Atlas / MCP servers / zachhandley / ZMCPTools

ZMCPToolsBLOCK

mcp/zachhandley/zmcptools

A custom TypeScript MCP Server intended to be used with Claude Code

Verdict
BLOCK
Grade
F
Trust score
42 /100
Exposed tools
137 110r · 17w · 10d
Transport
stdio · streamable-http
License
—
Stars
41
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/zachhandley-zmcptools)

[](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://nodejs.org/) [](https://modelcontextprotocol.io/)

🚀 TypeScript MCP Tools for Claude Code - Professional multi-agent orchestration platform with 61 enhanced tools, documentation intelligence, and advanced automation capabilities.

⚠️ Important Setup Note

Before spawning agents, run this command once to enable proper agent permissions:

claude --dangerously-skip-permissions

Agents run on daemon threads and need this permission to execute properly.

✨ Key Features

🎯 Multi-Agent Orchestration

  • Architect-Led Coordination: AI architect automatically spawns and coordinates specialized agent teams
  • Intelligent Dependencies: Agents work in proper order (Backend → Frontend → Testing → Documentation)
  • Real-Time Communication: Agents collaborate through dedicated chat rooms with message broadcasting
  • Foundation Session Caching: 85-90% cost reduction through automatic shared context management
  • Professional Task Management: Create, assign, track, and monitor complex development workflows

🎨 TypeScript-First Architecture

  • Type-Safe MCP Server: Built with Zod schemas and strict TypeScript for reliability
  • Modern CLI Interface: Commander.js-powered CLI with structured command hierarchy
  • Development Ready: One-command setup with hot-reload development via tsx
  • Binary Distribution: Global access via claude-mcp-tools and claude-mcp-server commands
  • Professional Build System: tsup-based compilatio
Read from source at commit 509dcbf1e3f1OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add zmcp-tools -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "zmcp-tools": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (137)

110 read · 17 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ImplementationreadCore feature implementation
agent_typesreadPreferred agent types for execution (comma-separated)
analysis_typereadType of analysis (technical, business, strategic, etc.)
analyze_coordination_patternsreadAnalyze coordination patterns and suggest improvements
analyze_dom_structurereadAI-guided exploration and analysis of DOM structure using goal-oriented patterns. Analyzes stored DOM JSON to identify interactive elements, content areas, and navigation patterns.
analyze_file_symbolsreadExtract and analyze symbols (functions, classes, etc.) from code files
analyze_project_structurereadAnalyze project structure and generate a comprehensive overview
analyze_screenshotreadAI-powered analysis of page screenshots with custom prompts. Can focus on specific regions and provide contextual insights.
api-documenterreadGenerate comprehensive API documentation with examples and schemas
api_filesreadAPI files or endpoints to document
approachreadPreferred approach (investigation, implementation, testing)
architect-orchestrationreadArchitect agent for complex multi-agent orchestration with sequential thinking
architect-planning-templatereadTemplate for architect agents to use sequential thinking for planning
architecturereadPreferred architecture or patterns to use
audiencereadTarget audience (developers, users, maintainers)
backwards_compatiblereadRequire backwards compatibility (true/false)
breakdown_depthreadBreakdown depth (shallow, medium, deep)
broadcast_message_to_agentsreadBroadcast a message to multiple agents with auto-resume functionality
bug_descriptionreadDescription of the bug to fix
cancel_scrape_jobreadCancel an active or pending scraping job
cleanup_orphaned_projectsreadClean up orphaned or unused project directories
cleanup_stale_agentsreadClean up stale agents with enhanced options and optional room cleanup
cleanup_stale_analysesreadClean up stale analysis files older than specified days
cleanup_stale_roomsreadClean up stale rooms based on activity and participant criteria
close_browser_sessionread[LEGACY] Close a browser session. Use manage_browser_sessions instead.
close_roomdestructiveClose a communication room (soft delete - marks as closed but keeps data)
code-reviewreadComprehensive code review with security, performance, and quality analysis
collectionreadVector collection to search (default: documentation)
collection_namewriteVector collection name to create/manage
complexity_levelreadComplexity level (low, medium, high, very_high)
constraintsreadConstraints or requirements to maintain
continue_agent_sessionreadContinue an agent session using stored conversation session ID with additional instructions
create_browser_sessionwriteCreate a new browser session with intelligent auto-close and session management
create_delayed_roomwriteCreate a delayed room for coordination when agents realize they need it
create_execution_planwriteCreate comprehensive execution plan using sequential thinking before spawning agents
create_knowledge_relationshipwriteCreate a relationship between two entities in the knowledge graph
create_taskwriteCreate and assign task to agents with enhanced capabilities
criteriareadDecision criteria or evaluation factors
database_typereadDatabase type (sqlite, postgres, mysql)
db-migrationwritePlan and execute database schema migrations safely
decision_contextreadContext and background for the decision
delete_all_website_pagesdestructiveDelete all pages for a website (useful for clean slate before re-scraping)
delete_execution_plandestructiveDelete an execution plan by ID
delete_pages_by_idsdestructiveDelete specific pages by their IDs
delete_pages_by_patterndestructiveDelete website pages matching URL patterns (useful for cleaning up version URLs, static assets)
delete_roomdestructivePermanently delete a communication room and all its messages
depthreadAnalysis depth (surface, detailed, comprehensive)
documentation-writerwriteCreate comprehensive documentation for code, APIs, and features
domainreadProblem domain (technical, business, architectural, etc.)
easy_replacereadFuzzy string replacement in files with smart matching
embedding_providerreadEmbedding provider (openai, default)
execute_browser_scriptwrite[LEGACY] Execute JavaScript in the browser context. Use interact_with_page instead.
execute_with_planwriteExecute an objective using a pre-created execution plan with well-defined agent tasks
feature-implementerreadSystematic feature implementation with planning and testing
feature_descriptionreadDetailed description of the feature to implement
files_affectedreadComma-separated list of files that might be affected
find_filesreadSearch for files by pattern with optional content matching
find_related_entitiesreadFind related entities through relationship traversal
force_unlock_jobdestructiveForce unlock a stuck scraping job - useful for debugging and recovery
force_unlock_stuck_jobsdestructiveForce unlock all stuck scraping jobs (jobs that haven\
formatreadDocumentation format (markdown, API docs, inline comments)
foundation_sessionreadFoundation session ID for cost reduction
generate_project_summaryreadGenerate AI-optimized project overview and analysis
get_cleanup_configurationreadGet current cleanup configuration and settings for agents and rooms
get_execution_planreadRetrieve a previously created execution plan
get_page_screenshotreadRetrieve stored screenshot for a page. Returns file path or base64 encoded image data for AI visual analysis.
get_project_overviewreadGet comprehensive project overview from TreeSummary analysis
get_scraping_statusreadGet status of active and recent scraping jobs (worker runs automatically)
include_examplesreadInclude request/response examples (true/false)
integration_depthreadIntegration depth (surface, detailed, comprehensive)
interact_with_elementread[LEGACY] Interact with a page element. Use interact_with_page instead.
interact_with_pagereadPerform multiple interactions with a page: click, type, hover, select, screenshot, wait, scroll
issue-fixerreadSingle-agent focused problem solver for specific issues
issue_descriptionreadDescription of the issue to resolve
join_roomreadJoin communication room for coordination
knowledge-graph-integrationreadIntegrate knowledge graph memory for better context and decision making
knowledge_domainsreadSpecific knowledge domains to search (comma-separated)
limitreadMaximum number of results (default: 10)
list_agentsreadGet list of active agents
list_browser_sessionsread[LEGACY] List all browser sessions. Use manage_browser_sessions instead.
list_documentation_sourcesreadList all configured documentation sources
list_execution_plansreadList execution plans for discovery and monitoring
list_filesreadList files in a directory with smart ignore patterns
list_room_messagesreadList messages from a specific room with pagination
list_roomsreadList communication rooms with filtering and pagination
manage_browser_sessionsreadManage browser sessions: list, close, cleanup idle sessions, get status
metricsreadPerformance metrics to focus on (speed, memory, throughput)
migration_typereadType of migration (schema, data, index, cleanup)
monitor_agentsreadMonitor agents with real-time updates using EventBus system
multi-agent-bug-fixreadCoordinate multiple agents to investigate and fix a bug with comprehensive testing
navigate_and_scrapereadNavigate to a URL and optionally scrape content in one operation. Auto-creates session if needed.
navigate_dom_pathreadNavigate to specific elements in DOM JSON using dot notation paths (e.g.,
navigate_to_urlread[LEGACY] Navigate to a URL in an existing browser session. Use navigate_and_scrape instead.
objectivereadComplex objective to decompose and plan
optionsreadAvailable options or alternatives
orchestrate_objectivereadSpawn architect agent to coordinate multi-agent objective completion
orchestrate_objective_structuredwriteExecute structured phased orchestration with intelligent model selection (Research → Plan → Execute → Monitor → Cleanup)
performance-optimizerreadAnalyze and optimize code performance with benchmarking
planning_contextreadContext requiring strategic planning
priorityreadPriority level (low, medium, high, critical)
problem_descriptionreadComplex problem to analyze and solve
queryreadSearch query for semantic similarity matching
remove_file_analysisdestructiveRemove analysis data for a deleted file from the TreeSummary system
report_progressreadReport progress updates for agent tasks and status changes
repository_pathreadPath to the repository
requirementsreadSpecific requirements or acceptance criteria
review_typereadType of review (security, performance, quality, full)
run_comprehensive_cleanupwriteRun comprehensive cleanup for both agents and rooms with detailed reporting
scrape_contentread[LEGACY] Scrape content from the current page. Use navigate_and_scrape instead.
scrape_documentationreadScrape documentation from a website using intelligent sub-agents. Jobs are queued and processed automatically by the background worker. Supports plain string selectors for content extraction.
search_dom_elementsreadSearch for DOM elements by type, content, keywords, or attributes. Returns matching elements with their paths for further navigation.
search_knowledge_graphreadSearch the knowledge graph using semantic or basic search
semantic-searchreadPerform semantic search across documentation using vector embeddings
send_messagewriteSend message to coordination room
sequential-thinking-analysisreadUse sequential thinking for step-by-step analysis of complex topics
sequential-thinking-architectreadUse sequential thinking for complex objective decomposition and planning
sequential-thinking-decisionreadUse sequential thinking for complex decision making processes
sequential-thinking-problem-solverreadUse sequential thinking for complex problem analysis and solution development
server_urlreadChromaDB server URL (default: localhost:8000)
spawn_agentreadSpawn fully autonomous Claude agent with complete tool access
stakeholdersreadKey stakeholders and their requirements
standardsreadCoding standards or guidelines to follow
store_knowledge_memoryreadStore a knowledge graph memory with entity creation
take_screenshotread[LEGACY] Take a screenshot of the current page. Use interact_with_page instead.
targetreadWhat to document (API, feature, codebase, etc.)
target_areareadArea to optimize (database, API, algorithms, etc.)
target_filesreadFiles or patterns to review (e.g.,
task-breakdown-specialistreadSpecialized agent for hierarchical task breakdown and planning
task_contextreadContext of the task requiring knowledge integration
terminate_agentdestructiveTerminate one or more agents
thresholdreadSimilarity threshold 0-1 (default: 0.7)
topicreadTopic or subject to analyze
update_execution_planwriteUpdate an execution plan\
update_file_analysiswriteUpdate or create analysis data for a specific file in the TreeSummary system
update_project_metadatawriteUpdate project metadata in the TreeSummary system
vector-db-setupwriteSet up and configure ChromaDB vector database for semantic search
wait_for_messagesreadWait for messages in a room
04

Trust audit

BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/services/BrowserManager.ts:302
const dynamicFunction = new Function('document', 'window', `return (${selectorOrCode})`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/services/WebScrapingService.ts:995
const elements = await page.$$eval(selector, (elements) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/tools/BrowserTools.ts:649
const func = new Function('...args', script);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/CLAUDE_CODE_SDK.md:14
[
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/CLAUDE_CODE_SDK.md:25
[
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/CLAUDE_CODE_SDK.md:38
[
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/CLAUDE_CODE_SDK.md:51
[
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/CLAUDE_CODE_SDK.md:62
[
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/installer/index.ts:480
const mcpCommand = `claude mcp add --transport http claude-mcp-tools-http http://127.0.0.1:${port}`;
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
close_room, delete_all_website_pages, delete_execution_plan, delete_pages_by_ids, delete_pages_by_pattern, delete_room, force_unlock_job, force_unlock_stuck_jobs, remove_file_analysis, terminate_agent
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.claudeignore
.claudeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmessage
.gitmessage
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/schemas/tools/webScraping.ts:2
import type { ScrapingPattern, StringPattern, PathPattern, VersionPattern } from '../../utils/patternMatcher.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/claude-code, @lancedb/lancedb, @lezer/common, @lezer/cpp, @lezer/css, @lezer/highlight, @lezer/html, @lezer/java
Why it matters. 48 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/CLAUDE_CODE_SDK.md:263
$ claude -p "Build a REST API" --system-prompt "You are a senior backend engineer. Focus on security, performance, and maintainability."
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:331
The following aliases are available (add to `~/.zshrc`):
Why it matters. instructs the agent to persist itself in the user's environment
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/CLAUDE_CODE.md:999
curl -s https://internal.company.com/claude-setup.sh | bash

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 509dcbf1e3f1full audit observations/trust-audit/mcp-server/zachhandley__zmcptools.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08509dcbf1e3f1BLOCKF42first audit
06

Questions

What is the ZMCPTools MCP server?

A custom TypeScript MCP Server intended to be used with Claude Code

What tools does ZMCPTools expose?

137 in total: 110 read-only, 17 that write, and 10 that can delete or overwrite (close_room, delete_all_website_pages, delete_execution_plan, delete_pages_by_ids, delete_pages_by_pattern). Every one is listed on this page with its risk.

Is ZMCPTools safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (42/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ZMCPTools need?

No credential environment variables were found in its source, so it appears to need none.

How does ZMCPTools run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as zmcp-tools at 0.2.2.

How current is this page?

The grade is for one exact copy of the source (509dcbf1e3f1), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement