DIY ToolsBLOCK
An MCP server that allows users to dynamically add custom tools/functions at runtime
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/diy-tools-mcp) [](./LICENSE) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://github.com/hesreallyhim/diy-tools-mcp/actions/workflows/ci.yml) [](https://mseep.ai/app/a3f05c40-4cc1-432d-b081-f5b418d00fd1)
A Model Context Protocol (MCP) server that allows you to create custom tools/functions at runtime in any programming language and expose them to Claude or other MCP clients.
Overview
The DIY Tools MCP server enables you to dynamically add custom tools without needing to write a full MCP server. Simply provide the function code, parameters schema, and the server handles the rest - validation, execution, persistence, and MCP protocol integration.
This server bridges the gap between simple function definitions and the MCP protocol, making it easy to extend Claude's capabilities with custom tools written in Python, JavaScript, Bash, Ruby, or TypeScript.
Features
- Dynamic Tool Registration: Add new tools at runtime without restarting the server
- Multi-Language Support: Write functions in Python, JavaScript, Bash, and more
- File-Based Functions: Define functions in separate files for better maintainability
- Automatic Validation: Functions are validated for syntax before registration
- Security Validation: Comprehensive security checks for file-based functions
- Persistence: Registered tools are saved and automatically loaded on server restart
- Type Safety: Full JSON Schema validation for function parameters
- Error Handling: Comprehensive error messages
186296f6a6d9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add diy-tools-mcp -- npx -y [email protected]
{
"mcpServers": {
"diy-tools-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (99)
82 read · 12 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_func | write | Add two numbers |
add_tool | write | Add a new custom tool/function to the server |
aws_file | read | Test |
backwardCompatible | read | test backward compatibility |
bashFunction | read | A Bash function |
bash_custom | read | Bash with custom entry point |
broken | read | Broken function |
chmod_danger | read | Test |
cjs_func | read | CommonJS function |
convert_temperature | read | Convert temperature between Celsius and Fahrenheit |
curl_pipe_danger | read | Test |
custom_calc | read | Calculate with custom entry point |
custom_tool | read | Custom tool |
default_entry | read | Test default entry point |
delete_file_test | destructive | Test file deletion |
delete_inline_test | destructive | Test deletion |
directory | read | Test |
doubler | read | Doubles input |
duplicate_name | read | First tool |
dynamic_require_danger | read | Test |
empty_file | read | Test |
error_function | read | Function that errors |
etc_file | read | Test |
eval_danger | read | Test |
exec_danger | write | Test |
exec_file | write | Execute file |
exec_inline | write | Execute inline |
factorial | read | Calculate factorial |
fileFunction | read | A file-based function |
file_load_test | read | Test loading file code |
file_multiply | read | File-based multiplication |
file_python_exec | write | Test file-based Python execution |
file_test | read | Test file-based function |
file_tool | read | File-based tool |
file_verbose_test | read | Test viewing file source with verbose |
file_view_test | read | Test viewing file-based source |
inline_add | write | Inline addition |
inline_func | read | Inline function |
inline_js_exec | write | Test inline JS execution |
inline_load_test | read | Test loading inline code |
inline_python_exec | write | Test inline Python execution |
inline_test | read | Test inline function |
inline_tool | read | Inline tool |
inline_verbose_test | read | Test viewing inline source with verbose |
inline_view_test | read | Test viewing inline source |
invalid | read | Invalid |
invalidJs | read | Invalid JavaScript |
invalid_both | read | Invalid tool |
invalid_neither | read | Invalid tool |
invalid_test | read | Invalid function |
jsFunction | read | A JavaScript function |
js_commonjs | read | CommonJS with custom entry point |
js_custom | read | JavaScript with custom entry point |
js_eval_danger | read | Test |
list_tools | read | List all available custom tools |
load_all_file | read | File function |
load_all_inline | read | Inline function |
math_ops | read | Math operations |
missing_entry | read | Test missing entry point |
mjs_func | read | ES module function |
multiply_func | read | Multiply two numbers |
nodeFunction | read | A Node.js function |
non_existent | read | Non-existent file |
notify_test | read | Test notification |
optimized_exec | write | Test optimized execution |
os_system_danger | read | Test |
parse_url | read | Parse a URL into its components |
pythonFunction | read | A Python function |
remove_test | destructive | Tool to remove |
remove_tool | destructive | Remove a custom tool/function from the server |
rm_danger | destructive | Test |
rubyFunction | read | A Ruby function |
ruby_custom | read | Ruby with custom entry point |
safe_add | write | Safe addition |
safe_info | read | Safe system info |
safe_text | read | Safe text operations |
schema_validation | read | Test schema validation |
ssh_file | read | Test |
subprocess_danger | read | Test |
symlink_test | read | Test |
system_info | read | Get system information |
test | read | test |
testFunction | read | A test function |
test_add | write | Test addition |
test_double | read | Test doubling |
test_echo | read | Test echo |
test_greet | read | Test greeting |
test_info | read | Test system info |
text_ops | read | Text operations |
timeout_function | read | Function that times out |
traversal | read | Test |
traversal_mixed | read | Test |
traversal_win | read | Test |
tsFunction | read | A TypeScript function |
usr_bin_file | read | Test |
validJs | read | Valid JavaScript |
view_source | read | View the source code of a registered custom tool |
whitespace_file | read | Test |
wrong_ext | read | Wrong extension |
Trust audit
BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (19)
exec(`git commit -m "${commitMessage}"`);exec(`git tag -a v${version} -m "${tagMessage}"`);exec(`git push origin v${version}`);exec(`gh release create v${version} --title "v${version}" --notes "${releaseNotes}"`);delete_file_test, delete_inline_test, remove_test, remove_tool, rm_danger
.prettierignore
it('should reject Python files with eval()', async () => {const sshPath = `${process.env.HOME}/.ssh/test.py`;const awsPath = `${process.env.HOME}/.aws/test.py`;`${process.env.HOME}/.ssh/test.py`,`${process.env.HOME}/.aws/credentials.py`,codePath: '/etc/passwd',
'/etc/passwd',
import { ToolManager } from '../../tools/manager.js';import { FunctionSpecification } from '../../types/index.js';import { logger } from '../../utils/logger.js';import { ToolManager } from '../../tools/manager.js';import { logger } from '../../utils/logger.js';@modelcontextprotocol/sdk, @types/json-schema, ajv, winston, @eslint/eslintrc, @eslint/js, @types/jest, @types/node
Gates applied: no_behavioural_pass.
186296f6a6d9full audit observations/trust-audit/mcp-server/hesreallyhim__diy-tools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 186296f6a6d9 | BLOCK | D | 61 | first audit |
Questions
What is the DIY Tools MCP server?
An MCP server that allows users to dynamically add custom tools/functions at runtime
What tools does DIY Tools expose?
99 in total: 82 read-only, 12 that write, and 5 that can delete or overwrite (delete_file_test, delete_inline_test, remove_test, remove_tool, rm_danger). Every one is listed on this page with its risk.
Is DIY Tools safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (61/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does DIY Tools need?
No credential environment variables were found in its source, so it appears to need none.
How does DIY Tools run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as diy-tools-mcp at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (186296f6a6d9), read on 2026-10-08. The repository is watched and re-audited when it changes.