ToolbaseBLOCK
A desktop application that adds powerful tools to Claude and AI platforms
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
⚠️ We’re currently in the process of updating the open-source Toolbase repository to reflect our latest changes after testing with alpha testers.
Toolbase is a desktop application that makes it easy to add tools and plugins to Claude and AI Platforms. It provides a simple interface for discovering, installing, and managing tools without requiring technical expertise.
Learn more at https://gettoolbase.ai
Powered by the Model Context Protocol (MCP)
⚠️ Developer Preview: This project is currently in active development. APIs and features may change without notice.
Features
- 🔍 Visual tool browser
- 🚀 One-click tool installation
- 🔧 Simple configuration management
- 🔌 Seamless Claude Desktop integration
Getting Started
Prerequisites
- Claude Desktop installed
Download and Run Toolbase
Toolbase currently only supports macOS. Support for Windows and Linux in active development.
- Download the latest version of Toolbase from https://gettoolbase.ai
- Open the application and start using tools and plugins with Claude Desktop
Project Structure
toolbase/ ├── packages/ ├── app/ # Desktop application for tool management └── runner/ # Secure local runner for MCP servers
This monorepo contains two main packages:
packages/app- Desktop application for tool management and configuration, built with Electronpackages/runner- Local runner for executing MCP servers and tools, built with Deno
See individual package READMEs for detailed documentation:
- Desktop App Documentation
- Runner Documentation
Development Setup
Although setup as a monorepo, each package are managed independently.
Clone the repository:
da8a81cc17abOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add toolbase -- npx -y [email protected]
{
"mcpServers": {
"toolbase": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (9)
8 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Curl | read | Make HTTP requests to any website or API |
Everything | read | Try out different features and capabilities of Claude MCP Plugins |
Filesystem | read | Access and read files from your computer |
GitHub | read | Access and manage GitHub repositories and issues |
GitLab | read | Access and manage GitLab repositories and issues |
Mongo | read | Connect to and query MongoDB databases |
PostgreSQL | read | Connect to and query PostgreSQL databases |
Search1API | read | Search the web using Search1API |
Slack | write | Send and receive messages in Slack channels and DMs |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
exec(command, (error, stdout, stderr) => {icon.icns
.prettierignore
import { getEsmUrl } from '../../shared/utils';import { packages } from '../../shared/packages';import type { MCPServersRecord } from '../../shared/types/mcp';} from '../../shared/types/servers';
import { type MCPPackage } from '../../shared/types/types';@mantine/core, @mantine/form, @mantine/hooks, @tabler/icons-react, @tanstack/react-query, conf, electron-squirrel-startup, electron-store
Gates applied: no_behavioural_pass.
da8a81cc17abfull audit observations/trust-audit/mcp-server/toolbase-ai__toolbase.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | da8a81cc17ab | BLOCK | D | 69 | first audit |
Questions
What is the Toolbase MCP server?
A desktop application that adds powerful tools to Claude and AI platforms
What tools does Toolbase expose?
9 in total: 8 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Toolbase safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Toolbase need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (da8a81cc17ab), read on 2026-10-06. The repository is watched and re-audited when it changes.