Atlas / MCP servers / mcpc-tech / Mcpc

McpcSAFE

mcp/mcpc-tech/mcpc-1

Build agentic-MCP servers by composing existing MCP tools.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
77 71r · 5w · 1d
Transport
sse · stdio · streamable-http
License
MIT
Stars
103
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://jsr.io/@mcpc/core) [](https://www.npmjs.com/package/@mcpc-tech/core)

Build agentic MCP servers by composing existing MCP tools.

MCPC is the SDK for building agentic MCP (Model Context Protocol) Servers. You can use it to:

  1. Create Powerful Agentic MCP Tools: Simply describe your vision in text

and reference tools from the expanding MCP community. As standard MCP tools, your agents work everywhere and collaborate seamlessly.

  1. Fine-Tune Existing Tools: Flexibly modify existing tool descriptions and

parameters, or wrap and filter results to precisely adapt them to your specific business scenarios.

  1. Build Multi-Agent Systems: By defining each agent as a MCP tool, you can

compose and orchestrate them to construct sophisticated, collaborative multi-agent systems.

Key Features

  • Portability and agent interoperability: Build once, run everywhere as MCP

tools - agents work across all MCP clients and can discover and collaborate with each other through standard MCP interfaces

  • Simple composition and fine-tuning: Compose MCP servers as building

blocks, select and customize tools, or modify their descriptions and parameters

  • Logging and tracing: Built-in MCP logging and OpenTelemetry tracing

support

  • Skills support: Define domain-specific knowledge following the

Agent Skills specification - deploy to production, share via MCP, and declare tool dependencies

  • Flexible execution modes: Multiple specialized modes to fit different

scenarios - interactive agent (agentic), AI SDK sampling (ai_sampling), AI ACP mode (ai_acp), secure code execution (code_execution), and sandbox + sampling ([code_execution_sampling](packages/plugin-code-ex

Read from source at commit b4428fdd4c6fOBSERVED · 2026-10-07
02

Exposed tools (77)

71 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
GITHUB_TOKENreadGitHub token
RecipereadA cooking recipe
aread
addwriteAdd two numbers
agentreadCommand: $TEST_COMMAND
agent1readFirst
agent2readSecond
analyze-code-changesreadAnalyze code changes for KISS principle violations when code is modified. Uses git diff to detect changes and runs analysis in background.
ask-agentreadUse this tool to ask questions to the LLM
audit-loggerreadInternal audit logging for security and compliance tracking
calculatereadCalculate value
calculatorreadA calculator agent
coding-assistantreadA coding assistant powered by Claude Code ACP. Available tools: <tool name=
compose_mcpc_configreadGenerate MCPC agent configuration from selected servers and tools.
configurablereadOriginal description
context-toolreadContext tool
custom-agentreadCustom agent
cwd-agentreadtest
demo-toolreadDemo builder config
echoreadEcho tool
existingreadExisting tool
existing-toolreadExists
failing-toolreadA tool that throws
file-managerreadFile system assistant. Available tools: <tool name=
file-organizerreadI am a smart file organizer that helps users manage their files efficiently. Available tools: <tool name=
generate-greetingreadGenerate a greeting message using AI SDK
generate-recipereadGenerate a structured recipe object using AI SDK
get-analysis-resultreadGet the result of a previous code analysis
get_env_var_schemasreadGet environment variable requirements for servers.
get_project_factreadReturn one short fact about this demo project.
greetreadGreet a user
helper-agentreadHelper agent
hidden-toolreadHidden
huge_outputreadGenerate huge output
inline-agentreadAn inline defined agent
inline-sampling-agentreadInline sampling agent
internal-toolreadInternal only
large-output-handlerreadAgent that demonstrates automatic large output handling and file storage
make-big-textwriteCreate large text output
make-small-textwriteCreate small text output
manual-agentreadAgent with manual. <tool name=
memory-agentreadI am an agent that uses in-memory transport to communicate with MCP servers. Available tools: <tool name=
my-agentreadTest agent
my-toolreadMy tool description
my_toolreadTest tool
params-agentreadAgent test. <tool name=
processreadProcess text
public-toolreadPublic tool
removablereadTest
sampling-sandbox-agentwriteA secure sandbox agent that can execute JavaScript and ask the connected MCP client
sandbox-agentreadA secure code execution agent using Deno sandbox. Available tools: <tool name=
schema-agentreadAgent that provides schemas. <tool name=
search_logsreadSearch logs
search_mcp_serversreadSearch mcpc.tech registry for MCP servers by keyword.
secure-file-deletedestructiveSecurely delete files with comprehensive validation, audit logging, and backup creation
security-validatorreadInternal security validation for sensitive file operations
simple-file-readerreadA simple file reading agent. Use <tool name=
small-output-handlerreadAgent for testing small output
stream-greetingreadStream a greeting message using AI SDK
stream-with-toolsreadStream text generation with tool calls
terminal-assistantwriteI am a terminal assistant that can help you run shell commands. Available tools: <tool name=
testreadtest
test-agentreadTest agent
test-toolreadA test tool
test-tool-callsreadTest tool calling functionality with AI SDK
test-tool1readTest tool 1
test-tool2readTest tool 2
test_toolreadA test tool
tool-alphareadAlpha tool
tool-betareadBeta tool
tool-gammareadGamma tool
tool-onereadTool one
tool-tworeadTool two
tool1readWrapped
tool2readUnwrapped
unwrapped-toolreadTest with unwrapped schema
wrapped-toolreadTest with wrapped schema
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
secure-file-delete
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.envrc
.envrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/tests/dependency_sync_test.ts:5
"../../plugin-code-execution/deno.json",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/tests/dependency_sync_test.ts:9
"../../plugin-code-execution-sampling/deno.json",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/examples/14-skills-plugin.ts:19
const projectRoot = join(__dirname, "../../..");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/examples/16-markdown-agent-file.ts:20
"../../plugin-markdown-loader/examples/codex-fork.md",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/core/examples/17-mixed-agent-sources.ts:38
"../../plugin-markdown-loader/examples/codex-fork.md",
INFOInventory / provenance · inv.oversize · CWE-1104
packages/acp-ai-provider/examples/acp-demo.gif
packages/acp-ai-provider/examples/acp-demo.gif
Why it matters. 9961804 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b4428fdd4c6ffull audit observations/trust-audit/mcp-server/mcpc-tech__mcpc-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b4428fdd4c6fSAFEB89first audit
05

Questions

What is the Mcpc MCP server?

Build agentic-MCP servers by composing existing MCP tools.

What tools does Mcpc expose?

77 in total: 71 read-only, 5 that write, and 1 that can delete or overwrite (secure-file-delete). Every one is listed on this page with its risk.

Is Mcpc safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mcpc need?

It reads GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcpc run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (b4428fdd4c6f), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement