Read/write files within allow-listed directories.
Every server, safety-graded
18 MCP servers across development, data, messaging, and system categories. Each reviewed against a 45-check permission matrix and assigned a tier: SAFE, CAUTION, or DANGER.
Read repos, issues, PRs. Write requires explicit scope.
Read-only SQL queries against user-supplied database.
Web search via Brave API.
Fetch URLs and extract text content.
Persistent local key-value store for cross-session memory.
Post messages, read channels with workspace auth.
Read error reports and issue metadata.
Read customers, subscriptions. Write gated by explicit scopes.
Read/write issues, projects, cycles.
List and read files with OAuth scopes.
Read/write Notion pages and databases.
Execute shell commands. Requires explicit allow-list.
Headless browser automation. Can interact with sensitive sites.
Send emails via SMTP. Requires confirmation mode for production.
Full desktop file + process access. Review permissions carefully.
Shell access with no sandbox. Agent can execute arbitrary commands.
Signs and broadcasts on-chain transactions. Private keys stored locally.