McpcSAFE
Build agentic-MCP servers by composing existing MCP tools.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://jsr.io/@mcpc/core) [](https://www.npmjs.com/package/@mcpc-tech/core)
Build agentic MCP servers by composing existing MCP tools.
MCPC is the SDK for building agentic MCP (Model Context Protocol) Servers. You can use it to:
- Create Powerful Agentic MCP Tools: Simply describe your vision in text
and reference tools from the expanding MCP community. As standard MCP tools, your agents work everywhere and collaborate seamlessly.
- Fine-Tune Existing Tools: Flexibly modify existing tool descriptions and
parameters, or wrap and filter results to precisely adapt them to your specific business scenarios.
- Build Multi-Agent Systems: By defining each agent as a MCP tool, you can
compose and orchestrate them to construct sophisticated, collaborative multi-agent systems.
Key Features
- Portability and agent interoperability: Build once, run everywhere as MCP
tools - agents work across all MCP clients and can discover and collaborate with each other through standard MCP interfaces
- Simple composition and fine-tuning: Compose MCP servers as building
blocks, select and customize tools, or modify their descriptions and parameters
- Logging and tracing: Built-in MCP logging and OpenTelemetry tracing
support
- Skills support: Define domain-specific knowledge following the
Agent Skills specification - deploy to production, share via MCP, and declare tool dependencies
- Flexible execution modes: Multiple specialized modes to fit different
scenarios - interactive agent (agentic), AI SDK sampling (ai_sampling), AI ACP mode (ai_acp), secure code execution (code_execution), and sandbox + sampling ([code_execution_sampling](packages/plugin-code-ex
b4428fdd4c6fOBSERVED · 2026-10-07Exposed tools (77)
71 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
GITHUB_TOKEN | read | GitHub token |
Recipe | read | A cooking recipe |
a | read | |
add | write | Add two numbers |
agent | read | Command: $TEST_COMMAND |
agent1 | read | First |
agent2 | read | Second |
analyze-code-changes | read | Analyze code changes for KISS principle violations when code is modified. Uses git diff to detect changes and runs analysis in background. |
ask-agent | read | Use this tool to ask questions to the LLM |
audit-logger | read | Internal audit logging for security and compliance tracking |
calculate | read | Calculate value |
calculator | read | A calculator agent |
coding-assistant | read | A coding assistant powered by Claude Code ACP. Available tools: <tool name= |
compose_mcpc_config | read | Generate MCPC agent configuration from selected servers and tools. |
configurable | read | Original description |
context-tool | read | Context tool |
custom-agent | read | Custom agent |
cwd-agent | read | test |
demo-tool | read | Demo builder config |
echo | read | Echo tool |
existing | read | Existing tool |
existing-tool | read | Exists |
failing-tool | read | A tool that throws |
file-manager | read | File system assistant. Available tools: <tool name= |
file-organizer | read | I am a smart file organizer that helps users manage their files efficiently. Available tools: <tool name= |
generate-greeting | read | Generate a greeting message using AI SDK |
generate-recipe | read | Generate a structured recipe object using AI SDK |
get-analysis-result | read | Get the result of a previous code analysis |
get_env_var_schemas | read | Get environment variable requirements for servers. |
get_project_fact | read | Return one short fact about this demo project. |
greet | read | Greet a user |
helper-agent | read | Helper agent |
hidden-tool | read | Hidden |
huge_output | read | Generate huge output |
inline-agent | read | An inline defined agent |
inline-sampling-agent | read | Inline sampling agent |
internal-tool | read | Internal only |
large-output-handler | read | Agent that demonstrates automatic large output handling and file storage |
make-big-text | write | Create large text output |
make-small-text | write | Create small text output |
manual-agent | read | Agent with manual. <tool name= |
memory-agent | read | I am an agent that uses in-memory transport to communicate with MCP servers. Available tools: <tool name= |
my-agent | read | Test agent |
my-tool | read | My tool description |
my_tool | read | Test tool |
params-agent | read | Agent test. <tool name= |
process | read | Process text |
public-tool | read | Public tool |
removable | read | Test |
sampling-sandbox-agent | write | A secure sandbox agent that can execute JavaScript and ask the connected MCP client |
sandbox-agent | read | A secure code execution agent using Deno sandbox. Available tools: <tool name= |
schema-agent | read | Agent that provides schemas. <tool name= |
search_logs | read | Search logs |
search_mcp_servers | read | Search mcpc.tech registry for MCP servers by keyword. |
secure-file-delete | destructive | Securely delete files with comprehensive validation, audit logging, and backup creation |
security-validator | read | Internal security validation for sensitive file operations |
simple-file-reader | read | A simple file reading agent. Use <tool name= |
small-output-handler | read | Agent for testing small output |
stream-greeting | read | Stream a greeting message using AI SDK |
stream-with-tools | read | Stream text generation with tool calls |
terminal-assistant | write | I am a terminal assistant that can help you run shell commands. Available tools: <tool name= |
test | read | test |
test-agent | read | Test agent |
test-tool | read | A test tool |
test-tool-calls | read | Test tool calling functionality with AI SDK |
test-tool1 | read | Test tool 1 |
test-tool2 | read | Test tool 2 |
test_tool | read | A test tool |
tool-alpha | read | Alpha tool |
tool-beta | read | Beta tool |
tool-gamma | read | Gamma tool |
tool-one | read | Tool one |
tool-two | read | Tool two |
tool1 | read | Wrapped |
tool2 | read | Unwrapped |
unwrapped-tool | read | Test with unwrapped schema |
wrapped-tool | read | Test with wrapped schema |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
secure-file-delete
.envrc
"../../plugin-code-execution/deno.json",
"../../plugin-code-execution-sampling/deno.json",
const projectRoot = join(__dirname, "../../..");
"../../plugin-markdown-loader/examples/codex-fork.md",
"../../plugin-markdown-loader/examples/codex-fork.md",
packages/acp-ai-provider/examples/acp-demo.gif
Gates applied: no_behavioural_pass.
b4428fdd4c6ffull audit observations/trust-audit/mcp-server/mcpc-tech__mcpc-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b4428fdd4c6f | SAFE | B | 89 | first audit |
Questions
What is the Mcpc MCP server?
Build agentic-MCP servers by composing existing MCP tools.
What tools does Mcpc expose?
77 in total: 71 read-only, 5 that write, and 1 that can delete or overwrite (secure-file-delete). Every one is listed on this page with its risk.
Is Mcpc safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Mcpc need?
It reads GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mcpc run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (b4428fdd4c6f), read on 2026-10-07. The repository is watched and re-audited when it changes.