📡 MCP Radar

zhihaochen67/mcp-toolhub

Security-focused MCP server for coding agents, featuring approval-gated execution, hardened filesystem/Git tools, audit logs, and workspace isolation.

3 stars
0 forks
Python
momentum ▲ 10.0
created 2026-08-26
on radar since 2026-08-30
View on GitHub ↗

About mcp-toolhub

MCP ToolHub is a local, stdio-only Model Context Protocol server that exposes bounded workspace filesystem operations, read-only Git inspection, structured command execution, and an audit trail. Mutating filesystem operations and all agent-selected external shell commands use the existing out-of-band human approval model.

ToolHub does not expose an HTTP, SSE, or other network listener.

- Workspace-confined file reading, directory listing, writes, and patches - Read-only Git status and diff operations - Structured shell commands with deny-by-default risk classification - OS-backed process-tree containment for external executions - Atomic, expiring, single-use approval requests - Versioned, resumable Contract V1 lifecycle results - Separate trusted administrator CLI; no MCP self-approval tool - Bounded, redacted JSON Lines audit events - Windows and POSIX support

- Python 3.12 or newer (CI currently validates 3.12 and 3.13) - An MCP client that supports stdio servers - git for Git tools and approval-gated Git shell requests

- mcp-toolhub — the stdio MCP server - mcp-toolhub-admin — the trusted human approval CLI

TOOLHUBWORKSPACEROOT is required for mcp-toolhub serve and for the admin CLI. It must contain an absolute path to an existing directory. ToolHub canonicalizes the path once and freezes it for the lifetime of the process.

ToolHub intentionally does not default to the current directory, source checkout, or installation directory.

From the project README.

Maintaining this server?

Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:

[![On MCP Radar](https://mcp.liqiwa.com/badge.svg)](https://mcp.liqiwa.com/s/zhihaochen67--mcp-toolhub.html)

Related MCP servers

fellowgeek/mcp-memory

An OKF-backed Model Context Protocol (MCP) server delivering persistent long-term memory and SQLite FTS5 search for AI agents.

⭐ 188Python
sosoj92/jarvis-assistant-vocal

Assistant vocal local en francais : Claude ou Ollama (offline), domotique Hue, OBS, agenda, navigateur, appels Twilio, serveur MCP. Python.

⭐ 132Python
Stupidoodle/swissdevjobs-cli

Search & apply to ~4,700 salary-transparent tech jobs across 7 countries (🇨🇭🇩🇪🇬🇧🇺🇸🇨🇦🇳🇱🇫🇷) from your terminal or AI agent — zero-dependency Python CLI + MCP server + Claude Code plugin

⭐ 92Python
agents-universe/agents-universe

让智能体像人一样学习和工作,共享智能体和项目记忆

⭐ 83Python
bybit-exchange/kaas

Turn scattered notes, docs and transcripts into a queryable Markdown wiki — an LLM knowledge-base compiler with MCP access, no embeddings, self-hosted.

⭐ 82Python
alxgntv/substack-api-mcp

MCP server for Substack posts (FastMCP + substack-api-client)

⭐ 80Python

📬 Get the weekly radar in your inbox

The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.