.io/github/license/ai-zerolab/mcp-toolbox)

A comprehensive toolkit for enhancing LLM capabilities through the Model Context Protocol (MCP). This package provides a collection of tools that allow LLMs to interact with external services and APIs, extending their functionality beyond text generation.

  • GitHub repository:
  • (WIP)Documentation:

Features

\*nix is our main target, but Windows should work too.
  • Command Line Execution: Execute any command line instruction through LLM
  • Figma Integration: Access Figma files, components, styles, and more
  • Extensible Architecture: Easily add new API integrations
  • MCP Protocol Support: Compatible with Claude Desktop and other MCP-enabled LLMs
  • Comprehensive Testing: Well-tested codebase with high test coverage

Installation

Using uv (Recommended)

We recommend using uv to manage your environment.

# Install uv
curl -LsSf https://astral.sh/uv/install.sh | sh  # For macOS/Linux
# or
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"  # For Windows

Then you can use `uvx "mcp-t

Read from source at commit 06fb4434e523OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-toolbox --env BFL_API_KEY=${BFL_API_KEY} -- uvx mcp-toolbox
claude-desktop
{
  "mcpServers": {
    "mcp-toolbox": {
      "command": "uvx",
      "args": [
        "mcp-toolbox"
      ],
      "env": {
        "BFL_API_KEY": "${BFL_API_KEY}"
      }
    }
  }
}
03

Exposed tools (11)

11 read · 0 write · 0 destructive.

ToolRiskDescription
figma_get_commentsreadGet comments on a Figma file.
figma_get_componentreadGet a component by key.
figma_get_file_componentsreadGet components from a file.
figma_get_file_stylesreadGet styles from a file.
figma_get_image_fillsreadGet URLs for images used in a Figma file.
figma_get_stylereadGet a style by key.
forgetreadmemory: LocalMemory = get_current_session_memory()
get_audio_lengthreadGet the length of an audio file in seconds.
get_htmlreadtry:
get_session_idreadmemory: LocalMemory = get_current_session_memory()
thinkread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:32
curl -LsSf https://astral.sh/uv/install.sh | sh  # For macOS/Linux
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
llms.txt:25
curl -LsSf https://astral.sh/uv/install.sh | sh  # For macOS/Linux

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 06fb4434e523full audit observations/trust-audit/mcp-server/ai-zerolab__mcp-toolbox.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0806fb4434e523SAFEB89first audit
06

Questions

What is the Mcp Toolbox MCP server?

Maintenance of a set of tools to enhance LLM through MCP protocols.

What tools does Mcp Toolbox expose?

11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mcp Toolbox safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Mcp Toolbox need?

It reads BFL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcp Toolbox run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-toolbox.

How current is this page?

The grade is for one exact copy of the source (06fb4434e523), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement