ZMCPToolsBLOCK
A custom TypeScript MCP Server intended to be used with Claude Code
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/zachhandley-zmcptools)
[](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://nodejs.org/) [](https://modelcontextprotocol.io/)
🚀 TypeScript MCP Tools for Claude Code - Professional multi-agent orchestration platform with 61 enhanced tools, documentation intelligence, and advanced automation capabilities.
⚠️ Important Setup Note
Before spawning agents, run this command once to enable proper agent permissions:
claude --dangerously-skip-permissions
Agents run on daemon threads and need this permission to execute properly.
✨ Key Features
🎯 Multi-Agent Orchestration
- Architect-Led Coordination: AI architect automatically spawns and coordinates specialized agent teams
- Intelligent Dependencies: Agents work in proper order (Backend → Frontend → Testing → Documentation)
- Real-Time Communication: Agents collaborate through dedicated chat rooms with message broadcasting
- Foundation Session Caching: 85-90% cost reduction through automatic shared context management
- Professional Task Management: Create, assign, track, and monitor complex development workflows
🎨 TypeScript-First Architecture
- Type-Safe MCP Server: Built with Zod schemas and strict TypeScript for reliability
- Modern CLI Interface: Commander.js-powered CLI with structured command hierarchy
- Development Ready: One-command setup with hot-reload development via tsx
- Binary Distribution: Global access via
claude-mcp-toolsandclaude-mcp-servercommands - Professional Build System: tsup-based compilatio
509dcbf1e3f1OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add zmcp-tools -- npx -y [email protected]
{
"mcpServers": {
"zmcp-tools": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (137)
110 read · 17 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Implementation | read | Core feature implementation |
agent_types | read | Preferred agent types for execution (comma-separated) |
analysis_type | read | Type of analysis (technical, business, strategic, etc.) |
analyze_coordination_patterns | read | Analyze coordination patterns and suggest improvements |
analyze_dom_structure | read | AI-guided exploration and analysis of DOM structure using goal-oriented patterns. Analyzes stored DOM JSON to identify interactive elements, content areas, and navigation patterns. |
analyze_file_symbols | read | Extract and analyze symbols (functions, classes, etc.) from code files |
analyze_project_structure | read | Analyze project structure and generate a comprehensive overview |
analyze_screenshot | read | AI-powered analysis of page screenshots with custom prompts. Can focus on specific regions and provide contextual insights. |
api-documenter | read | Generate comprehensive API documentation with examples and schemas |
api_files | read | API files or endpoints to document |
approach | read | Preferred approach (investigation, implementation, testing) |
architect-orchestration | read | Architect agent for complex multi-agent orchestration with sequential thinking |
architect-planning-template | read | Template for architect agents to use sequential thinking for planning |
architecture | read | Preferred architecture or patterns to use |
audience | read | Target audience (developers, users, maintainers) |
backwards_compatible | read | Require backwards compatibility (true/false) |
breakdown_depth | read | Breakdown depth (shallow, medium, deep) |
broadcast_message_to_agents | read | Broadcast a message to multiple agents with auto-resume functionality |
bug_description | read | Description of the bug to fix |
cancel_scrape_job | read | Cancel an active or pending scraping job |
cleanup_orphaned_projects | read | Clean up orphaned or unused project directories |
cleanup_stale_agents | read | Clean up stale agents with enhanced options and optional room cleanup |
cleanup_stale_analyses | read | Clean up stale analysis files older than specified days |
cleanup_stale_rooms | read | Clean up stale rooms based on activity and participant criteria |
close_browser_session | read | [LEGACY] Close a browser session. Use manage_browser_sessions instead. |
close_room | destructive | Close a communication room (soft delete - marks as closed but keeps data) |
code-review | read | Comprehensive code review with security, performance, and quality analysis |
collection | read | Vector collection to search (default: documentation) |
collection_name | write | Vector collection name to create/manage |
complexity_level | read | Complexity level (low, medium, high, very_high) |
constraints | read | Constraints or requirements to maintain |
continue_agent_session | read | Continue an agent session using stored conversation session ID with additional instructions |
create_browser_session | write | Create a new browser session with intelligent auto-close and session management |
create_delayed_room | write | Create a delayed room for coordination when agents realize they need it |
create_execution_plan | write | Create comprehensive execution plan using sequential thinking before spawning agents |
create_knowledge_relationship | write | Create a relationship between two entities in the knowledge graph |
create_task | write | Create and assign task to agents with enhanced capabilities |
criteria | read | Decision criteria or evaluation factors |
database_type | read | Database type (sqlite, postgres, mysql) |
db-migration | write | Plan and execute database schema migrations safely |
decision_context | read | Context and background for the decision |
delete_all_website_pages | destructive | Delete all pages for a website (useful for clean slate before re-scraping) |
delete_execution_plan | destructive | Delete an execution plan by ID |
delete_pages_by_ids | destructive | Delete specific pages by their IDs |
delete_pages_by_pattern | destructive | Delete website pages matching URL patterns (useful for cleaning up version URLs, static assets) |
delete_room | destructive | Permanently delete a communication room and all its messages |
depth | read | Analysis depth (surface, detailed, comprehensive) |
documentation-writer | write | Create comprehensive documentation for code, APIs, and features |
domain | read | Problem domain (technical, business, architectural, etc.) |
easy_replace | read | Fuzzy string replacement in files with smart matching |
embedding_provider | read | Embedding provider (openai, default) |
execute_browser_script | write | [LEGACY] Execute JavaScript in the browser context. Use interact_with_page instead. |
execute_with_plan | write | Execute an objective using a pre-created execution plan with well-defined agent tasks |
feature-implementer | read | Systematic feature implementation with planning and testing |
feature_description | read | Detailed description of the feature to implement |
files_affected | read | Comma-separated list of files that might be affected |
find_files | read | Search for files by pattern with optional content matching |
find_related_entities | read | Find related entities through relationship traversal |
force_unlock_job | destructive | Force unlock a stuck scraping job - useful for debugging and recovery |
force_unlock_stuck_jobs | destructive | Force unlock all stuck scraping jobs (jobs that haven\ |
format | read | Documentation format (markdown, API docs, inline comments) |
foundation_session | read | Foundation session ID for cost reduction |
generate_project_summary | read | Generate AI-optimized project overview and analysis |
get_cleanup_configuration | read | Get current cleanup configuration and settings for agents and rooms |
get_execution_plan | read | Retrieve a previously created execution plan |
get_page_screenshot | read | Retrieve stored screenshot for a page. Returns file path or base64 encoded image data for AI visual analysis. |
get_project_overview | read | Get comprehensive project overview from TreeSummary analysis |
get_scraping_status | read | Get status of active and recent scraping jobs (worker runs automatically) |
include_examples | read | Include request/response examples (true/false) |
integration_depth | read | Integration depth (surface, detailed, comprehensive) |
interact_with_element | read | [LEGACY] Interact with a page element. Use interact_with_page instead. |
interact_with_page | read | Perform multiple interactions with a page: click, type, hover, select, screenshot, wait, scroll |
issue-fixer | read | Single-agent focused problem solver for specific issues |
issue_description | read | Description of the issue to resolve |
join_room | read | Join communication room for coordination |
knowledge-graph-integration | read | Integrate knowledge graph memory for better context and decision making |
knowledge_domains | read | Specific knowledge domains to search (comma-separated) |
limit | read | Maximum number of results (default: 10) |
list_agents | read | Get list of active agents |
list_browser_sessions | read | [LEGACY] List all browser sessions. Use manage_browser_sessions instead. |
list_documentation_sources | read | List all configured documentation sources |
list_execution_plans | read | List execution plans for discovery and monitoring |
list_files | read | List files in a directory with smart ignore patterns |
list_room_messages | read | List messages from a specific room with pagination |
list_rooms | read | List communication rooms with filtering and pagination |
manage_browser_sessions | read | Manage browser sessions: list, close, cleanup idle sessions, get status |
metrics | read | Performance metrics to focus on (speed, memory, throughput) |
migration_type | read | Type of migration (schema, data, index, cleanup) |
monitor_agents | read | Monitor agents with real-time updates using EventBus system |
multi-agent-bug-fix | read | Coordinate multiple agents to investigate and fix a bug with comprehensive testing |
navigate_and_scrape | read | Navigate to a URL and optionally scrape content in one operation. Auto-creates session if needed. |
navigate_dom_path | read | Navigate to specific elements in DOM JSON using dot notation paths (e.g., |
navigate_to_url | read | [LEGACY] Navigate to a URL in an existing browser session. Use navigate_and_scrape instead. |
objective | read | Complex objective to decompose and plan |
options | read | Available options or alternatives |
orchestrate_objective | read | Spawn architect agent to coordinate multi-agent objective completion |
orchestrate_objective_structured | write | Execute structured phased orchestration with intelligent model selection (Research → Plan → Execute → Monitor → Cleanup) |
performance-optimizer | read | Analyze and optimize code performance with benchmarking |
planning_context | read | Context requiring strategic planning |
priority | read | Priority level (low, medium, high, critical) |
problem_description | read | Complex problem to analyze and solve |
query | read | Search query for semantic similarity matching |
remove_file_analysis | destructive | Remove analysis data for a deleted file from the TreeSummary system |
report_progress | read | Report progress updates for agent tasks and status changes |
repository_path | read | Path to the repository |
requirements | read | Specific requirements or acceptance criteria |
review_type | read | Type of review (security, performance, quality, full) |
run_comprehensive_cleanup | write | Run comprehensive cleanup for both agents and rooms with detailed reporting |
scrape_content | read | [LEGACY] Scrape content from the current page. Use navigate_and_scrape instead. |
scrape_documentation | read | Scrape documentation from a website using intelligent sub-agents. Jobs are queued and processed automatically by the background worker. Supports plain string selectors for content extraction. |
search_dom_elements | read | Search for DOM elements by type, content, keywords, or attributes. Returns matching elements with their paths for further navigation. |
search_knowledge_graph | read | Search the knowledge graph using semantic or basic search |
semantic-search | read | Perform semantic search across documentation using vector embeddings |
send_message | write | Send message to coordination room |
sequential-thinking-analysis | read | Use sequential thinking for step-by-step analysis of complex topics |
sequential-thinking-architect | read | Use sequential thinking for complex objective decomposition and planning |
sequential-thinking-decision | read | Use sequential thinking for complex decision making processes |
sequential-thinking-problem-solver | read | Use sequential thinking for complex problem analysis and solution development |
server_url | read | ChromaDB server URL (default: localhost:8000) |
spawn_agent | read | Spawn fully autonomous Claude agent with complete tool access |
stakeholders | read | Key stakeholders and their requirements |
standards | read | Coding standards or guidelines to follow |
store_knowledge_memory | read | Store a knowledge graph memory with entity creation |
take_screenshot | read | [LEGACY] Take a screenshot of the current page. Use interact_with_page instead. |
target | read | What to document (API, feature, codebase, etc.) |
target_area | read | Area to optimize (database, API, algorithms, etc.) |
target_files | read | Files or patterns to review (e.g., |
task-breakdown-specialist | read | Specialized agent for hierarchical task breakdown and planning |
task_context | read | Context of the task requiring knowledge integration |
terminate_agent | destructive | Terminate one or more agents |
threshold | read | Similarity threshold 0-1 (default: 0.7) |
topic | read | Topic or subject to analyze |
update_execution_plan | write | Update an execution plan\ |
update_file_analysis | write | Update or create analysis data for a specific file in the TreeSummary system |
update_project_metadata | write | Update project metadata in the TreeSummary system |
vector-db-setup | write | Set up and configure ChromaDB vector database for semantic search |
wait_for_messages | read | Wait for messages in a room |
Trust audit
BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
const dynamicFunction = new Function('document', 'window', `return (${selectorOrCode})`);const elements = await page.$$eval(selector, (elements) => {const func = new Function('...args', script);[
[
[
[
[
const mcpCommand = `claude mcp add --transport http claude-mcp-tools-http http://127.0.0.1:${port}`;close_room, delete_all_website_pages, delete_execution_plan, delete_pages_by_ids, delete_pages_by_pattern, delete_room, force_unlock_job, force_unlock_stuck_jobs, remove_file_analysis, terminate_agent
.claudeignore
.gitmessage
import type { ScrapingPattern, StringPattern, PathPattern, VersionPattern } from '../../utils/patternMatcher.js';@anthropic-ai/claude-code, @lancedb/lancedb, @lezer/common, @lezer/cpp, @lezer/css, @lezer/highlight, @lezer/html, @lezer/java
$ claude -p "Build a REST API" --system-prompt "You are a senior backend engineer. Focus on security, performance, and maintainability."
The following aliases are available (add to `~/.zshrc`):
curl -s https://internal.company.com/claude-setup.sh | bash
Gates applied: no_behavioural_pass, no_license.
509dcbf1e3f1full audit observations/trust-audit/mcp-server/zachhandley__zmcptools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 509dcbf1e3f1 | BLOCK | F | 42 | first audit |
Questions
What is the ZMCPTools MCP server?
A custom TypeScript MCP Server intended to be used with Claude Code
What tools does ZMCPTools expose?
137 in total: 110 read-only, 17 that write, and 10 that can delete or overwrite (close_room, delete_all_website_pages, delete_execution_plan, delete_pages_by_ids, delete_pages_by_pattern). Every one is listed on this page with its risk.
Is ZMCPTools safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (42/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does ZMCPTools need?
No credential environment variables were found in its source, so it appears to need none.
How does ZMCPTools run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as zmcp-tools at 0.2.2.
How current is this page?
The grade is for one exact copy of the source (509dcbf1e3f1), read on 2026-10-08. The repository is watched and re-audited when it changes.