HypertoolBLOCK
Dynamically expose tools from proxied servers based on an Agent Persona
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Give your AI the best tools from all your MCPs 🎯
[](https://npmjs.com/package/@toolprint/hypertool-mcp) [](https://npmjs.com/package/@toolprint/hypertool-mcp) [](https://discord.gg/MbvndnJ45W) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io) [](LICENSE)
⚡ Features
🔓 Break Free from Tool Limits
Connect unlimited MCP servers. Use 10, 50, or 500+ tools total - your AI only sees what it needs.
🎯 Task-Specific Toolsets
Build "git-essentials" with 5 tools instead of drowning in 47 Git commands. Switch contexts instantly.
🧠 Smart Tool Descriptions
Enhance tools with examples and context. Watch your AI pick the right tool 89% more often.
🚀 Quick Start
Step 1: Copy Your Existing Config
# In your project directory cp .mcp.json .mcp.hypertool.json
Step 2: Point Your AI to HyperTool
Replace your .mcp.json with:
{
"mcpServers": {
"hypertool": {
"command": "npx",
"args": ["-y", "@toolprint/hypertool-mcp", "mcp", "run", "--mcp-config", ".mcp.hypertool.json"]
a5df37f12690OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add hypertool-mcp -- npx -y @toolprint/[email protected]
{
"mcpServers": {
"hypertool-mcp": {
"command": "npx",
"args": [
"-y",
"@toolprint/[email protected]"
]
}
}
}Exposed tools (80)
60 read · 19 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
DevTools | read | Development tools |
add-tool-annotation | write | Add contextual annotations to a tool in the current toolset to guide LLM usage. Annotations provide user-specific guidance, best practices, and usage notes that will be displayed with the tool |
build-toolset | read | Build a toolset |
cached_tool | read | A cached tool |
commit | write | Git commit tool |
complete-persona | read | A complete persona configuration with all optional fields |
complex-integration-test | read | Complex integration test persona |
config-without-tools | read | A config that lacks tools array |
coverage.check | read | Check code coverage |
create_issue | write | Creates a new issue in Linear |
custom-name | read | Custom description |
database.query | write | Execute database query |
debugger.attach | read | Attach debugger to process |
default-without-toolsets | read | Configuration with default toolset but no toolsets array |
delete-toolset | destructive | Delete a saved toolset configuration |
dev-tools | read | Short |
docker.build | read | Build docker image |
docker.compose.up | write | Start docker-compose services |
docker.ps | read | List running containers |
docker.run | write | Run docker container |
duplicate-tools | read | Configuration with duplicate tool IDs |
duplicate-toolsets | read | Configuration with duplicate toolset names |
dxtEnabled | write | Enable DXT extension system and management commands |
enableConfigToolsMenu | read | Enables a dynamic configuration tools menu instead of showing all tools together |
enter-configuration-mode | read | Enter configuration mode to manage toolsets |
equip-toolset | read | Equip a saved toolset configuration to filter available tools |
exit-configuration-mode | read | Leave configuration mode and return to normal operational mode. This will hide configuration tools and restore access to your equipped toolset |
extended-test | read | Extended test persona |
filesystem.read | read | Read file contents |
filesystem.write | write | Write file contents |
get-active-persona | read | Get information about the currently active persona. Returns the active persona |
get-active-toolset | read | Get detailed information about the currently equipped toolset including availability status |
git.add | write | Stage files for commit |
git.commit | write | Commit staged changes |
git.push | write | Push commits to remote |
git.status | read | Get git repository status |
git_status | read | Show the working tree status |
hello | read | Returns a friendly greeting |
integration-test | read | Integration test persona |
invalid-default | read | Configuration with invalid default toolset |
jest.run | write | Run Jest tests |
kubernetes.deploy | write | Deploy to Kubernetes |
list-available-tools | read | Discover all tools available from connected MCP servers |
list-personas | read | List available personas with their validation status and metadata. Returns structured data showing all discovered personas with essential information for selection and activation. |
list-saved-toolsets | read | List all saved toolset configurations with detailed information including server configurations and tool counts |
logs.search | read | Search application logs |
logs.tail | read | Tail application logs |
long-desc | read | x |
max-desc | read | x |
mcpLoggerEnabled | read | Use experimental mcp-logger instead of default Pino logging |
metrics.query | read | Query system metrics |
min-desc | read | x |
minimal-persona | read | A minimal persona configuration for testing purposes |
monitoring.check | read | Check monitoring status |
new_tool | read | A new tool |
no-toolsets | read | A persona without any toolsets defined |
npm.build | read | Build npm project |
npm.install | write | Install npm dependencies |
npm.test | write | Run npm tests |
partial-metadata | read | Persona with partial metadata |
profiler.start | write | Start performance profiling |
ps | read | Docker ps tool |
read | read | Read file from filesystem |
required-test | read | Test with all required fields |
save-test | write | Configuration for save test |
setupWizardEnabled | write | Enable interactive setup wizard on first run (default: disabled) |
short-desc | read | Too short |
simple-persona | read | Simple test persona |
status | read | Git status tool |
terraform.apply | write | Apply Terraform configuration |
test | read | Test configuration |
test-config | read | Test configuration |
test-persona | read | A test persona for archive tests |
test-toolset | read | Test toolset |
test_tool | read | A test tool |
unequip-toolset | read | Unequip the currently equipped toolset and show all available tools |
unknown-fields | read | Configuration with unknown fields |
valid-persona | read | A valid persona configuration |
validate-persona | read | Validate a specific persona |
wrong-name | read | A persona with wrong name |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (23)
flags: "--insecure",
- `-----BEGIN OPENSSH PRIVATE KEY-----`
- Ensure the deploy key is properly formatted (starts with `-----BEGIN OPENSSH PRIVATE KEY-----`)
"SLACK_BOT_TOKEN": "xoxb-YOUR-SLACK-BOT-TOKEN-HERE",
delete-toolset
persona-content-pack.md
persona-content-pack-tasks.md
.codannaignore
.markdownlint.json
.mcp.backup.json
.pre-commit-config.yaml
.prettierignore
import { ExtensionManager } from "../../extensions/index.js";import { ExtensionManager } from "../../extensions/index.js";import { ExtensionManager } from "../../extensions/index.js";import { ExtensionManager } from "../../extensions/index.js";import { ExtensionManager } from "../../extensions/index.js";@modelcontextprotocol/sdk
@modelcontextprotocol/sdk, @toolprint/mcp-logger, @types/chalk, @types/express, @types/figlet, @types/inquirer, @types/node-cache, axios
assets/hypertool_darkmode_wordmark_horizontal.png
assets/hypertool_lightmode_wordmark_horizontal.png
demos/build_dynamic_toolsets_1080p_25fps.gif
examples/hello-dxt.dxt
Gates applied: no_behavioural_pass.
a5df37f12690full audit observations/trust-audit/mcp-server/toolprint__hypertool.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a5df37f12690 | BLOCK | D | 69 | first audit |
Questions
What is the Hypertool MCP server?
Dynamically expose tools from proxied servers based on an Agent Persona
What tools does Hypertool expose?
80 in total: 60 read-only, 19 that write, and 1 that can delete or overwrite (delete-toolset). Every one is listed on this page with its risk.
Is Hypertool safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Hypertool need?
No credential environment variables were found in its source, so it appears to need none.
How does Hypertool run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @toolprint/hypertool-mcp at 0.0.46.
How current is this page?
The grade is for one exact copy of the source (a5df37f12690), read on 2026-10-07. The repository is watched and re-audited when it changes.