Atlas / MCP servers / fdmtl / Director

DirectorBLOCK

mcp/fdmtl/director-2

MCP Playbooks for AI agents

Verdict
BLOCK
Grade
F
Trust score
51 /100
Exposed tools
153 110r · 35w · 8d
Transport
sse · stdio · streamable-http
License
AGPL-3.0
Stars
482
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Director MCP Playbooks for AI agents

curl -LsSf https://director.run/install.sh | sh

[](https://www.gnu.org/licenses/agpl-3.0) [](https://github.com/director-run/director/actions/workflows/ci.yml) [](https://github.com/director-run/director/actions/workflows/release.yml) [](https://www.npmjs.com/package/@director.run/cli)

Director allows you to provide playbooks to AI Agents. A playbook is a set of MCP tools, prompts and configuration, that give agents new skills. You can connect Claude, Cursor and VSCode in 1-click, or integrate manually through a single MCP endpoint.

Playbooks are portable and can easily be switched in and out of context. Director is local-first - setup and client integration takes 30 seconds. In addition, Director provides all of the MCP management functionality that you'd expect: tool filtering, logging, strong isolation, and unified OAuth.

https://github.com/user-attachments/assets/cafc0902-a854-4ee8-ac89-b7535f10c93d

Key Features

  • 📚 Playbooks - Maintain sets of tools, prompts and config for different tasks or environments.
  • 🚀 1-Click Integration - Switch playbooks with a single click. Currently supports Claude Code, Claude Desktop, Cursor, VSCode
  • 🔗 Shareable - Playbooks are accessible through a single MCP endpoint, making them easy to share across agents.
  • 🏠 Local-First - Director is local-first, designed to easily run on your own machine or infrastructure.
  • 🔑 Unified OAuth - Connect to OAuth MCPs centrally, and use
Read from source at commit 0ea6ce704039OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add utilities --env SLACK_BOT_TOKEN=${SLACK_BOT_TOKEN} -- npx -y @director.run/[email protected]
claude-desktop
{
  "mcpServers": {
    "utilities": {
      "command": "npx",
      "args": [
        "-y",
        "@director.run/[email protected]"
      ],
      "env": {
        "SLACK_BOT_TOKEN": "${SLACK_BOT_TOKEN}"
      }
    }
  }
}
03

Exposed tools (153)

110 read · 35 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
API-create-a-commentwriteCreate comment
API-create-a-databasewriteCreate a database
API-delete-a-blockdestructiveDelete a block
API-get-block-childrenreadRetrieve block children
API-get-selfreadRetrieve your token
API-get-userreadRetrieve a user\nError Responses:\n400: 400
API-get-usersreadList all users\nError Responses:\n400: 400
API-patch-block-childrenwriteAppend block children
API-patch-pagewriteUpdate page properties
API-post-database-querywriteQuery a database
API-post-pagewriteCreate a page
API-post-searchwriteSearch by title
API-retrieve-a-blockreadRetrieve a block
API-retrieve-a-commentreadRetrieve comments
API-retrieve-a-databasereadRetrieve a database
API-retrieve-a-pagereadRetrieve a page
API-retrieve-a-page-propertyreadRetrieve a page property item
API-update-a-blockwriteUpdate a block
API-update-a-databasewriteUpdate a database
add_observationswriteAdd new observations to existing entities in the knowledge graph
alphareadfoo
apiKeyreadAPI Key for authentication
apply_migrationwriteApplies a migration to the database. Use this when executing DDL operations. Do not hardcode references to generated IDs in data migrations.
arg-paramread
baseUrlreadBase URL for the API
betareadbar
browser_clickreadPerform click on a web page
browser_closereadClose the page
browser_console_messagesreadReturns all console messages
browser_dragdestructivePerform drag and drop between two elements
browser_evaluatereadEvaluate JavaScript expression on page or element
browser_file_uploadwriteUpload one or multiple files
browser_handle_dialogreadHandle a dialog
browser_hoverreadHover over element on page
browser_installwriteInstall the browser specified in the config. Call this if you get an error about the browser not being installed.
browser_navigatereadNavigate to a URL
browser_navigate_backreadGo back to the previous page
browser_navigate_forwardreadGo forward to the next page
browser_network_requestsreadReturns all network requests since loading the page
browser_press_keyreadPress a key on the keyboard
browser_resizereadResize the browser window
browser_select_optionreadSelect an option in a dropdown
browser_snapshotreadCapture accessibility snapshot of the current page, this is better than screenshot
browser_tab_closereadClose a tab
browser_tab_listreadList browser tabs
browser_tab_newreadOpen a new tab
browser_tab_selectreadSelect a tab by index
browser_take_screenshotreadTake a screenshot of the current page. You can
browser_typereadType text into editable element
browser_wait_forreadWait for text to appear or disappear or a specified time to pass
context-7readContext7 MCP pulls up-to-date, version-specific documentation and code examples straight from the source — and places them directly into your prompt.
convert_timereadConvert time between timezones
create_entitieswriteCreate multiple new entities in the knowledge graph
create_issuewriteCreate a new issue in a GitHub repository. This tool allows you to create issues with titles, descriptions, labels, assignees, and milestones.
create_relationswriteCreate multiple new relations between entities in the knowledge graph. Relations should be in active voice
database-urireadPostgres database connection URI [see here](https://www.postgresql.org/docs/current/libpq-connect.html#LIBPQ-CONNSTRING-URIS)
delete_branchdestructiveDeletes a development branch.
delete_entitiesdestructiveDelete multiple entities and their associated relations from the knowledge graph
delete_observationsdestructiveDelete specific observations from entities in the knowledge graph
delete_relationsdestructiveDelete multiple relations from the knowledge graph
deploy_edge_functionwriteDeploys an Edge Function to a Supabase project. If the function already exists, this will create a new version. Example:\n\nimport \
env-paramread
execute_sqlwriteExecutes raw SQL in the Postgres database. Use
existing-serverreadExisting server
fetchreadRetrieves and converts web content for efficient LLM usage.
filesystemreadSecure file operations with configurable access controls.
fs-allowed-pathreadThe path to the directory to allow filesystem operations in.
gammareadbaz
generate_typescript_typesreadGenerates TypeScript types for a project.
get-library-docsreadFetches up-to-date documentation for a library. You must call
get_advisorsreadGets a list of advisory notices for the Supabase project. Use this to check for security vulnerabilities or performance improvements. Include the remediation URL as a clickable link so that the user can reference the issue themselves. It
get_anon_keyreadGets the anonymous API key for a project.
get_current_timereadGet current time in a specific timezones
get_logsreadGets logs for a Supabase project by service type. Use this to help debug problems with your app. This will only return logs within the last minute. If the logs you are looking for are older than 1 minute, re-run your test to reproduce them.
get_project_urlreadGets the API URL for a project.
get_storiesreadGet stories from Hacker News. The options are
get_story_inforeadGet detailed story info from Hacker News, including the comments
get_user_inforeadGet information about the authenticated user. This tool retrieves basic profile information and account details for the currently authenticated GitHub user.
gitreadProvides tools to read, search, and manipulate Git repositories.
git_addwriteAdds file contents to the staging area
git_branchreadList Git branches
git_checkoutreadSwitches branches
git_commitwriteRecords changes to the repository
git_create_branchwriteCreates a new branch from an optional base branch
git_diffreadShows differences between branches or commits
git_diff_stagedwriteShows changes that are staged for commit
git_diff_unstagedreadShows changes in the working directory that are not yet staged
git_initreadInitialize a new Git repository
git_logwriteShows the commit logs
git_resetdestructiveUnstages all staged changes
git_showwriteShows the contents of a commit
git_statusreadShows the working tree status
githubreadProvides seamless integration with GitHub APIs, enabling advanced automation and interaction capabilities for developers and tools.
github-personal-access-tokenread
google-calendarreadAllows you to interact with Google Calendar integration.
google-oauth-credentials-filereadFull path to the Google OAuth credentials JSON file.
hackernewsreadProvides tools for fetching information from Hacker News.
list_branchesreadLists all development branches of a Supabase project. This will return branch details including status which you can use to check when operations like merge/rebase/reset complete.
list_edge_functionsreadLists all Edge Functions in a Supabase project.
list_extensionsreadLists all extensions in the database.
list_migrationsreadLists all migrations in the database.
list_tablesreadLists all tables in one or more schemas.
memoryreadKnowledge graph-based persistent memory system.
merge_branchwriteMerges migrations and edge functions from a development branch to production.
namereadName to greet
notionreadConnect to Notion API, enabling advanced automation and interaction capabilities for developers and tools.
notion-create-commentwriteAdd a comment to a page
notion-create-databasewriteCreates a new Notion database with the specified properties schema.\nIf no title property provided,
notion-create-pageswrite## Overview\nCreates one or more Notion pages, with the specified properties and content.\n## Parent\nAll pages created with a single call to this tool will have the same parent. The parent can be a Notion page (
notion-fetchreadRetrieves details about a Notion entity (page or database) by URL or ID.\nProvide URL or ID in
notion-get-commentsreadGet all comments of a page
notion-get-userreadRetrieve a user
notion-get-usersreadList all users
notion-move-pageswriteMove one or more Notion pages or databases to a new parent.
notion-searchreadPerform a search over: -
notion-update-databasewriteUpdate a Notion database\
notion-update-pagewrite## Overview\nUpdate a Notion page\
open_nodesreadOpen specific nodes in the knowledge graph by their names
playwrightreadInteract with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.
postgresreadA Postgres MCP server with index tuning, explain plans, health checks, and safe sql execution.
prompt-1readFirst test prompt
prompt-2readSecond test prompt
read_graphreadRead the entire knowledge graph
rebase_branchwriteRebases a development branch on production. This will effectively run any newer migrations from production onto this branch to help handle migration drift.
reset_branchdestructiveResets migrations of a development branch. Any untracked data or schema changes will be lost.
resolve-library-idreadResolves a package/product name to a Context7-compatible library ID and returns a list of matching libraries.\n\nYou MUST call this function before
search_nodesreadSearch for nodes in the knowledge graph based on a query
search_storiesreadSearch stories from Hacker News. It is generally recommended to use simpler queries to get a broader set of results (less than 5 words). Very targetted queries may not return any results.
sentrywriteEnable secure connectivity between Sentry issues and debugging data, and LLM clients.
sequential-thinkingreadDynamic and reflective problem-solving through a structured thinking process.
slackreadAllows you to interact with the Slack API.
slack-bot-tokenreadSlack Bot Token (e.g.
slack-channel-idsreadChannel IDs, comma separated. (e.g.
slack-team-idreadSlack Team ID. (e.g.
slack_add_reactionwriteAdd a reaction emoji to a message
slack_get_channel_historyreadGet recent messages from a channel
slack_get_thread_repliesreadGet all replies in a message thread
slack_get_user_profilereadGet detailed profile information for a specific user
slack_get_usersreadGet a list of all users in the workspace with their basic profile information
slack_list_channelsreadList public or pre-defined channels in the workspace with pagination
slack_post_messagewritePost a new message to a Slack channel
slack_reply_to_threadreadReply to a specific message thread in Slack
supabasereadConnect your AI tools to Supabase.
supabase-personal-access-tokenreadPersonal access token for Supabase.
supabase-project-refreadSupabase project reference.
testreadtest
test-playbook-updatedreadtest-playbook-updated
test-serverreadA test server
test-server-1readTest server 1
test-server-2readTest server 2
test-server-3readTest server 3
timereadTime and timezone conversion capabilities.
timeoutreadRequest timeout in milliseconds
04

Trust audit

BLOCKgrade F · trust 51/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (10 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
apps/gateway/docker-compose.yml:22
DATABASE_URL: postgresql://postgres:[email protected]:5432/director-gateway-test
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
apps/gateway/env/.env.development:1
DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-gateway-dev
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
apps/gateway/env/.env.test:1
DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-gateway-test
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/mcp/src/client/http-client.ts:216
logger.info(`[${this.name}] oAuth token exchange completed`);
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/__ci.yml:129
cd apps/registry && DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-registry-test bun run db:push
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/__ci.yml:130
cd ../../apps/gateway && DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-gateway-test bun run db:push
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
apps/studio/src/kitchen-sink/lib/fixtures.ts:168
apiKey: "dk_live_abc123def456ghi789jkl012",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
apps/studio/src/pages/onboarding.stories.tsx:12
apiKey: "sk_test_abc123def456ghi789",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
apps/studio/src/pages/playbook-detail.stories.tsx:31
apiKey: "sk_test_abc123def456ghi789",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
API-delete-a-block, browser_drag, delete_branch, delete_entities, delete_observations, delete_relations, git_reset, reset_branch
Why it matters. 8 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/cli/env/.env.dev
.env.dev
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/cli/env/.env.test
.env.test
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/gateway/env/.env.development
.env.development
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/gateway/env/.env.test
.env.test
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/registry/env/.env.dev
.env.dev
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/__ci.yml:130
cd ../../apps/gateway && DATABASE_URL=postgresql://postgres:travel-china-spend-nothing@localhost:5432/director-gateway-test bun run db:push
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/cli/src/commands/core.test.ts:18
path.join(__dirname, "../../bin/cli"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/cli/src/commands/core/add.ts:10
import { gatewayClient, registryClient } from "../../client";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/cli/src/commands/core/authenticate.ts:4
import { gatewayClient } from "../../client";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/cli/src/commands/core/connect.ts:8
import { gatewayClient } from "../../client";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/utilities/src/security.test.ts:31
expect(() => assertSecureURL("https://192.168.1.1")).toThrow(AppError);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/utilities/src/security.test.ts:32
expect(() => assertSecureURL("https://192.168.1.1")).toThrow(
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/utilities/src/security.test.ts:35
expect(() => assertSecureURL("https://10.0.0.1")).toThrow(AppError);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/utilities/src/security.test.ts:36
expect(() => assertSecureURL("https://127.0.0.1")).toThrow(AppError);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/utilities/src/security.test.ts:37
expect(() => assertSecureURL("https://0.0.0.0")).toThrow(AppError);

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 0ea6ce704039full audit observations/trust-audit/mcp-server/fdmtl__director-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-300ea6ce704039BLOCKF51first audit
06

Questions

What is the Director MCP server?

MCP Playbooks for AI agents

What tools does Director expose?

153 in total: 110 read-only, 35 that write, and 8 that can delete or overwrite (API-delete-a-block, browser_drag, delete_branch, delete_entities, delete_observations). Every one is listed on this page with its risk.

Is Director safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (51/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Director need?

It reads SLACK_BOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Director run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @director.run/utilities at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (0ea6ce704039), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement