DirectorBLOCK
MCP Playbooks for AI agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Director MCP Playbooks for AI agents
curl -LsSf https://director.run/install.sh | sh
[](https://www.gnu.org/licenses/agpl-3.0) [](https://github.com/director-run/director/actions/workflows/ci.yml) [](https://github.com/director-run/director/actions/workflows/release.yml) [](https://www.npmjs.com/package/@director.run/cli)
Director allows you to provide playbooks to AI Agents. A playbook is a set of MCP tools, prompts and configuration, that give agents new skills. You can connect Claude, Cursor and VSCode in 1-click, or integrate manually through a single MCP endpoint.
Playbooks are portable and can easily be switched in and out of context. Director is local-first - setup and client integration takes 30 seconds. In addition, Director provides all of the MCP management functionality that you'd expect: tool filtering, logging, strong isolation, and unified OAuth.
https://github.com/user-attachments/assets/cafc0902-a854-4ee8-ac89-b7535f10c93d
Key Features
- 📚 Playbooks - Maintain sets of tools, prompts and config for different tasks or environments.
- 🚀 1-Click Integration - Switch playbooks with a single click. Currently supports Claude Code, Claude Desktop, Cursor, VSCode
- 🔗 Shareable - Playbooks are accessible through a single MCP endpoint, making them easy to share across agents.
- 🏠 Local-First - Director is local-first, designed to easily run on your own machine or infrastructure.
- 🔑 Unified OAuth - Connect to OAuth MCPs centrally, and use
0ea6ce704039OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add utilities --env SLACK_BOT_TOKEN=${SLACK_BOT_TOKEN} -- npx -y @director.run/[email protected]{
"mcpServers": {
"utilities": {
"command": "npx",
"args": [
"-y",
"@director.run/[email protected]"
],
"env": {
"SLACK_BOT_TOKEN": "${SLACK_BOT_TOKEN}"
}
}
}
}Exposed tools (153)
110 read · 35 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
API-create-a-comment | write | Create comment |
API-create-a-database | write | Create a database |
API-delete-a-block | destructive | Delete a block |
API-get-block-children | read | Retrieve block children |
API-get-self | read | Retrieve your token |
API-get-user | read | Retrieve a user\nError Responses:\n400: 400 |
API-get-users | read | List all users\nError Responses:\n400: 400 |
API-patch-block-children | write | Append block children |
API-patch-page | write | Update page properties |
API-post-database-query | write | Query a database |
API-post-page | write | Create a page |
API-post-search | write | Search by title |
API-retrieve-a-block | read | Retrieve a block |
API-retrieve-a-comment | read | Retrieve comments |
API-retrieve-a-database | read | Retrieve a database |
API-retrieve-a-page | read | Retrieve a page |
API-retrieve-a-page-property | read | Retrieve a page property item |
API-update-a-block | write | Update a block |
API-update-a-database | write | Update a database |
add_observations | write | Add new observations to existing entities in the knowledge graph |
alpha | read | foo |
apiKey | read | API Key for authentication |
apply_migration | write | Applies a migration to the database. Use this when executing DDL operations. Do not hardcode references to generated IDs in data migrations. |
arg-param | read | |
baseUrl | read | Base URL for the API |
beta | read | bar |
browser_click | read | Perform click on a web page |
browser_close | read | Close the page |
browser_console_messages | read | Returns all console messages |
browser_drag | destructive | Perform drag and drop between two elements |
browser_evaluate | read | Evaluate JavaScript expression on page or element |
browser_file_upload | write | Upload one or multiple files |
browser_handle_dialog | read | Handle a dialog |
browser_hover | read | Hover over element on page |
browser_install | write | Install the browser specified in the config. Call this if you get an error about the browser not being installed. |
browser_navigate | read | Navigate to a URL |
browser_navigate_back | read | Go back to the previous page |
browser_navigate_forward | read | Go forward to the next page |
browser_network_requests | read | Returns all network requests since loading the page |
browser_press_key | read | Press a key on the keyboard |
browser_resize | read | Resize the browser window |
browser_select_option | read | Select an option in a dropdown |
browser_snapshot | read | Capture accessibility snapshot of the current page, this is better than screenshot |
browser_tab_close | read | Close a tab |
browser_tab_list | read | List browser tabs |
browser_tab_new | read | Open a new tab |
browser_tab_select | read | Select a tab by index |
browser_take_screenshot | read | Take a screenshot of the current page. You can |
browser_type | read | Type text into editable element |
browser_wait_for | read | Wait for text to appear or disappear or a specified time to pass |
context-7 | read | Context7 MCP pulls up-to-date, version-specific documentation and code examples straight from the source — and places them directly into your prompt. |
convert_time | read | Convert time between timezones |
create_entities | write | Create multiple new entities in the knowledge graph |
create_issue | write | Create a new issue in a GitHub repository. This tool allows you to create issues with titles, descriptions, labels, assignees, and milestones. |
create_relations | write | Create multiple new relations between entities in the knowledge graph. Relations should be in active voice |
database-uri | read | Postgres database connection URI [see here](https://www.postgresql.org/docs/current/libpq-connect.html#LIBPQ-CONNSTRING-URIS) |
delete_branch | destructive | Deletes a development branch. |
delete_entities | destructive | Delete multiple entities and their associated relations from the knowledge graph |
delete_observations | destructive | Delete specific observations from entities in the knowledge graph |
delete_relations | destructive | Delete multiple relations from the knowledge graph |
deploy_edge_function | write | Deploys an Edge Function to a Supabase project. If the function already exists, this will create a new version. Example:\n\nimport \ |
env-param | read | |
execute_sql | write | Executes raw SQL in the Postgres database. Use |
existing-server | read | Existing server |
fetch | read | Retrieves and converts web content for efficient LLM usage. |
filesystem | read | Secure file operations with configurable access controls. |
fs-allowed-path | read | The path to the directory to allow filesystem operations in. |
gamma | read | baz |
generate_typescript_types | read | Generates TypeScript types for a project. |
get-library-docs | read | Fetches up-to-date documentation for a library. You must call |
get_advisors | read | Gets a list of advisory notices for the Supabase project. Use this to check for security vulnerabilities or performance improvements. Include the remediation URL as a clickable link so that the user can reference the issue themselves. It |
get_anon_key | read | Gets the anonymous API key for a project. |
get_current_time | read | Get current time in a specific timezones |
get_logs | read | Gets logs for a Supabase project by service type. Use this to help debug problems with your app. This will only return logs within the last minute. If the logs you are looking for are older than 1 minute, re-run your test to reproduce them. |
get_project_url | read | Gets the API URL for a project. |
get_stories | read | Get stories from Hacker News. The options are |
get_story_info | read | Get detailed story info from Hacker News, including the comments |
get_user_info | read | Get information about the authenticated user. This tool retrieves basic profile information and account details for the currently authenticated GitHub user. |
git | read | Provides tools to read, search, and manipulate Git repositories. |
git_add | write | Adds file contents to the staging area |
git_branch | read | List Git branches |
git_checkout | read | Switches branches |
git_commit | write | Records changes to the repository |
git_create_branch | write | Creates a new branch from an optional base branch |
git_diff | read | Shows differences between branches or commits |
git_diff_staged | write | Shows changes that are staged for commit |
git_diff_unstaged | read | Shows changes in the working directory that are not yet staged |
git_init | read | Initialize a new Git repository |
git_log | write | Shows the commit logs |
git_reset | destructive | Unstages all staged changes |
git_show | write | Shows the contents of a commit |
git_status | read | Shows the working tree status |
github | read | Provides seamless integration with GitHub APIs, enabling advanced automation and interaction capabilities for developers and tools. |
github-personal-access-token | read | |
google-calendar | read | Allows you to interact with Google Calendar integration. |
google-oauth-credentials-file | read | Full path to the Google OAuth credentials JSON file. |
hackernews | read | Provides tools for fetching information from Hacker News. |
list_branches | read | Lists all development branches of a Supabase project. This will return branch details including status which you can use to check when operations like merge/rebase/reset complete. |
list_edge_functions | read | Lists all Edge Functions in a Supabase project. |
list_extensions | read | Lists all extensions in the database. |
list_migrations | read | Lists all migrations in the database. |
list_tables | read | Lists all tables in one or more schemas. |
memory | read | Knowledge graph-based persistent memory system. |
merge_branch | write | Merges migrations and edge functions from a development branch to production. |
name | read | Name to greet |
notion | read | Connect to Notion API, enabling advanced automation and interaction capabilities for developers and tools. |
notion-create-comment | write | Add a comment to a page |
notion-create-database | write | Creates a new Notion database with the specified properties schema.\nIf no title property provided, |
notion-create-pages | write | ## Overview\nCreates one or more Notion pages, with the specified properties and content.\n## Parent\nAll pages created with a single call to this tool will have the same parent. The parent can be a Notion page ( |
notion-fetch | read | Retrieves details about a Notion entity (page or database) by URL or ID.\nProvide URL or ID in |
notion-get-comments | read | Get all comments of a page |
notion-get-user | read | Retrieve a user |
notion-get-users | read | List all users |
notion-move-pages | write | Move one or more Notion pages or databases to a new parent. |
notion-search | read | Perform a search over: - |
notion-update-database | write | Update a Notion database\ |
notion-update-page | write | ## Overview\nUpdate a Notion page\ |
open_nodes | read | Open specific nodes in the knowledge graph by their names |
playwright | read | Interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models. |
postgres | read | A Postgres MCP server with index tuning, explain plans, health checks, and safe sql execution. |
prompt-1 | read | First test prompt |
prompt-2 | read | Second test prompt |
read_graph | read | Read the entire knowledge graph |
rebase_branch | write | Rebases a development branch on production. This will effectively run any newer migrations from production onto this branch to help handle migration drift. |
reset_branch | destructive | Resets migrations of a development branch. Any untracked data or schema changes will be lost. |
resolve-library-id | read | Resolves a package/product name to a Context7-compatible library ID and returns a list of matching libraries.\n\nYou MUST call this function before |
search_nodes | read | Search for nodes in the knowledge graph based on a query |
search_stories | read | Search stories from Hacker News. It is generally recommended to use simpler queries to get a broader set of results (less than 5 words). Very targetted queries may not return any results. |
sentry | write | Enable secure connectivity between Sentry issues and debugging data, and LLM clients. |
sequential-thinking | read | Dynamic and reflective problem-solving through a structured thinking process. |
slack | read | Allows you to interact with the Slack API. |
slack-bot-token | read | Slack Bot Token (e.g. |
slack-channel-ids | read | Channel IDs, comma separated. (e.g. |
slack-team-id | read | Slack Team ID. (e.g. |
slack_add_reaction | write | Add a reaction emoji to a message |
slack_get_channel_history | read | Get recent messages from a channel |
slack_get_thread_replies | read | Get all replies in a message thread |
slack_get_user_profile | read | Get detailed profile information for a specific user |
slack_get_users | read | Get a list of all users in the workspace with their basic profile information |
slack_list_channels | read | List public or pre-defined channels in the workspace with pagination |
slack_post_message | write | Post a new message to a Slack channel |
slack_reply_to_thread | read | Reply to a specific message thread in Slack |
supabase | read | Connect your AI tools to Supabase. |
supabase-personal-access-token | read | Personal access token for Supabase. |
supabase-project-ref | read | Supabase project reference. |
test | read | test |
test-playbook-updated | read | test-playbook-updated |
test-server | read | A test server |
test-server-1 | read | Test server 1 |
test-server-2 | read | Test server 2 |
test-server-3 | read | Test server 3 |
time | read | Time and timezone conversion capabilities. |
timeout | read | Request timeout in milliseconds |
Trust audit
BLOCKgrade F · trust 51/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
DATABASE_URL: postgresql://postgres:[email protected]:5432/director-gateway-test
DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-gateway-dev
DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-gateway-test
logger.info(`[${this.name}] oAuth token exchange completed`);cd apps/registry && DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-registry-test bun run db:push
cd ../../apps/gateway && DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-gateway-test bun run db:push
apiKey: "dk_live_abc123def456ghi789jkl012",
apiKey: "sk_test_abc123def456ghi789",
apiKey: "sk_test_abc123def456ghi789",
API-delete-a-block, browser_drag, delete_branch, delete_entities, delete_observations, delete_relations, git_reset, reset_branch
.env.dev
.env.test
.env.development
.env.test
.env.dev
cd ../../apps/gateway && DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-gateway-test bun run db:push
path.join(__dirname, "../../bin/cli"),
import { gatewayClient, registryClient } from "../../client";import { gatewayClient } from "../../client";import { gatewayClient } from "../../client";expect(() => assertSecureURL("https://192.168.1.1")).toThrow(AppError);expect(() => assertSecureURL("https://192.168.1.1")).toThrow(expect(() => assertSecureURL("https://10.0.0.1")).toThrow(AppError);expect(() => assertSecureURL("https://127.0.0.1")).toThrow(AppError);expect(() => assertSecureURL("https://0.0.0.0")).toThrow(AppError);Gates applied: no_behavioural_pass.
0ea6ce704039full audit observations/trust-audit/mcp-server/fdmtl__director-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 0ea6ce704039 | BLOCK | F | 51 | first audit |
Questions
What is the Director MCP server?
MCP Playbooks for AI agents
What tools does Director expose?
153 in total: 110 read-only, 35 that write, and 8 that can delete or overwrite (API-delete-a-block, browser_drag, delete_branch, delete_entities, delete_observations). Every one is listed on this page with its risk.
Is Director safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (51/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Director need?
It reads SLACK_BOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Director run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @director.run/utilities at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (0ea6ce704039), read on 2026-09-30. The repository is watched and re-audited when it changes.