NCPBLOCK
Natural Context Provider (NCP). Your MCPs, supercharged. Find any tool instantly, load on demand, run on schedule, ready for any client. Smart loading saves tokens and energy.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@portel/ncp) [](https://www.npmjs.com/package/@portel/ncp) [](https://github.com/portel-dev/ncp/releases) [](https://github.com/portel-dev/ncp/releases/latest) [](https://www.elastic.co/licensing/elastic-license) [](https://modelcontextprotocol.io/)
1 MCP to rule them all
Your MCPs, supercharged. Find any tool instantly, execute with code mode, run on schedule, discover skills, load Photons, ready for any client. Smart loading saves tokens and energy.
Related Portel project: Photon turns TypeScript methods into reliable agent-facing capabilities: MCP tools, embedded app UIs, CLI commands, web routes, schedules, webhooks, retries, and Beam interfaces. NCP helps agents discover and operate tools; Photon helps developers build the tools and apps agents can trust.
💍 What is NCP?
Instead of your AI juggling 50+ tools scattered across different MCPs, NCP gives it a single, unified interface with code mode execution, scheduling, skills discovery, and custom Photons.
Your AI sees just 2-3 simple tools:
- `find` - Search for any tool, skill, or Photon: "I need to read a file" → finds the right tool automatically
- `code` - Execute TypeScript directly: `await github.create
d471a4f48d87OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ncp -- npx -y @portel/[email protected]
Exposed tools (200)
239 read · 86 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
7z | read | 7-Zip file archiver |
add | write | Add MCP server(s) to NCP with smart auto-detection of input type. Supports multiple modes: (1) SINGLE: Add one MCP from registry or manual config (e.g., |
add_audio | write | Add audio track to video |
add_subtitles | write | Add subtitles to video |
adjust_volume | read | Adjust audio volume level |
advanced-operations | write | Create multiple files, read directory contents, update existing resources, and delete old data |
ag | read | The Silver Searcher |
all | read | Universal profile with all configured MCP servers |
alpaca | read | Stock and options trading with real-time market data and portfolio management |
another-tool | read | Another |
ansible | read | IT automation tool |
approve_dangerous_operation | read | Request approval for potentially dangerous operations |
apt | read | Advanced Package Tool |
atomic-tool | read | Test |
auth0 | read | Identity and access management with authentication, authorization, and user management |
awk | read | Pattern scanning and processing language |
aws | read | Amazon Web Services integration for EC2, S3, Lambda, and cloud resource management |
az | read | Azure command-line interface |
azure | read | Microsoft Azure services including storage, compute, databases, and AI services |
basename | read | Strip directory and suffix from filenames |
brave-search | read | Web search capabilities with privacy-focused results and real-time information |
brew | read | Homebrew package manager |
bright-data | read | Discover, extract, and interact with web data through advanced scraping infrastructure |
browserbase | read | Automate browser interactions in the cloud for web scraping and testing |
build_image | write | Build Docker images from Dockerfile with build context. Create custom images, package applications. |
cal | read | Display a calendar |
calendar | read | Calendar scheduling and booking management across platforms |
camelCaseToolName_with-hyphens | read | Tool with complex naming patterns |
cargo | read | Rust package manager |
change_codec | read | Change video/audio codec |
check_system_info | read | Get system information including resources, processes, and status. Monitor system health, check resources. |
chmod | read | Change file mode bits |
choco | read | Chocolatey package manager |
chown | read | Change file owner and group |
circleci | read | CircleCI integration to monitor builds, fix failures, and manage CI/CD pipelines |
click_element | read | Click on web page elements using selectors. Click buttons, links, form elements. |
clickhouse | read | ClickHouse analytics database for real-time data processing and OLAP queries |
cloudflare | write | Deploy, configure and manage Cloudflare CDN, security, and edge computing services |
cmd | read | Windows Command Prompt |
code | write | Execute TypeScript code with automatic tool discovery and parameter mapping. **PRIMARY METHOD - ncp.do(intent, params):** Single-call execution with embedding-based param matching. No need to know exact tool names or param schemas! ncp.do( |
command | write | Command to execute |
commit | write | Commit changes to git repository with message |
commit_changes | write | Create Git commits to save changes to version history. Save progress, commit code changes, record modifications. |
compress | read | Compress/reduce video file size |
conditional-workflow | read | Smart workflow that adapts based on conditions |
confidence | read | Match confidence (0.0-1.0) |
config_type | read | Type of configuration needed |
configure_mcp | read | Request user input for MCP configuration (env vars, args) |
confirm_add_mcp | write | Request user confirmation before adding a new MCP server |
confirm_operation | read | Request user confirmation before executing modifier operations |
confirm_remove_mcp | destructive | Request user confirmation before removing an MCP server |
convert | read | Convert video/audio to different format |
copy | read | Copy files between different locations |
copy_file | read | Copy files to different locations for backup or organization |
cp | read | Copy files and directories |
create | write | Create scheduled job with cron/natural language timing. |
create_branch | write | Create new Git branches for feature development and parallel work. Start new features, create development branches. |
create_channel | write | Create new Slack channels for team communication |
create_database | write | Create structured Notion databases with properties and schema. Set up project tracking, create data tables. |
create_directory | write | Create new directories and folder structures. Organize files, set up project structure, create folder hierarchies. |
create_ec2_instance | write | Launch new EC2 virtual machine instances with configuration. Create servers, deploy applications to cloud. |
create_gif | write | Convert video to animated GIF |
create_issue | write | Create GitHub issues for bug reports and feature requests. Report bugs, request features, track tasks. |
create_lambda | write | Create AWS Lambda functions for serverless computing |
create_lambda_function | write | Deploy serverless Lambda functions for event-driven computing. Run code without servers, process events. |
create_node | write | Create nodes in Neo4j graph with labels and properties. Add entities, create graph elements. |
create_page | write | Create new pages in Notion workspaces |
create_payment | write | Process credit card payments and charges from customers. Charge customer for order, process payment from customer. |
create_pull_request | write | Create pull requests for code review and collaboration |
create_rds_database | write | Create managed RDS database instances with configuration. Set up MySQL, PostgreSQL databases in cloud. |
create_relationship | write | Create relationships between nodes in Neo4j graph. Connect entities, define associations, build graph structure. |
create_repository | write | Create a new GitHub repository with configuration options. Set up new project, initialize repository. |
create_subscription | write | Create recurring subscription billing for customers |
create_table | write | Create new tables in PostgreSQL database with schema definition |
cron | write | Daemon to execute scheduled commands |
crontab | read | Maintain crontab files |
csvkit | read | Suite of utilities for working with CSV |
curl | write | Transfer data with URLs |
cut | read | Cut/trim video segment |
data-analyzer | read | Analyze data patterns and generate insights |
data-pipeline | read | Fetch, transform, and store data every hour |
date | write | Print or set system date and time |
delete | destructive | Delete scheduled job. |
delete_file | destructive | Delete files or directories from the file system |
df | read | Report file system disk space usage |
diff | read | Compare files line by line |
dirname | read | Strip last component from file name |
docker | read | Container management including Docker operations, image building, and deployment |
doctor | write | Run diagnostics on NCP system health and MCP configurations. Read-only - reports issues without making changes. Matches CLI: ncp doctor |
dropbox | read | Dropbox cloud storage for file synchronization, sharing, and backup operations |
du | read | Estimate file space usage |
echo | read | Echo back the input |
egrep | read | Extended grep with regex support |
empty-desc | read | |
env | write | Run a program in a modified environment |
execute | write | Execute shell command |
execute_command | write | Execute shell commands and system operations. Run scripts, manage processes, perform system tasks. |
execute_cypher | write | Execute Cypher queries on Neo4j graph database. Query relationships, find patterns, analyze connections. |
execute_in_container | write | Execute commands inside running Docker containers. Debug containers, run maintenance tasks. |
executions | read | View execution history. |
export | read | Export current NCP configuration. Use clipboard for security (no chat history), response for transparency. |
extract_audio | read | Extract audio track from video |
extract_frames | read | Extract frames/images from video |
extract_text | read | Extract text content from web page elements |
failing-tool | read | Will fail |
fd | read | Fast alternative to find |
ffmpeg | read | Complete solution to record, convert and stream audio and video |
file-manager | read | Manage files and directories on the system |
filesystem | read | Local file system operations including reading, writing, directory management, and permissions |
fill_form | read | Fill out web forms with specified data |
fill_form_field | read | Fill form inputs and text fields on web pages. Enter text, complete forms, input data. |
find | read | Search and discover installed Anthropic Agent Skills with progressive detail levels. Use depth parameter for progressive disclosure: 1=metadata only, 2=+SKILL.md content (AI learns skill), 3=+file listings. |
find_path | read | Find paths between nodes in Neo4j graph database. Discover connections, analyze relationships, trace routes. |
firecrawl | read | Extract and convert web content for LLM consumption with smart crawling |
fzf | read | Fuzzy finder |
gcloud | read | Google Cloud SDK |
gcp | read | Google Cloud Platform services for compute, storage, BigQuery, and machine learning |
gem | read | RubyGems package manager |
get | read | Get job details. |
get-run | write | Get details of a specific code execution run including full JSONL log |
get_channel_history | read | Retrieve message history from Slack channels |
get_file | read | Retrieve file contents from GitHub repositories |
get_file_contents | read | Read file contents from GitHub repositories. Access source code, read configuration files. |
get_file_info | read | Get detailed information about files and directories. Check file size, modification time, permissions. |
get_info | read | Get video/audio file information |
gh | read | GitHub CLI tool |
gifsicle | write | Create, edit, and optimize GIF images |
git | read | Git version control operations including commits, branches, merges, and repository management |
git-commit | write | Create Git commits to save changes to version history. git commit for saving progress, commit code changes, record modifications. |
github | read | GitHub API integration for repository management, file operations, issues, and pull requests |
go | read | Go programming language compiler |
google-drive | read | Google Drive integration for file access, search, sharing, and cloud storage management |
gpg | read | GNU Privacy Guard |
grep | read | Search text using patterns |
gzip | read | GNU zip compression |
head | read | Output the first part of files |
hg | read | Mercurial version control |
htop | read | Interactive process viewer |
httpie | read | User-friendly HTTP client |
ifconfig | read | Configure network interface |
image_search | read | Search for images with filtering options. Find pictures, locate visual content, discover graphics. |
imagemagick | write | Create, edit, compose, or convert digital images |
impact | read | Potential impact description |
insert | write | Insert new records into PostgreSQL database tables. Store customer data, add new information, create records. |
ip | read | Show/manipulate routing, devices, policy routing |
ipconfig | read | Display network configuration |
jq | read | Command-line JSON processor |
kill | destructive | Send signals to processes |
killall | destructive | Kill processes by name |
kubectl | read | Kubernetes command-line tool |
langfuse | read | LLM prompt management, evaluation, and observability for AI applications |
list | read | List all configured skill marketplaces |
list-runs | write | List recent code execution runs for potential save-as-photon conversion |
list_containers | read | List Docker containers with filtering and status information. View running containers, check container status. |
list_directory | read | List contents of a directory |
list_payments | read | List payment transactions with filtering and pagination |
list_repos | read | List repositories |
list_resources | read | List AWS resources across different services |
ln | read | Make links between files |
ls | read | List directory contents |
make | read | Build automation tool |
manage_container | write | Manage Docker container lifecycle including start, stop, restart operations. Control running containers. |
manage_environment | write | Manage environment variables and system configuration. Set variables, configure system settings. |
manage_process | write | Manage system processes including start, stop, and monitoring. Control services, manage applications. |
manage_schema | read | Manage Neo4j database schema including indexes and constraints. Optimize queries, ensure data integrity. |
matched_pattern | read | The modifier pattern that matched |
math | read | Perform mathematical calculations and computations |
mcp_name | write | Name of the MCP server to add |
merge | write | Concatenate/merge multiple videos |
merge_branch | write | Merge Git branches to combine changes from different development lines. Integrate features, combine work. |
mkdir | read | Make directories |
mongosh | read | MongoDB shell |
monitor | read | Monitor system performance and resource usage |
multi-operation-tool | destructive | Create, read, update and delete multiple files in directory while executing commands and validating operations |
multi-step-etl | read | Extract, Transform, Load with error handling |
mv | write | Move or rename files |
mysql | read | MySQL client |
navigate | read | Navigate browser to specified URL for web automation |
navigate_to_page | read | Navigate to web pages and URLs for automation tasks. Open websites, load web applications. |
neo4j | write | Neo4j graph database server with schema management and read/write cypher operations |
netcat | write | Read and write data across networks |
netsh | read | Network Shell utility |
netstat | read | Print network connections, routing tables |
news_search | read | Search for news articles with current events and breaking news. Get latest news, find articles, track stories. |
nmap | read | Network exploration and security scanner |
node | read | Node.js JavaScript runtime |
notion | read | Notion workspace management for documents, databases, and collaborative content |
npm | read | Node.js package manager |
oauth | read | OAuth authentication flows and token management for secure API access |
only_tool | read | New tool |
openssl | read | SSL/TLS toolkit |
operation | read | Description of the operation |
optimize_client | read | Back up a supported MCP client configuration and replace its MCP server list with NCP. Requires explicit user confirmation. |
original-tool | read | Original |
overview | read | Visual analytics dashboard with ASCII charts showing usage stats, token savings, performance metrics, and trends. Returns formatted in markdown code blocks for rendering. |
pandoc | read | Universal document converter |
parameters | read | JSON string of parameters being passed |
patch | write | Apply a diff file to an original |
pause | read | Pause job (stops future executions). |
payment-file-web | read | Process payment files on web server database |
Trust audit
BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (16 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (11 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
const parsed = yaml.load(frontmatter) as Partial<SkillMetadata>;
exec(`${start} "${url}"`, (error) => {{ pattern: /eval\s*\(/g, name: 'eval() call' },description: 'Direct eval() call - arbitrary code execution',
dangerousConstructs.push('eval()');dangerousConstructs.push('new Function()');logger.debug(`Exchanging code for token at ${this.config.tokenUrl}`);logger.debug(`Token stored for ${mcpName}, expires at ${new Date(expiresAt).toISOString()}`);logger.debug(`Token for ${mcpName} expired or expiring soon`);logger.debug(`No token found for ${mcpName}`);logger.error(`Failed to read token for ${mcpName}:`, error);exfiltration: {description: 'Potential data exfiltration - reading sensitive data and sending externally',
const exfil = MALICIOUS_INTENT_PATTERNS.exfiltration;
const hasReadSensitive = exfil.readPatterns.some(
const hasSendExternal = exfil.sendPatterns.some(
[NotificationType.MCP_DISCONNECTED]: '⛓️💥',
confirm_remove_mcp, delete, delete_file, kill, killall, multi-operation-tool, remove, rm, taskkill, tr
.dxtignore
.gitkeep-md
.mcpbignore
.release-it.json
.nojekyll
return crypto.createHash('md5').update(description).digest('hex');return crypto.createHash('md5').update(combined).digest('hex');Gates applied: no_behavioural_pass.
d471a4f48d87full audit observations/trust-audit/mcp-server/portel-dev__ncp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d471a4f48d87 | BLOCK | F | 42 | first audit |
Questions
What is the NCP MCP server?
Natural Context Provider (NCP). Your MCPs, supercharged. Find any tool instantly, load on demand, run on schedule, ready for any client. Smart loading saves tokens and energy.
What tools does NCP expose?
200 in total: 239 read-only, 86 that write, and 10 that can delete or overwrite (confirm_remove_mcp, delete, delete_file, kill, killall). Every one is listed on this page with its risk.
Is NCP safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (42/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does NCP need?
It reads ANTHROPIC_API_KEY, GITHUB_TOKEN, NCP_CREDENTIAL_KEY, PORTEL_ADMIN_KEY and SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does NCP run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-smithery-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (d471a4f48d87), read on 2026-10-07. The repository is watched and re-audited when it changes.