Atlas / MCP servers / shadowcz007 / Executable

ExecutableBLOCK

mcp/shadowcz007/executable

小智 & Cursor 的 MCP 启动器 - MCP For Cursor&xiaozhi。打包成可执行文件。Turn MCP server into an executable file

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
11 10r · 1w · 0d
Transport
sse · stdio
License
MIT
Stars
166
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

小智 & Cursor 的 MCP 启动器 - MCP For Cursor&xiaozhi

MCP Server.exe 是一个强大的可执行服务器,它不仅能够运行标准的 MCP (Model Context Protocol) 服务,更提供了丰富的高级功能:

  • 工具链式调用:支持将多个工具按序组合,实现复杂的自动化流程
  • 多 MCP 服务组合:可同时运行和管理多个 MCP 服务,支持 SSE 和 stdio 双模式
  • 插件化工具系统:支持自定义工具的动态加载和配置
  • 灵活的部署选项:从单机运行到分布式部署,满足各类集成场景
  • 自动重载:监听 --mcp-config 与 --mcp-js 变更,自动重启生效

MCP Server.exe is a powerful executable server that not only runs standard MCP (Model Context Protocol) services, but also provides rich advanced features:

  • Tool Chain Execution: Support sequential combination of multiple tools for complex automation
  • Multiple MCP Services: Can run and manage multiple MCP services simultaneously, supporting both SSE and stdio modes
  • Pluggable Tool System: Support dynamic loading and configuration of custom tools
  • Flexible Deployment: From standalone operation to distributed deployment, meeting various integration scenarios
  • Auto reload for config changes

Usage

# 推荐:通过 CLI 运行(无需本地构建)
npx mcp_exe --mcp-config ./examples/mcp.json

# 或运行打包后的可执行文件(Windows/macOS)
./executables/mcp_server-win-x64.exe --mcp-config ./examples/mcp.json

🎯 主要使用场景 | Main Usage Scenarios

1. WebSocket 连接模式 | WebSocket Connection Mode

支持通过 WebSocket 连接到其他 MCP 服务,特别适合连接到 xiaozhi.me 等的接入。通过配置文件,可以轻松地将多个 MCP 服务接入到 xiaozhi.me。

Support connecting to other MCP services via WebSocket, especially suitable for connecting to WebSocket-enabled MCP services like xiaozhi.me. Through configuration files, you can easily integrate multiple MCP services with xiaozhi.me.

# 使用配置文件连接到 xiaozhi.me / Start in WebSocket mode
npx mcp_exe --ws wss://api.xiaozhi.me/mcp/?token=...xxx --mcp-config ./examples/mcp-sse.json

配置示例 | Configuration Example (mcp-sse.json):

{
"mcpServers": {
"Model Server sse": {
"url": "http://127.0.0.1:3000"
}
},
"serverInfo": {
"serverName": "ws-client-mcp-s
Read from source at commit 0f7cd6fcc99aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp_exe -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp_exe": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (11)

10 read · 1 write · 0 destructive.

ToolRiskDescription
custom-toolread
echoread
exampleToolread示例工具
get-current-timereadGet the current date and time
get_product_hunt_urlreadget product hunt url
greetread问候工具
integration-testread集成测试工具
load_product_hunt_js_codereadload product hunt js code
math-addwriteAdd two numbers together
test-echoreadEcho back the input message
userreadstore user
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/utils/cursorLink.ts:22
exec(command, (error) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
executables/notifier/InfoPlist.strings
InfoPlist.strings
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
executables/notifier/MainMenu.nib
MainMenu.nib
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
executables/notifier/Terminal.icns
Terminal.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
executables/notifier/notifu.exe
notifu.exe
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
executables/notifier/notifu64.exe
notifu64.exe
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cronjob/config/index.ts:2
import { formatLog, LogLevel } from '../../utils/console'
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:51
"url": "http://127.0.0.1:3000"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:104
"Model Server sse": { "url": "http://127.0.0.1:9090" },
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/library-usage.js:32
url: "http://127.0.0.1:3000/mcp"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/cors, @types/uuid, @types/ws, cors, dotenv, express, node-cron
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
executables/mcp_server-macos-x64
executables/mcp_server-macos-x64
Why it matters. 67200848 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
executables/mcp_server-win-x64.exe
executables/mcp_server-win-x64.exe
Why it matters. 53104893 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
executables/notifier/snoretoast-x64.exe
executables/notifier/snoretoast-x64.exe
Why it matters. 2519032 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
executables/notifier/snoretoast-x86.exe
executables/notifier/snoretoast-x86.exe
Why it matters. 2065912 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0f7cd6fcc99afull audit observations/trust-audit/mcp-server/shadowcz007__executable.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070f7cd6fcc99aBLOCKD69first audit
06

Questions

What is the Executable MCP server?

小智 & Cursor 的 MCP 启动器 - MCP For Cursor&xiaozhi。打包成可执行文件。Turn MCP server into an executable file

What tools does Executable expose?

11 in total: 10 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Executable safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Executable need?

No credential environment variables were found in its source, so it appears to need none.

How does Executable run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as mcp_exe at 0.12.0.

How current is this page?

The grade is for one exact copy of the source (0f7cd6fcc99a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement