Atlas / MCP servers / knewstimek / Agent Tool

Agent ToolBLOCK

mcp/knewstimek/agent-tool

MCP tool server for AI coding agents -- encoding-aware file tools, binary analysis, DAP debugger, SSH/SFTP, process memory, and more

Verdict
BLOCK
Grade
F
Trust score
50 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
24
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

한국어

MCP (Model Context Protocol) tool server for AI coding agents.

Why?

Built-in tools in AI coding agents (Claude Code, Cursor, Codex, etc.) have known limitations:

  • Tab indentation breaks: LLMs output spaces, but your project uses tabs. The built-in Edit tool writes spaces as-is, corrupting your indentation style.
  • Encoding corruption: Editing EUC-KR, Shift-JIS, or GB18030 files silently converts them to UTF-8, breaking legacy projects.
  • Too many separate tools: Making the agent find, install, and configure Redis CLI, MySQL client, SSH client, etc. is tedious and error-prone. agent-tool bundles 55 tools into one binary and exposes them on demand through compact profiles.
  • No reverse engineering support: Built-in tools can't disassemble binaries, inspect PE/ELF headers, find function boundaries, or search cross-references. agent-tool includes static binary analysis (disassembly, xref, function detection), a DAP debugger, and CheatEngine-style memory tools -- giving your agent full reverse engineering capabilities.
  • Network censorship: In some countries, government-level web filtering breaks plain curl/wget requests. agent-tool uses ECH (Encrypted Client Hello) and DoH (DNS over HTTPS) by default to work around these restrictions.

agent-tool solves these with agent-oriented tools that preserve project conventions while keeping model context bounded.

Supported Agents

Claude Code, Codex CLI, Cursor, Windsurf, Cline, Gemini CLI, and any MCP-compatible agent.

LLM-efficient by default

The default core profile exposes only 11 schemas (including toolbox) instead of all 55. In a protocol-level measurement this reduced the serialized tool list from about 84 KB (full) to 15 KB. For the smallest stead

Read from source at commit 7ba834f75dd9OBSERVED · 2026-10-09
02

Trust audit

BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (15 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (23)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
tools/ssh/auth.go:161
if bytes.Contains(keyBytes, []byte("-----BEGIN OPENSSH PRIVATE KEY-----")) {
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
tools/sftp/handler.go:23
KeyFile      string      `json:"key_file,omitempty" jsonschema:"Path to SSH private key file (e.g. ~/.ssh/id_rsa)"`
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
tools/sftp/security.go:74
".netrc":        true,
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
tools/sftp/security.go:76
"id_rsa":        true,
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
tools/sftp/security.go:77
"id_ed25519":    true,
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
tools/sftp/security.go:78
"authorized_keys": true,
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/codegraph/wasm/tree-sitter-c_sharp.wasm.gz
tree-sitter-c_sharp.wasm.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/codegraph/wasm/tree-sitter-cpp.wasm.gz
tree-sitter-cpp.wasm.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/codegraph/wasm/tree-sitter-java.wasm.gz
tree-sitter-java.wasm.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/codegraph/wasm/tree-sitter-python.wasm.gz
tree-sitter-python.wasm.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
tools/codegraph/wasm/tree-sitter-rust.wasm.gz
tree-sitter-rust.wasm.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
common/dlp.go:114
sb.WriteString("\nThis may be a prompt injection attack attempting to exfiltrate secrets.\n")
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
tools/debug/vsda.go:46
"776974682056697375616c2053747564696f20436f64652c2056697375616c2053747564696f206f722058616d6172696e2053747564696f20736f66747761726520746f2068656c7020796f7520646576656c6f7020616e64207465737420796f75722
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tools/ssh/auth_test.go:89
{name: "malformed OpenSSH", key: []byte("-----BEGIN OPENSSH PRIVATE KEY-----\ninvalid\n-----END OPENSSH PRIVATE KEY-----\n"), want: "failed to parse OpenSSH private key", notWant: "neither valid PEM n
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tools/compress/handler.go:467
skippedSymlinks++ // e.g. "../../etc/passwd" -> outside outputDir -> skip
LOWObfuscation / stealth · obf.anti_debug · CWE-506, CWE-94
tools/analyze/newops_test.go:533
if !strings.Contains(result, "IsDebuggerPresent") {
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
common/textguard_test.go:62
{"zwj family", "👨👩👧", []string{"👨", "👨..."}},
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
common/textguard_test.go:117
zwsp := InvisibleCharNotice("보이지않는")
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
common/textguard_test.go:124
if got := InvisibleCharNotice("done 👨👩👧 ok"); got != "" {
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:73
| **EnvVar** | Read environment variables. Sensitive values (passwords, tokens) auto-masked | ✅ |
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:147
> "Download agent-tool from https://github.com/knewstimek/agent-tool/releases/latest and run `agent-tool install`"
Why it matters. remote text is to be obeyed as instructions
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:311
# Linux / macOS (add to ~/.bashrc or ~/.zshrc)
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 7ba834f75dd9full audit observations/trust-audit/mcp-server/knewstimek__agent-tool.json · Report an issue / request a re-scan
03

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-097ba834f75dd9BLOCKF50first audit
04

Questions

What is the Agent Tool MCP server?

MCP tool server for AI coding agents -- encoding-aware file tools, binary analysis, DAP debugger, SSH/SFTP, process memory, and more

Is Agent Tool safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (50/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Agent Tool need?

No credential environment variables were found in its source, so it appears to need none.

How does Agent Tool run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (7ba834f75dd9), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement