Atlas / MCP servers / toolbase-ai / Toolbase

ToolbaseBLOCK

mcp/toolbase-ai/toolbase

A desktop application that adds powerful tools to Claude and AI platforms

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
9 8r · 1w · 0d
Transport
—
License
Apache-2.0
Stars
165
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚠️ We’re currently in the process of updating the open-source Toolbase repository to reflect our latest changes after testing with alpha testers.

Toolbase is a desktop application that makes it easy to add tools and plugins to Claude and AI Platforms. It provides a simple interface for discovering, installing, and managing tools without requiring technical expertise.

Learn more at https://gettoolbase.ai

Powered by the Model Context Protocol (MCP)

⚠️ Developer Preview: This project is currently in active development. APIs and features may change without notice.

Features

  • 🔍 Visual tool browser
  • 🚀 One-click tool installation
  • 🔧 Simple configuration management
  • 🔌 Seamless Claude Desktop integration

Getting Started

Prerequisites

Download and Run Toolbase

Toolbase currently only supports macOS. Support for Windows and Linux in active development.
  1. Download the latest version of Toolbase from https://gettoolbase.ai
  2. Open the application and start using tools and plugins with Claude Desktop

Project Structure

toolbase/
├── packages/
├── app/      # Desktop application for tool management
└── runner/   # Secure local runner for MCP servers

This monorepo contains two main packages:

  • packages/app - Desktop application for tool management and configuration, built with Electron
  • packages/runner - Local runner for executing MCP servers and tools, built with Deno

See individual package READMEs for detailed documentation:

  • Desktop App Documentation
  • Runner Documentation

Development Setup

Although setup as a monorepo, each package are managed independently.

Clone the repository:

Read from source at commit da8a81cc17abOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add toolbase -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "toolbase": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (9)

8 read · 1 write · 0 destructive.

ToolRiskDescription
CurlreadMake HTTP requests to any website or API
EverythingreadTry out different features and capabilities of Claude MCP Plugins
FilesystemreadAccess and read files from your computer
GitHubreadAccess and manage GitHub repositories and issues
GitLabreadAccess and manage GitLab repositories and issues
MongoreadConnect to and query MongoDB databases
PostgreSQLreadConnect to and query PostgreSQL databases
Search1APIreadSearch the web using Search1API
SlackwriteSend and receive messages in Slack channels and DMs
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (1 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/app/src/main/ipc-listeners.ts:20
exec(command, (error, stdout, stderr) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/app/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/app/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/app/src/renderer/components/ServerInfoModal.tsx:17
import { getEsmUrl } from '../../shared/utils';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/app/src/renderer/components/ServersGrid.tsx:3
import { packages } from '../../shared/packages';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/app/src/renderer/providers/MCPServersProvider.tsx:2
import type { MCPServersRecord } from '../../shared/types/mcp';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/app/src/renderer/providers/ServerConfigsProvider.tsx:5
} from '../../shared/types/servers';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/app/src/renderer/types/types.ts:1
import { type MCPPackage } from '../../shared/types/types';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/app/package.json
@mantine/core, @mantine/form, @mantine/hooks, @tabler/icons-react, @tanstack/react-query, conf, electron-squirrel-startup, electron-store
Why it matters. 44 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha da8a81cc17abfull audit observations/trust-audit/mcp-server/toolbase-ai__toolbase.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06da8a81cc17abBLOCKD69first audit
06

Questions

What is the Toolbase MCP server?

A desktop application that adds powerful tools to Claude and AI platforms

What tools does Toolbase expose?

9 in total: 8 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Toolbase safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Toolbase need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (da8a81cc17ab), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement