Atlas / MCP servers / cgize / Think Tool

Think ToolSAFE

mcp/cgize/think-tool-1

MCP Think Tool Claude Desktop

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 3r · 0w · 1d
Transport
stdio
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@cgize/claude-mcp-think-tool)

A Model Context Protocol (MCP) server implementing the "think" tool for improving Claude's complex reasoning capabilities.

Overview

This MCP server implements Anthropic's "think" tool, which provides Claude with a dedicated space for structured thinking during complex problem-solving tasks. As described in Anthropic's blog post, the think tool has been shown to significantly improve performance in complex tasks requiring policy adherence and reasoning in long chains of tool calls.

Custom Instructions

Add these custom instructions to Claude to optimize its use of the think tool:

You have access to a "think" tool that provides a dedicated space for structured reasoning. Using this tool significantly improves your performance on complex tasks. 

## When to use the think tool 
Before taking any action or responding to the user after receiving tool results, use the think tool as a scratchpad to: 
- List the specific rules that apply to the current request 
- Check if all required information is collected 
- Verify that the planned action complies with all policies 
- Iterate over tool results for correctness 
- Analyze complex information from web searches or other tools 
- Plan multi-step approaches before executing them 

## How to use the think tool effectively 
When using the think tool: 
1. Break down complex problems into clearly defined steps 
2. Identify key facts, constraints, and requirements 
3. Check for gaps in information and plan how to fill them 
4. Evaluate
Read from source at commit 1b45987df505OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-think-tool -- npx -y @cgize/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-think-tool": {
      "command": "npx",
      "args": [
        "-y",
        "@cgize/[email protected]"
      ]
    }
  }
}
03

Exposed tools (4)

3 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
clear_thoughtsdestructiveClear all thoughts recorded in the current session. Use this to start fresh if the thinking process needs to be reset.
get_thought_statsreadGet statistics about the thoughts recorded in the current session to analyze your thinking process.
get_thoughtsreadRetrieve all thoughts recorded in the current session to review your reasoning process.
thinkreadUse this tool to think about something. It will not obtain new information or change anything, but just append the thought to the log. Use it when complex reasoning or cache memory is needed, especially during long chains of tool calls, policy adherence scenarios, or sequential decision making.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_thoughts
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, ts-node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 1b45987df505full audit observations/trust-audit/mcp-server/cgize__think-tool-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-081b45987df505SAFEB89first audit
06

Questions

What is the Think Tool MCP server?

MCP Think Tool Claude Desktop

What tools does Think Tool expose?

4 in total: 3 read-only, 0 that write, and 1 that can delete or overwrite (clear_thoughts). Every one is listed on this page with its risk.

Is Think Tool safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Think Tool need?

No credential environment variables were found in its source, so it appears to need none.

How does Think Tool run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @cgize/mcp-think-tool at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (1b45987df505), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement