Atlas / MCP servers / portel-dev / NCP

NCPBLOCK

mcp/portel-dev/ncp

Natural Context Provider (NCP). Your MCPs, supercharged. Find any tool instantly, load on demand, run on schedule, ready for any client. Smart loading saves tokens and energy.

Verdict
BLOCK
Grade
F
Trust score
42 /100
Exposed tools
200 239r · 86w · 10d
Transport
sse · stdio · streamable-http
License
NOASSERTION
Stars
100
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@portel/ncp) [](https://www.npmjs.com/package/@portel/ncp) [](https://github.com/portel-dev/ncp/releases) [](https://github.com/portel-dev/ncp/releases/latest) [](https://www.elastic.co/licensing/elastic-license) [](https://modelcontextprotocol.io/)

1 MCP to rule them all

Your MCPs, supercharged. Find any tool instantly, execute with code mode, run on schedule, discover skills, load Photons, ready for any client. Smart loading saves tokens and energy.

Related Portel project: Photon turns TypeScript methods into reliable agent-facing capabilities: MCP tools, embedded app UIs, CLI commands, web routes, schedules, webhooks, retries, and Beam interfaces. NCP helps agents discover and operate tools; Photon helps developers build the tools and apps agents can trust.

💍 What is NCP?

Instead of your AI juggling 50+ tools scattered across different MCPs, NCP gives it a single, unified interface with code mode execution, scheduling, skills discovery, and custom Photons.

Your AI sees just 2-3 simple tools:

  • `find` - Search for any tool, skill, or Photon: "I need to read a file" → finds the right tool automatically
  • `code` - Execute TypeScript directly: `await github.create
Read from source at commit d471a4f48d87OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add ncp -- npx -y @portel/[email protected]
03

Exposed tools (200)

239 read · 86 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
7zread7-Zip file archiver
addwriteAdd MCP server(s) to NCP with smart auto-detection of input type. Supports multiple modes: (1) SINGLE: Add one MCP from registry or manual config (e.g.,
add_audiowriteAdd audio track to video
add_subtitleswriteAdd subtitles to video
adjust_volumereadAdjust audio volume level
advanced-operationswriteCreate multiple files, read directory contents, update existing resources, and delete old data
agreadThe Silver Searcher
allreadUniversal profile with all configured MCP servers
alpacareadStock and options trading with real-time market data and portfolio management
another-toolreadAnother
ansiblereadIT automation tool
approve_dangerous_operationreadRequest approval for potentially dangerous operations
aptreadAdvanced Package Tool
atomic-toolreadTest
auth0readIdentity and access management with authentication, authorization, and user management
awkreadPattern scanning and processing language
awsreadAmazon Web Services integration for EC2, S3, Lambda, and cloud resource management
azreadAzure command-line interface
azurereadMicrosoft Azure services including storage, compute, databases, and AI services
basenamereadStrip directory and suffix from filenames
brave-searchreadWeb search capabilities with privacy-focused results and real-time information
brewreadHomebrew package manager
bright-datareadDiscover, extract, and interact with web data through advanced scraping infrastructure
browserbasereadAutomate browser interactions in the cloud for web scraping and testing
build_imagewriteBuild Docker images from Dockerfile with build context. Create custom images, package applications.
calreadDisplay a calendar
calendarreadCalendar scheduling and booking management across platforms
camelCaseToolName_with-hyphensreadTool with complex naming patterns
cargoreadRust package manager
change_codecreadChange video/audio codec
check_system_inforeadGet system information including resources, processes, and status. Monitor system health, check resources.
chmodreadChange file mode bits
chocoreadChocolatey package manager
chownreadChange file owner and group
circlecireadCircleCI integration to monitor builds, fix failures, and manage CI/CD pipelines
click_elementreadClick on web page elements using selectors. Click buttons, links, form elements.
clickhousereadClickHouse analytics database for real-time data processing and OLAP queries
cloudflarewriteDeploy, configure and manage Cloudflare CDN, security, and edge computing services
cmdreadWindows Command Prompt
codewriteExecute TypeScript code with automatic tool discovery and parameter mapping. **PRIMARY METHOD - ncp.do(intent, params):** Single-call execution with embedding-based param matching. No need to know exact tool names or param schemas! ncp.do(
commandwriteCommand to execute
commitwriteCommit changes to git repository with message
commit_changeswriteCreate Git commits to save changes to version history. Save progress, commit code changes, record modifications.
compressreadCompress/reduce video file size
conditional-workflowreadSmart workflow that adapts based on conditions
confidencereadMatch confidence (0.0-1.0)
config_typereadType of configuration needed
configure_mcpreadRequest user input for MCP configuration (env vars, args)
confirm_add_mcpwriteRequest user confirmation before adding a new MCP server
confirm_operationreadRequest user confirmation before executing modifier operations
confirm_remove_mcpdestructiveRequest user confirmation before removing an MCP server
convertreadConvert video/audio to different format
copyreadCopy files between different locations
copy_filereadCopy files to different locations for backup or organization
cpreadCopy files and directories
createwriteCreate scheduled job with cron/natural language timing.
create_branchwriteCreate new Git branches for feature development and parallel work. Start new features, create development branches.
create_channelwriteCreate new Slack channels for team communication
create_databasewriteCreate structured Notion databases with properties and schema. Set up project tracking, create data tables.
create_directorywriteCreate new directories and folder structures. Organize files, set up project structure, create folder hierarchies.
create_ec2_instancewriteLaunch new EC2 virtual machine instances with configuration. Create servers, deploy applications to cloud.
create_gifwriteConvert video to animated GIF
create_issuewriteCreate GitHub issues for bug reports and feature requests. Report bugs, request features, track tasks.
create_lambdawriteCreate AWS Lambda functions for serverless computing
create_lambda_functionwriteDeploy serverless Lambda functions for event-driven computing. Run code without servers, process events.
create_nodewriteCreate nodes in Neo4j graph with labels and properties. Add entities, create graph elements.
create_pagewriteCreate new pages in Notion workspaces
create_paymentwriteProcess credit card payments and charges from customers. Charge customer for order, process payment from customer.
create_pull_requestwriteCreate pull requests for code review and collaboration
create_rds_databasewriteCreate managed RDS database instances with configuration. Set up MySQL, PostgreSQL databases in cloud.
create_relationshipwriteCreate relationships between nodes in Neo4j graph. Connect entities, define associations, build graph structure.
create_repositorywriteCreate a new GitHub repository with configuration options. Set up new project, initialize repository.
create_subscriptionwriteCreate recurring subscription billing for customers
create_tablewriteCreate new tables in PostgreSQL database with schema definition
cronwriteDaemon to execute scheduled commands
crontabreadMaintain crontab files
csvkitreadSuite of utilities for working with CSV
curlwriteTransfer data with URLs
cutreadCut/trim video segment
data-analyzerreadAnalyze data patterns and generate insights
data-pipelinereadFetch, transform, and store data every hour
datewritePrint or set system date and time
deletedestructiveDelete scheduled job.
delete_filedestructiveDelete files or directories from the file system
dfreadReport file system disk space usage
diffreadCompare files line by line
dirnamereadStrip last component from file name
dockerreadContainer management including Docker operations, image building, and deployment
doctorwriteRun diagnostics on NCP system health and MCP configurations. Read-only - reports issues without making changes. Matches CLI: ncp doctor
dropboxreadDropbox cloud storage for file synchronization, sharing, and backup operations
dureadEstimate file space usage
echoreadEcho back the input
egrepreadExtended grep with regex support
empty-descread
envwriteRun a program in a modified environment
executewriteExecute shell command
execute_commandwriteExecute shell commands and system operations. Run scripts, manage processes, perform system tasks.
execute_cypherwriteExecute Cypher queries on Neo4j graph database. Query relationships, find patterns, analyze connections.
execute_in_containerwriteExecute commands inside running Docker containers. Debug containers, run maintenance tasks.
executionsreadView execution history.
exportreadExport current NCP configuration. Use clipboard for security (no chat history), response for transparency.
extract_audioreadExtract audio track from video
extract_framesreadExtract frames/images from video
extract_textreadExtract text content from web page elements
failing-toolreadWill fail
fdreadFast alternative to find
ffmpegreadComplete solution to record, convert and stream audio and video
file-managerreadManage files and directories on the system
filesystemreadLocal file system operations including reading, writing, directory management, and permissions
fill_formreadFill out web forms with specified data
fill_form_fieldreadFill form inputs and text fields on web pages. Enter text, complete forms, input data.
findreadSearch and discover installed Anthropic Agent Skills with progressive detail levels. Use depth parameter for progressive disclosure: 1=metadata only, 2=+SKILL.md content (AI learns skill), 3=+file listings.
find_pathreadFind paths between nodes in Neo4j graph database. Discover connections, analyze relationships, trace routes.
firecrawlreadExtract and convert web content for LLM consumption with smart crawling
fzfreadFuzzy finder
gcloudreadGoogle Cloud SDK
gcpreadGoogle Cloud Platform services for compute, storage, BigQuery, and machine learning
gemreadRubyGems package manager
getreadGet job details.
get-runwriteGet details of a specific code execution run including full JSONL log
get_channel_historyreadRetrieve message history from Slack channels
get_filereadRetrieve file contents from GitHub repositories
get_file_contentsreadRead file contents from GitHub repositories. Access source code, read configuration files.
get_file_inforeadGet detailed information about files and directories. Check file size, modification time, permissions.
get_inforeadGet video/audio file information
ghreadGitHub CLI tool
gifsiclewriteCreate, edit, and optimize GIF images
gitreadGit version control operations including commits, branches, merges, and repository management
git-commitwriteCreate Git commits to save changes to version history. git commit for saving progress, commit code changes, record modifications.
githubreadGitHub API integration for repository management, file operations, issues, and pull requests
goreadGo programming language compiler
google-drivereadGoogle Drive integration for file access, search, sharing, and cloud storage management
gpgreadGNU Privacy Guard
grepreadSearch text using patterns
gzipreadGNU zip compression
headreadOutput the first part of files
hgreadMercurial version control
htopreadInteractive process viewer
httpiereadUser-friendly HTTP client
ifconfigreadConfigure network interface
image_searchreadSearch for images with filtering options. Find pictures, locate visual content, discover graphics.
imagemagickwriteCreate, edit, compose, or convert digital images
impactreadPotential impact description
insertwriteInsert new records into PostgreSQL database tables. Store customer data, add new information, create records.
ipreadShow/manipulate routing, devices, policy routing
ipconfigreadDisplay network configuration
jqreadCommand-line JSON processor
killdestructiveSend signals to processes
killalldestructiveKill processes by name
kubectlreadKubernetes command-line tool
langfusereadLLM prompt management, evaluation, and observability for AI applications
listreadList all configured skill marketplaces
list-runswriteList recent code execution runs for potential save-as-photon conversion
list_containersreadList Docker containers with filtering and status information. View running containers, check container status.
list_directoryreadList contents of a directory
list_paymentsreadList payment transactions with filtering and pagination
list_reposreadList repositories
list_resourcesreadList AWS resources across different services
lnreadMake links between files
lsreadList directory contents
makereadBuild automation tool
manage_containerwriteManage Docker container lifecycle including start, stop, restart operations. Control running containers.
manage_environmentwriteManage environment variables and system configuration. Set variables, configure system settings.
manage_processwriteManage system processes including start, stop, and monitoring. Control services, manage applications.
manage_schemareadManage Neo4j database schema including indexes and constraints. Optimize queries, ensure data integrity.
matched_patternreadThe modifier pattern that matched
mathreadPerform mathematical calculations and computations
mcp_namewriteName of the MCP server to add
mergewriteConcatenate/merge multiple videos
merge_branchwriteMerge Git branches to combine changes from different development lines. Integrate features, combine work.
mkdirreadMake directories
mongoshreadMongoDB shell
monitorreadMonitor system performance and resource usage
multi-operation-tooldestructiveCreate, read, update and delete multiple files in directory while executing commands and validating operations
multi-step-etlreadExtract, Transform, Load with error handling
mvwriteMove or rename files
mysqlreadMySQL client
navigatereadNavigate browser to specified URL for web automation
navigate_to_pagereadNavigate to web pages and URLs for automation tasks. Open websites, load web applications.
neo4jwriteNeo4j graph database server with schema management and read/write cypher operations
netcatwriteRead and write data across networks
netshreadNetwork Shell utility
netstatreadPrint network connections, routing tables
news_searchreadSearch for news articles with current events and breaking news. Get latest news, find articles, track stories.
nmapreadNetwork exploration and security scanner
nodereadNode.js JavaScript runtime
notionreadNotion workspace management for documents, databases, and collaborative content
npmreadNode.js package manager
oauthreadOAuth authentication flows and token management for secure API access
only_toolreadNew tool
opensslreadSSL/TLS toolkit
operationreadDescription of the operation
optimize_clientreadBack up a supported MCP client configuration and replace its MCP server list with NCP. Requires explicit user confirmation.
original-toolreadOriginal
overviewreadVisual analytics dashboard with ASCII charts showing usage stats, token savings, performance metrics, and trends. Returns formatted in markdown code blocks for rendering.
pandocreadUniversal document converter
parametersreadJSON string of parameters being passed
patchwriteApply a diff file to an original
pausereadPause job (stops future executions).
payment-file-webreadProcess payment files on web server database
04

Trust audit

BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (16 observation(s))
Network
declared (11 observation(s))
Shell
declared (11 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/services/skills-manager.ts:157
const parsed = yaml.load(frontmatter) as Partial<SkillMetadata>;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/auth/oauth-auth-code-flow.ts:185
exec(`${start} "${url}"`, (error) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/code-mode/code-worker.ts:218
{ pattern: /eval\s*\(/g, name: 'eval() call' },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/code-mode/validation/code-analyzer.ts:465
description: 'Direct eval() call - arbitrary code execution',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/code-mode/validation/code-analyzer.ts:467
dangerousConstructs.push('eval()');
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/code-mode/validation/code-analyzer.ts:493
dangerousConstructs.push('new Function()');
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/oauth-auth-code-flow.ts:333
logger.debug(`Exchanging code for token at ${this.config.tokenUrl}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/token-store.ts:57
logger.debug(`Token stored for ${mcpName}, expires at ${new Date(expiresAt).toISOString()}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/token-store.ts:75
logger.debug(`Token for ${mcpName} expired or expiring soon`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/token-store.ts:82
logger.debug(`No token found for ${mcpName}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/token-store.ts:84
logger.error(`Failed to read token for ${mcpName}:`, error);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/code-mode/validation/semantic-validator.ts:172
exfiltration: {
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/code-mode/validation/semantic-validator.ts:175
description: 'Potential data exfiltration - reading sensitive data and sending externally',
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/code-mode/validation/semantic-validator.ts:675
const exfil = MALICIOUS_INTENT_PATTERNS.exfiltration;
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/code-mode/validation/semantic-validator.ts:676
const hasReadSensitive = exfil.readPatterns.some(
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/code-mode/validation/semantic-validator.ts:679
const hasSendExternal = exfil.sendPatterns.some(
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/services/NotificationQueue.ts:282
[NotificationType.MCP_DISCONNECTED]: '⛓️💥',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
confirm_remove_mcp, delete, delete_file, kill, killall, multi-operation-tool, remove, rm, taskkill, tr
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.dxtignore
.dxtignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitkeep-md
.gitkeep-md
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-it.json
.release-it.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs-site/public/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/discovery/rag-engine.ts:1099
return crypto.createHash('md5').update(description).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/discovery/rag-engine.ts:1111
return crypto.createHash('md5').update(combined).digest('hex');

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d471a4f48d87full audit observations/trust-audit/mcp-server/portel-dev__ncp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d471a4f48d87BLOCKF42first audit
06

Questions

What is the NCP MCP server?

Natural Context Provider (NCP). Your MCPs, supercharged. Find any tool instantly, load on demand, run on schedule, ready for any client. Smart loading saves tokens and energy.

What tools does NCP expose?

200 in total: 239 read-only, 86 that write, and 10 that can delete or overwrite (confirm_remove_mcp, delete, delete_file, kill, killall). Every one is listed on this page with its risk.

Is NCP safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (42/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does NCP need?

It reads ANTHROPIC_API_KEY, GITHUB_TOKEN, NCP_CREDENTIAL_KEY, PORTEL_ADMIN_KEY and SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does NCP run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-smithery-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (d471a4f48d87), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement