Recherche et location d'outils entre particuliers en France via Toolzy.
This MCP tool is listed in an official registry, has been updated within the last year, and does not require extra credentials; however, its source code, license, and detailed README are absent, making implementation and data handling non-auditable. Overall, there are no clear high-risk red flags, but it should be treated with caution because it has network access to its service endpoint and can execute code.
The material explicitly states that no keys or environment variables are required, and there is no indication of API keys, OAuth tokens, or local sensitive credentials being requested; this keeps credential exposure relatively low. Users should still avoid manually entering passwords or other secrets during tool interactions.
The tool connects to the remote endpoint mcp.toolzy.io, and user requests or tool parameters may be sent to that service for processing. The endpoint appears related to the stated function, but the documentation does not specify what data is transmitted, retained, or protected, so data egress should be treated with caution.
The system checks indicate an executes-code capability, meaning it may trigger local process or code execution within the MCP runtime environment. This is a normal tool capability, but the current material does not disclose the exact system powers or boundaries, so it should be used in a constrained environment.
The material does not specify which local files, directories, or other resources it can read or write, leaving its data-access scope unclear. There is no explicit sign of excessive permissions unrelated to its purpose, but sensitive workspaces and personal data should not be granted by default when access boundaries are undocumented.
Positive signals include its presence in an official registry and updates within the last year; however, there is no open-source repository, no declared license, no README, and very low public community adoption, which makes the implementation and dependency chain hard to audit. The source credibility is not strong enough for a low-risk rating, but there are also no clear red flags that would justify a high-risk rating.
Copy the install command and let the AI configure it · recommended for beginners
Please install the "io.toolzy/toolzy" MCP server from askskill: Run: claude mcp add --transport http 'io-toolzy-toolzy' 'https://mcp.toolzy.io/api/mcp'