Agent ToolBLOCK
MCP tool server for AI coding agents -- encoding-aware file tools, binary analysis, DAP debugger, SSH/SFTP, process memory, and more
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
한국어
MCP (Model Context Protocol) tool server for AI coding agents.
Why?
Built-in tools in AI coding agents (Claude Code, Cursor, Codex, etc.) have known limitations:
- Tab indentation breaks: LLMs output spaces, but your project uses tabs. The built-in Edit tool writes spaces as-is, corrupting your indentation style.
- Encoding corruption: Editing EUC-KR, Shift-JIS, or GB18030 files silently converts them to UTF-8, breaking legacy projects.
- Too many separate tools: Making the agent find, install, and configure Redis CLI, MySQL client, SSH client, etc. is tedious and error-prone. agent-tool bundles 55 tools into one binary and exposes them on demand through compact profiles.
- No reverse engineering support: Built-in tools can't disassemble binaries, inspect PE/ELF headers, find function boundaries, or search cross-references. agent-tool includes static binary analysis (disassembly, xref, function detection), a DAP debugger, and CheatEngine-style memory tools -- giving your agent full reverse engineering capabilities.
- Network censorship: In some countries, government-level web filtering breaks plain
curl/wgetrequests. agent-tool uses ECH (Encrypted Client Hello) and DoH (DNS over HTTPS) by default to work around these restrictions.
agent-tool solves these with agent-oriented tools that preserve project conventions while keeping model context bounded.
Supported Agents
Claude Code, Codex CLI, Cursor, Windsurf, Cline, Gemini CLI, and any MCP-compatible agent.
LLM-efficient by default
The default core profile exposes only 11 schemas (including toolbox) instead of all 55. In a protocol-level measurement this reduced the serialized tool list from about 84 KB (full) to 15 KB. For the smallest stead
7ba834f75dd9OBSERVED · 2026-10-09Trust audit
BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (15 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (23)
if bytes.Contains(keyBytes, []byte("-----BEGIN OPENSSH PRIVATE KEY-----")) {KeyFile string `json:"key_file,omitempty" jsonschema:"Path to SSH private key file (e.g. ~/.ssh/id_rsa)"`
".netrc": true,
"id_rsa": true,
"id_ed25519": true,
"authorized_keys": true,
tree-sitter-c_sharp.wasm.gz
tree-sitter-cpp.wasm.gz
tree-sitter-java.wasm.gz
tree-sitter-python.wasm.gz
tree-sitter-rust.wasm.gz
sb.WriteString("\nThis may be a prompt injection attack attempting to exfiltrate secrets.\n")"776974682056697375616c2053747564696f20436f64652c2056697375616c2053747564696f206f722058616d6172696e2053747564696f20736f66747761726520746f2068656c7020796f7520646576656c6f7020616e64207465737420796f75722
{name: "malformed OpenSSH", key: []byte("-----BEGIN OPENSSH PRIVATE KEY-----\ninvalid\n-----END OPENSSH PRIVATE KEY-----\n"), want: "failed to parse OpenSSH private key", notWant: "neither valid PEM nskippedSymlinks++ // e.g. "../../etc/passwd" -> outside outputDir -> skip
if !strings.Contains(result, "IsDebuggerPresent") {{"zwj family", "👨👩👧", []string{"👨", "👨..."}},zwsp := InvisibleCharNotice("보이지않는")if got := InvisibleCharNotice("done 👨👩👧 ok"); got != "" {| **EnvVar** | Read environment variables. Sensitive values (passwords, tokens) auto-masked | ✅ |
> "Download agent-tool from https://github.com/knewstimek/agent-tool/releases/latest and run `agent-tool install`"
# Linux / macOS (add to ~/.bashrc or ~/.zshrc)
Gates applied: critical_finding, no_behavioural_pass.
7ba834f75dd9full audit observations/trust-audit/mcp-server/knewstimek__agent-tool.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 7ba834f75dd9 | BLOCK | F | 50 | first audit |
Questions
What is the Agent Tool MCP server?
MCP tool server for AI coding agents -- encoding-aware file tools, binary analysis, DAP debugger, SSH/SFTP, process memory, and more
Is Agent Tool safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (50/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Agent Tool need?
No credential environment variables were found in its source, so it appears to need none.
How does Agent Tool run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (7ba834f75dd9), read on 2026-10-09. The repository is watched and re-audited when it changes.