Atlas / MCP servers / hesreallyhim / DIY Tools

DIY ToolsBLOCK

mcp/hesreallyhim/diy-tools

An MCP server that allows users to dynamically add custom tools/functions at runtime

Verdict
BLOCK
Grade
D
Trust score
61 /100
Exposed tools
99 82r · 12w · 5d
Transport
stdio
License
MIT
Stars
44
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/diy-tools-mcp) [](./LICENSE) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://github.com/hesreallyhim/diy-tools-mcp/actions/workflows/ci.yml) [](https://mseep.ai/app/a3f05c40-4cc1-432d-b081-f5b418d00fd1)

A Model Context Protocol (MCP) server that allows you to create custom tools/functions at runtime in any programming language and expose them to Claude or other MCP clients.

Overview

The DIY Tools MCP server enables you to dynamically add custom tools without needing to write a full MCP server. Simply provide the function code, parameters schema, and the server handles the rest - validation, execution, persistence, and MCP protocol integration.

This server bridges the gap between simple function definitions and the MCP protocol, making it easy to extend Claude's capabilities with custom tools written in Python, JavaScript, Bash, Ruby, or TypeScript.

Features

  • Dynamic Tool Registration: Add new tools at runtime without restarting the server
  • Multi-Language Support: Write functions in Python, JavaScript, Bash, and more
  • File-Based Functions: Define functions in separate files for better maintainability
  • Automatic Validation: Functions are validated for syntax before registration
  • Security Validation: Comprehensive security checks for file-based functions
  • Persistence: Registered tools are saved and automatically loaded on server restart
  • Type Safety: Full JSON Schema validation for function parameters
  • Error Handling: Comprehensive error messages
Read from source at commit 186296f6a6d9OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add diy-tools-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "diy-tools-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (99)

82 read · 12 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_funcwriteAdd two numbers
add_toolwriteAdd a new custom tool/function to the server
aws_filereadTest
backwardCompatiblereadtest backward compatibility
bashFunctionreadA Bash function
bash_customreadBash with custom entry point
brokenreadBroken function
chmod_dangerreadTest
cjs_funcreadCommonJS function
convert_temperaturereadConvert temperature between Celsius and Fahrenheit
curl_pipe_dangerreadTest
custom_calcreadCalculate with custom entry point
custom_toolreadCustom tool
default_entryreadTest default entry point
delete_file_testdestructiveTest file deletion
delete_inline_testdestructiveTest deletion
directoryreadTest
doublerreadDoubles input
duplicate_namereadFirst tool
dynamic_require_dangerreadTest
empty_filereadTest
error_functionreadFunction that errors
etc_filereadTest
eval_dangerreadTest
exec_dangerwriteTest
exec_filewriteExecute file
exec_inlinewriteExecute inline
factorialreadCalculate factorial
fileFunctionreadA file-based function
file_load_testreadTest loading file code
file_multiplyreadFile-based multiplication
file_python_execwriteTest file-based Python execution
file_testreadTest file-based function
file_toolreadFile-based tool
file_verbose_testreadTest viewing file source with verbose
file_view_testreadTest viewing file-based source
inline_addwriteInline addition
inline_funcreadInline function
inline_js_execwriteTest inline JS execution
inline_load_testreadTest loading inline code
inline_python_execwriteTest inline Python execution
inline_testreadTest inline function
inline_toolreadInline tool
inline_verbose_testreadTest viewing inline source with verbose
inline_view_testreadTest viewing inline source
invalidreadInvalid
invalidJsreadInvalid JavaScript
invalid_bothreadInvalid tool
invalid_neitherreadInvalid tool
invalid_testreadInvalid function
jsFunctionreadA JavaScript function
js_commonjsreadCommonJS with custom entry point
js_customreadJavaScript with custom entry point
js_eval_dangerreadTest
list_toolsreadList all available custom tools
load_all_filereadFile function
load_all_inlinereadInline function
math_opsreadMath operations
missing_entryreadTest missing entry point
mjs_funcreadES module function
multiply_funcreadMultiply two numbers
nodeFunctionreadA Node.js function
non_existentreadNon-existent file
notify_testreadTest notification
optimized_execwriteTest optimized execution
os_system_dangerreadTest
parse_urlreadParse a URL into its components
pythonFunctionreadA Python function
remove_testdestructiveTool to remove
remove_tooldestructiveRemove a custom tool/function from the server
rm_dangerdestructiveTest
rubyFunctionreadA Ruby function
ruby_customreadRuby with custom entry point
safe_addwriteSafe addition
safe_inforeadSafe system info
safe_textreadSafe text operations
schema_validationreadTest schema validation
ssh_filereadTest
subprocess_dangerreadTest
symlink_testreadTest
system_inforeadGet system information
testreadtest
testFunctionreadA test function
test_addwriteTest addition
test_doublereadTest doubling
test_echoreadTest echo
test_greetreadTest greeting
test_inforeadTest system info
text_opsreadText operations
timeout_functionreadFunction that times out
traversalreadTest
traversal_mixedreadTest
traversal_winreadTest
tsFunctionreadA TypeScript function
usr_bin_filereadTest
validJsreadValid JavaScript
view_sourcereadView the source code of a registered custom tool
whitespace_filereadTest
wrong_extreadWrong extension
04

Trust audit

BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release.js:96
exec(`git commit -m "${commitMessage}"`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release.js:103
exec(`git tag -a v${version} -m "${tagMessage}"`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release.js:108
exec(`git push origin v${version}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release.js:129
exec(`gh release create v${version} --title "v${version}" --notes "${releaseNotes}"`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file_test, delete_inline_test, remove_test, remove_tool, rm_danger
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/__tests__/integration/security.test.ts:135
it('should reject Python files with eval()', async () => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/__tests__/integration/security.test.ts:372
const sshPath = `${process.env.HOME}/.ssh/test.py`;
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/__tests__/integration/security.test.ts:385
const awsPath = `${process.env.HOME}/.aws/test.py`;
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/utils/__tests__/security.test.ts:254
`${process.env.HOME}/.ssh/test.py`,
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/utils/__tests__/security.test.ts:255
`${process.env.HOME}/.aws/credentials.py`,
Why it matters. touches a credential store
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/__tests__/integration/security.test.ts:353
codePath: '/etc/passwd',
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/utils/__tests__/security.test.ts:252
'/etc/passwd',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/integration/file-based-functions.test.ts:2
import { ToolManager } from '../../tools/manager.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/integration/file-based-functions.test.ts:6
import { FunctionSpecification } from '../../types/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/integration/file-based-functions.test.ts:7
import { logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/integration/security.test.ts:2
import { ToolManager } from '../../tools/manager.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/integration/security.test.ts:6
import { logger } from '../../utils/logger.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/json-schema, ajv, winston, @eslint/eslintrc, @eslint/js, @types/jest, @types/node
Why it matters. 22 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 186296f6a6d9full audit observations/trust-audit/mcp-server/hesreallyhim__diy-tools.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08186296f6a6d9BLOCKD61first audit
06

Questions

What is the DIY Tools MCP server?

An MCP server that allows users to dynamically add custom tools/functions at runtime

What tools does DIY Tools expose?

99 in total: 82 read-only, 12 that write, and 5 that can delete or overwrite (delete_file_test, delete_inline_test, remove_test, remove_tool, rm_danger). Every one is listed on this page with its risk.

Is DIY Tools safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (61/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does DIY Tools need?

No credential environment variables were found in its source, so it appears to need none.

How does DIY Tools run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as diy-tools-mcp at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (186296f6a6d9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement