MCP ToolHub
Provides read-only Git repository inspection with status and diff tools, and supports administrator-approved Git shell commands for broader Git operations.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP ToolHubShow me the git status and current diff in the workspace."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP ToolHub
MCP ToolHub is a local, stdio-only Model Context Protocol server that exposes bounded workspace filesystem operations, read-only Git inspection, structured command execution, and an audit trail. Mutating filesystem operations and all agent-selected external shell commands use the existing out-of-band human approval model.
ToolHub does not expose an HTTP, SSE, or other network listener.
Features
Workspace-confined file reading, directory listing, writes, and patches
Read-only Git status and diff operations
Structured shell commands with deny-by-default risk classification
Atomic, expiring, single-use approval requests
Separate trusted administrator CLI; no MCP self-approval tool
Bounded, redacted JSON Lines audit events
Windows and POSIX support
Related MCP server: Laguarde
Requirements
Python 3.12 or newer (CI currently validates 3.12 and 3.13)
An MCP client that supports stdio servers
gitfor Git tools and approval-gated Git shell requests
Installation
Install from a source checkout with uv:
uv tool install .Or build and install the wheel:
uv build
uv tool install dist/mcp_toolhub-0.1.0-py3-none-any.whlInstallation provides two executables:
mcp-toolhub— the stdio MCP servermcp-toolhub-admin— the trusted human approval CLI
Runtime configuration
Workspace root
TOOLHUB_WORKSPACE_ROOT is required for mcp-toolhub serve and for the admin
CLI. It must contain an absolute path to an existing directory. ToolHub
canonicalizes the path once and freezes it for the lifetime of the process.
ToolHub intentionally does not default to the current directory, source checkout, or installation directory.
Trusted state root
TOOLHUB_STATE_ROOT optionally selects the directory containing
workspace-binding.json, approvals.json, and audit.jsonl. It must be
absolute when provided. The directory is permanently bound on first valid use
to exactly one canonical workspace; reusing it for another workspace fails
closed.
When TOOLHUB_STATE_ROOT is unset, ToolHub uses the platform-appropriate
per-user state directory from platformdirs as a base. Each canonical
workspace receives an independent namespace below workspaces/, named with a
deterministic SHA-256 identifier derived from the platform-normalized canonical
workspace path. The identifier avoids placing the workspace path in directory
names, but it is namespace separation rather than an authentication secret.
Moving or renaming a workspace normally creates a new default namespace.
The state directory is created as needed, canonicalized, and frozen with the workspace configuration. Startup fails if the state root is inside the workspace. The server and administrator CLI must run as the same user and with the same workspace and state configuration so they share this state.
POSIX example
export TOOLHUB_WORKSPACE_ROOT=/home/alice/projects/example
export TOOLHUB_STATE_ROOT=/home/alice/.local/state/mcp-toolhub
mcp-toolhub serveWindows PowerShell example
$env:TOOLHUB_WORKSPACE_ROOT = "D:\work\example"
$env:TOOLHUB_STATE_ROOT = "$env:LOCALAPPDATA\mcp-toolhub"
mcp-toolhub serveThe server writes no banner or human log text to stdout. Stdout is reserved exclusively for MCP protocol messages. Expected configuration errors are reported concisely on stderr and exit nonzero.
Commands
mcp-toolhub --version
mcp-toolhub serve
python -m mcp_toolhub serve
mcp-toolhub-admin --help
mcp-toolhub-admin list
mcp-toolhub-admin approve REQUEST_ID
mcp-toolhub-admin reject REQUEST_IDThe admin command is human-facing and may write ordinary output to stdout. It is not an MCP transport process.
MCP client configuration
The exact outer configuration key varies by client. A typical POSIX stdio entry is:
{
"mcpServers": {
"toolhub": {
"command": "mcp-toolhub",
"args": ["serve"],
"env": {
"TOOLHUB_WORKSPACE_ROOT": "/home/alice/projects/example",
"TOOLHUB_STATE_ROOT": "/home/alice/.local/state/mcp-toolhub"
}
}
}
}Windows paths require JSON escaping:
{
"mcpServers": {
"toolhub": {
"command": "mcp-toolhub",
"args": ["serve"],
"env": {
"TOOLHUB_WORKSPACE_ROOT": "D:\\work\\example",
"TOOLHUB_STATE_ROOT": "C:\\Users\\alice\\AppData\\Local\\mcp-toolhub"
}
}
}
}Use an absolute executable path if the MCP client does not inherit the shell's
PATH.
Tool inventory
The production server exposes exactly these 12 MCP tools:
toolhub.pingtoolhub.audit_recentfilesystem.list_directoryfilesystem.read_filefilesystem.write_filefilesystem.write_file_approvedfilesystem.apply_patchfilesystem.apply_patch_approvedgit.statusgit.diffshell.runshell.run_approved
There is no MCP administration, approve, or reject tool.
Human approval workflow
An MCP mutation or external shell request returns a pending request ID.
The administrator runs
mcp-toolhub-admin listwith the same workspace and state environment as the server.For approval, the administrator runs
mcp-toolhub-admin approve REQUEST_ID.The CLI displays the protected request and requires the operator to type
APPROVEexactly.The MCP caller invokes the corresponding
_approvedtool with the request ID. Successful consumption is atomic and single-use.
For shell requests, the approval display includes the original program, canonical resolved executable, SHA-256, byte size, cwd, and separately JSON-escaped argument values. It does not represent arguments as an ambiguous shell command string.
Security model and limitations
Structured shell commands
shell.run uses a deny-by-default command policy. LOW is limited to exact
ToolHub intrinsics, currently the running Python version query. LOW never
searches PATH and never creates an external subprocess. Generic Git, shell
interpreters, Windows batch scripts, the py launcher, and unknown programs
are never LOW.
Every external shell command is MEDIUM or HIGH and requires an out-of-band administrator approval. The approval captures immutable program, argument, cwd, timeout, workspace, and primary-executable snapshots. An approved shell request is atomically consumed before snapshot validation; any later failure permanently consumes it, so a retry requires a new approval.
Immediately before subprocess launch, ToolHub validates the primary
executable's canonical path, size, and SHA-256. Execution uses that absolute
path with shell=False. This is a validated primary executable identity
immediately before launch, not a cryptographic guarantee of the exact bytes
ultimately mapped by the operating system.
ToolHub guarantees:
LOW never creates an external subprocess.
Every external shell execution requires MEDIUM or HIGH approval.
The agent cannot replace approved program, arguments, cwd, or timeout.
Approvals are atomic, expiring, and single-use.
Workspace and primary-executable snapshots are required and fail closed.
The primary executable's canonical identity and hash are revalidated immediately before launch.
Filesystem paths remain within the frozen workspace boundary.
Mutation paths reject symlink traversal and enforce
expected_hashconcurrency checks where applicable.
ToolHub does not guarantee:
Exact byte identity against a concurrent local filesystem adversary during the narrow final check-to-exec race.
Identity of DLLs, interpreters, helpers, plugins, configuration files, environment-selected dependencies, or descendant processes.
That approved executable bytes are benign, signed, or from a reputable publisher.
The administrator approval display exposes the protected canonical path, hash, size, cwd, and exact JSON-escaped argument boundaries. Agent-readable audit events omit external executable directories, retaining basename, hash, size, scope, and request-ID correlation.
Audit behavior
Audit events are appended to audit.jsonl under the trusted state root. They
contain bounded metadata, redact recognizable secret arguments, and store only
stdout/stderr character counts rather than raw process output. Audit write
failures are non-fatal to tool execution.
Development
Install all locked runtime and development dependencies:
uv sync --all-groupsRun the required checks:
uv run ruff check .
uv run ruff format --check .
uv run python -m compileall -q src/mcp_toolhub
uv run pytest -q
uv build
git diff --checkTo apply formatting deliberately:
uv run ruff format .Artifact smoke test
After uv build, run the cross-platform smoke driver with a virtual
environment outside the checkout.
POSIX:
uv run python scripts/artifact_smoke.py --dist-dir dist --venv /tmp/mcp-toolhub-wheel-env --repository .Windows PowerShell:
uv run python scripts/artifact_smoke.py --dist-dir dist --venv "$env:TEMP\mcp-toolhub-wheel-env" --repository .The driver inspects wheel contents, installs only the wheel into the isolated
environment, verifies console/version behavior, and runs initialize,
list_tools, ping, configured workspace access, invalid configuration, and
server/admin shared-state tests from outside the repository.
Troubleshooting
TOOLHUB_WORKSPACE_ROOT is required: add an absolute existing workspace path to the MCP client's environment.Workspace is not a directory: create the directory or correct the path.
State root must be outside the workspace: move
TOOLHUB_STATE_ROOTto a trusted directory the MCP filesystem tools cannot address.State namespace belongs to a different workspace: select a different explicit
TOOLHUB_STATE_ROOT; bindings are never silently reassigned.Client reports invalid stdio JSON: verify wrappers and startup scripts do not print banners or logs to stdout.
Admin cannot see a request: confirm server and admin run as the same user with identical workspace and state-root settings.
Executable changed after approval: request a new approval; consumed or invalidated approvals are never replayed.
Production ToolHub intentionally exposes no HTTP, SSE, public network, authentication-server, container-orchestration, or cloud-hosting surface.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceCombines AST intelligence and guarded file operations to provide a secure, controlled repository workflow for coding agents, enabling structural code analysis and safe edits without unbounded editor access.99MIT
- FlicenseNot gradedqualityBmaintenanceEnables AI coding agents to evaluate actions against team-defined policies, record decisions, and obtain human approvals for potentially risky operations.1651
- FlicenseNot gradedqualityCmaintenanceEnables controlled AI-agent access to enterprise-shaped tools with a deny-by-default gated write path, human approval, dry-run execution, and append-only audit logging.
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to safely read and write files in a sandboxed workspace via natural language, with on-demand connection, CVE-hardened path confinement, injection resistance, and full audit logging.
Related MCP Connectors
Runtime permission, approval, and audit layer for AI agent tool execution.
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/asxvgxkep/mcp-toolhub'
If you have feedback or need assistance with the MCP directory API, please join our Discord server