Atlas / MCP servers / hanweg / Tool Builder

Tool BuilderCAUTION

mcp/hanweg/tool-builder

MCP server that creates its own tools as needed

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
2 1r · 1w · 0d
Transport
stdio
License
Unlicense
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP Tool Builder

An MCP server that empowers LLMs to dynamically create new tools through MCP clients such as Claude Desktop.

Features

  • Create new tools by describing them in natural language
  • Requires client restart to use new tools (Claude Desktop)
  • New tools are saved as python scriptlets in ...\\mcp-tool-builder\\tools
  • New tool definitions are saved in ...\\mcp-tool-builder\\tools\tools.json

Example tools included at installation

  • getbitcoinprice: Fetches current Bitcoin price from CoinGecko
  • getweatherforecast: Gets weather for US ZIP codes (uses geopy)

Creating New Tools

Use the create_tool command in Claude Desktop (or suggest strongly!!) to create new tools dynamically

Installation

  1. Clone this repository
  2. Install dependencies:
cd mcp-tool-builder
uv venv
.venv\Scripts\activate
uv pip install -e .

Usage with Claude Desktop

Add to claude_desktop_config.json:

{
"mcpServers": {
"tool-builder": {
"command": "uv",
"args": [
"--directory", 
"PATH_TO\\mcp-tool-builder",
"run",
"tool-builder"
]
}
}
}

Read from source at commit a4c39b60da24OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-tool-builder -- uvx mcp-tool-builder
claude-desktop
{
  "mcpServers": {
    "mcp-tool-builder": {
      "command": "uvx",
      "args": [
        "mcp-tool-builder"
      ]
    }
  }
}
03

Exposed tools (2)

1 read · 1 write · 0 destructive.

ToolRiskDescription
create_toolwriteCreate a new Python tool with specified functionality
list_available_toolsreadList all currently available tools
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMInventory / provenance · inv.binary · CWE-1104
src/mcp_tool_builder/__pycache__/__init__.cpython-310.pyc
__init__.cpython-310.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/mcp_tool_builder/__pycache__/cli.cpython-310.pyc
cli.cpython-310.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/mcp_tool_builder/__pycache__/tool_builder_server.cpython-310.pyc
tool_builder_server.cpython-310.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/__pycache__/get_bitcoin_price.cpython-310.pyc
get_bitcoin_price.cpython-310.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWPrompt injection · review.reviewer_manipulation · CWE-94, CWE-1427
README.md
suggest strongly!!
Why it matters. The README instructs the agent to strongly push tool creation on users regardless of whether they asked for it, attempting to steer agent behavior beyond user intent.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha a4c39b60da24full audit observations/trust-audit/mcp-server/hanweg__tool-builder.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09a4c39b60da24CAUTIONB88first audit
06

Questions

What is the Tool Builder MCP server?

MCP server that creates its own tools as needed

What tools does Tool Builder expose?

2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Tool Builder safe to connect to an agent?

With care. The audit graded it B (88/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Tool Builder need?

No credential environment variables were found in its source, so it appears to need none.

How does Tool Builder run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-tool-builder.

How current is this page?

The grade is for one exact copy of the source (a4c39b60da24), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement