Atlas / MCP servers / izumin5210 / Any Script

Any ScriptSAFE

mcp/izumin5210/any-script

An MCP server that exposes arbitrary CLI tools and shell scripts as MCP Tools

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
28 28r · 0w · 0d
Transport
stdio
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/izumin5210-any-script-mcp)

An MCP server that exposes arbitrary CLI tools and shell scripts as MCP Tools

日本語版

Overview

An MCP server that publishes commands defined in YAML files as MCP Tools. By defining tools in a configuration file, you can execute arbitrary shell scripts from MCP clients.

Installation

npx

Claude Code:

$ claude mcp add any-script \
-s user \
-- npx any-script-mcp

json:

{
"mcpServers": {
"any-script": {
"command": "npx",
"args": ["any-script-mcp"]
}
}
}

Configuration

Create a configuration file at $XDG_CONFIG_HOME/any-script-mcp/config.yaml (typically ~/.config/any-script-mcp/config.yaml).

You can also specify custom configuration file paths using the ANY_SCRIPT_MCP_CONFIG environment variable:

# Single configuration file
$ ANY_SCRIPT_MCP_CONFIG=/path/to/custom/config.yaml npx any-script-mcp

# Multiple configuration files (Unix/macOS - separated by colon)
$ ANY_SCRIPT_MCP_CONFIG=/path/to/custom.yaml:$XDG_CONFIG_HOME/any-script-mcp/config.yaml npx any-script-mcp

# Multiple configuration files (Windows - separated by semicolon)
$ ANY_SCRIPT_MCP_CONFIG=C:\path\to\custom.yaml;%APPDATA%\any-script-mcp\config.yaml npx any-script-mcp

When multiple configuration files are specified:

  • All tools from all files are merged into a single collection
  • If the same tool name appears in multiple files, the first occurrence takes precedence
  • At least one valid configuration file must be successfully loaded
  • This is useful for separating common tools from project-specific or personal customizations

Testing Your Configuration

You can test your configuration using the MCP Inspector:

$ npx @modelcontextprotocol/inspector npx any-script-mcp

This will open a web inter

Read from source at commit c40770e3dff7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add any-script-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "any-script-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (28)

28 read · 0 write · 0 destructive.

ToolRiskDescription
all_typesreadTest all input types
boolean_testreadTest boolean inputs
compatibility_testreadTest backward compatibility
complex_json_testreadTest INPUTS_JSON with complex data
custom_shell_testreadTest custom shell command
default_shell_testreadTest default shell from config
default_timeout_testreadTest default timeout
echo_testreadTest echo
error_testreadTest execution errors
existing_toolreadExisting tool
hyphen_testreadTest hyphenated names
json_testreadTest INPUTS_JSON environment variable
json_type_testreadTest INPUTS_JSON with types
multi_testreadTest multiple inputs
multiline_testreadTest multiline scripts
no_inputsreadTool without inputs
node_json_testreadTest INPUTS_JSON with Node.js
node_testreadTest Node.js execution
optional_testreadTest optional parameters
placeholder_testreadTest {0} placeholder replacement
python_json_testreadTest INPUTS_JSON with Python
required_testreadTest required parameters
sh_testreadTest sh shell
timeout_success_testreadTest successful execution with timeout
timeout_testreadTest custom timeout
tool_onereadFirst tool
tool_tworeadSecond tool
type_testreadTest parameter types
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, execa, xdg-basedir, yaml, zod, vitest, zod-to-json-schema
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c40770e3dff7full audit observations/trust-audit/mcp-server/izumin5210__any-script.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c40770e3dff7SAFEB89first audit
06

Questions

What is the Any Script MCP server?

An MCP server that exposes arbitrary CLI tools and shell scripts as MCP Tools

What tools does Any Script expose?

28 in total: 28 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Any Script safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Any Script need?

No credential environment variables were found in its source, so it appears to need none.

How does Any Script run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as any-script-mcp at 0.3.0.

How current is this page?

The grade is for one exact copy of the source (c40770e3dff7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement