Generate random IDs, QR codes, and hashes, encode and decode values, and geolocate IPs, plus gated network and system diagnostics, via MCP. STDIO or Streamable HTTP.
Strong, consistent quality across 7 tools. All tools have clear names starting with action verbs (toolkit_*), comprehensive descriptions (172 - 370 chars), and complete JSON Schema with type definitions and parameter constraints. Output schemas are documented in descriptions. Tool names are distinct and specific (generate_id vs generate_qr, hash_value vs encode_value). No secrets in parameters. Error handling guidance present in descriptions (e.g., 'Decoding a value that is malformed... is reported as a recoverable error'). Minor gaps: output field details could be more formally structured as separate schema documentation; no per-tool permission annotations; error categorization (retryable vs. fatal) not explicit in all tools.
Run a read-only network diagnostic from the server host. mode selects the probe: ping (ICMP round-trip), traceroute (the hop path to the target), connectivity (a raw TCP connect to target on port), or public_ip (the host's own egress IP, where target is absent and ignored). target takes an IPv4/IPv6 address or a hostname (resolved server-side) and is required for every mode except public_ip; port is required only for connectivity and is passed separately, never as host:port. count sets ping echo requests and timeoutMs the per-probe deadline. A host that does not respond is reported as reachable:false — a valid result, not an error. The populated output fields depend on mode. This tool diagnoses the SERVER's own network, so it is useful only on a local/self-hosted deployment; reaching a private/reserved/internal target additionally requires the operator to enable TOOLKIT_ALLOW_PRIVATE_NETWORK.
Report a facet of the server host's system state, read-only. what selects the facet: os (platform, release, architecture, hostname, uptime, Node version), cpu (model, core count, speed), memory (total/free/used bytes), load (1/5/15-minute load averages, all zero on Windows), or interfaces (non-internal network interfaces with their addresses and families). Exactly one facet object is populated per call, matching what; the others are absent. All values describe the host this server runs on, NOT the calling client — so this is useful only on a local or self-hosted deployment. interfaces and os disclose host topology and version details, which is why this tool is gated off by default.
Encode or decode a value across base64, base64url, hex, or URL (percent) encoding, in either direction. Set operation to "encode" to transform raw UTF-8 text into the chosen encoding, or "decode" to recover the original text from an encoded value. base64url uses the URL-safe alphabet (- and _ instead of + and /); url applies encodeURIComponent / decodeURIComponent. Decoding a value that is malformed for the chosen encoding is reported as a recoverable error, not a silent best-effort.
Output schemas are documented only in prose within descriptions, not as formal JSON Schema. For toolkit_check_system, toolkit_check_network, and toolkit_geolocate_ip, the exact field structure and types of return values are implicit rather than explicitly registered.
No per-tool permission annotations. Tools like toolkit_check_system and toolkit_check_network disclose system topology and version details (marked 'gated off by default'), but there is no formal scope declaration (e.g., 'requires:read:system') in the tool metadata to enable least-privilege agent configuration.
toolkit_geolocate_ip description states results are 'best-effort' and fields can be absent, but does not provide explicit guidance on how an agent should handle missing fields (e.g., 'If latitude/longitude is absent, the location is unreliable').
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | A | 88 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 50 | - | v1 |
Mint cryptographically-random identifiers using the platform CSPRNG — the correct source for IDs that must be unpredictable, unlike model-generated values. type selects the format: uuid_v4 (random, the default), uuid_v7 (time-ordered, sortable by creation), or ulid (26-char Crockford-base32, lexicographically sortable). Set count to mint a batch in one call (up to 1000); the returned ids array always contains exactly count values and is never truncated. For uuid_v7 and ulid, a batch is monotonic — strictly increasing even within the same millisecond — so the ids array stays in sorted creation order. IDs from this tool feed into toolkit_generate_qr (pass ids[0] as data) to create a scannable code.
Encode text or a URL into a QR code. data is the content to encode (a link, a generated identifier such as toolkit_generate_id's ids[0], or any string). format selects the output: svg returns inline SVG markup, png_base64 returns base64-encoded PNG bytes (with mimeType and byteLength), and terminal returns a block of Unicode block characters renderable in a monospace terminal. errorCorrection (L/M/Q/H) trades data capacity for damage tolerance, margin sets the quiet-zone width, and scale sets pixels per module for raster output. The returned version (1–40) reflects how dense the encoded data is. png_base64 renders (modules + 2 × margin) × scale pixels per side and rejects anything past 2048 px with a typed raster_too_large error, so a dense symbol needs a lower scale; svg carries no such limit.
Resolve a public IP address (or hostname) to geographic and network metadata: country, region, city, latitude/longitude, the owning ASN and organization, timezone, and the proxy/hosting/mobile quality flags. target accepts an IPv4/IPv6 address or a hostname — a hostname is DNS-resolved first and the resolvedIp field echoes which IP was actually located. The provider is called directly (never the target), so this is SSRF-free and safe to expose anywhere. Results are best-effort and provider-bounded: VPNs, proxies, mobile NAT, and anycast all defeat IP-to-location, accuracy is city-level at best, and many fields can be absent for reserved or thinly-documented ranges — absent fields are reported as unknown, never invented. Read proxy, hosting, and mobile before trusting the coordinates: a true on any of them means the location describes infrastructure, not the user. Private/reserved addresses have no public geolocation and are rejected. The source field names which provider answered.
Generate a cryptographic digest of a value, or verify a value against an expected digest. Set operation to "generate" for a lowercase-hex digest, or "compare" to constant-time-check value against the expected digest — compare is timing-safe and avoids manual string equality checks. Algorithm defaults to sha256; sha512 is also secure, while md5 and sha1 are exposed for checksum and file-integrity compatibility ONLY and must not be used for passwords, signatures, or any security purpose. inputEncoding controls how value and expected are read before hashing (utf8 default, or hex/base64 for raw binary data) so binary blobs need no decode round-trip. The canonical use is matching a download against a vendor-published checksum.
Error types and recovery paths are mentioned in prose but not formally categorized. For toolkit_generate_qr, 'data_too_large' and 'raster_too_large' are typed errors, but other tools lack explicit error classification to help agents decide whether to retry or escalate.