BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier

Tools We Don't Recommend

We review hundreds of Claude AI tools; most make the catalog, some don't. This page is a curated (not exhaustive) list of exclusions worth knowing about, each with the specific reason — not just "niche" or "incomplete." Every verdict below is deep-linkable (hover a name for its #anchor).

Page last updated: 2026-08-17 · Security holds: 29 · Rejections: 2 · Scored below standard: 141

Security Holds

These tools were flagged during review for security concerns that make them unsuitable for recommendation.

Anthropic-Mythos-Desktop-StudioSecurity Hold Source
Security concerns identified during review. Exercise caution.
Claude-Code-Agent-Design-KitSecurity Hold Source
Security concerns identified during review. Exercise caution.
Claude-Zeroclaw-NexusSecurity Hold Source
Security concerns identified during review. Exercise caution.
FreeRideSecurity Hold Source
Rotates between free-tier accounts on multiple AI providers to dodge rate limits that those providers set intentionally. That is a direct violation of the Terms of Service for OpenAI, Anthropic, Google, and every other mainstream API — grounds for account termination, IP bans, and, for commercial use, potential breach-of-contract exposure. Beyond the legal posture, the tool's whole value proposition depends on staying one step ahead of provider enforcement, which means it will break unpredictably and invite anti-abuse scrutiny on any account touching it. If you need more throughput, pay for it; if you are building for clients, this is a liability you do not want in the stack.
Get Shit Done (GSD)Security Hold Source
Security concerns identified during review. Exercise caution.
Mythos-Claude-OrchestratorSecurity Hold Source
Security concerns identified during review. Exercise caution.
NanoBanana-PPT-SkillsSecurity Hold Source
Security concerns identified during review. Exercise caution.
agent-toolSecurity Hold Source
Bundles SSH and SFTP clients, live process memory inspection, binary analysis, and debugger (DAP) control into a single MCP server with no sandboxing or capability scoping. A successful prompt injection — or a confused model following a malicious README — could pivot into production servers using your keys, read credentials out of a running process's memory, or attach a debugger to a sensitive binary. Each of these capabilities alone warrants careful review; stacking them behind one LLM-driven interface turns the tool into a general-purpose post-exploitation toolkit. Use individual, purpose-built tools with narrower scopes instead.
awesome-claude-fable-5-prompt-vaultSecurity Hold Source
Security concerns identified during review. Exercise caution.
blender-mcpSecurity Hold Source
Security concerns identified during review. Exercise caution.
claude-autonomous-deploymentSecurity Hold Source
Security concerns identified during review. Exercise caution.
claude-cli-mcp-bridgeSecurity Hold Source
Security concerns identified during review. Exercise caution.
claude-design-studio-toolkitSecurity Hold Source
Security concerns identified during review. Exercise caution.
claude-opus-dev-workbenchSecurity Hold Source
Security concerns identified during review. Exercise caution.
claude-opus-interface-toolkitSecurity Hold Source
Security concerns identified during review. Exercise caution.
claude-session-flowSecurity Hold Source
Security concerns identified during review. Exercise caution.
everything-claude-codeSecurity Hold Source
Security concerns identified during review. Exercise caution.
exo-harness-ai-pipelineSecurity Hold Source
Security concerns identified during review. Exercise caution.
fable-opus-desktop-kitSecurity Hold Source
Security concerns identified during review. Exercise caution.
gryffin-calorai-ventusSecurity Hold Source
Security concerns identified during review. Exercise caution.
hewn-forgeSecurity Hold Source
Security concerns identified during review. Exercise caution.
local-ai-code-assistantSecurity Hold Source
Security concerns identified during review. Exercise caution.
mcp-edd-analytics-vantageSecurity Hold Source
Security concerns identified during review. Exercise caution.
multi-agent-architecture-advisorSecurity Hold Source
Security concerns identified during review. Exercise caution.
plan-execute-verify-claude-codeSecurity Hold Source
Security concerns identified during review. Exercise caution.
real-browser-mcpSecurity Hold Source
Connects Claude to your actual Chrome profile — the one logged into your bank, email, CRM, and admin panels. Prompt injection from any page the model reads (an email, a search result, a scraped article) can trigger real actions inside those sessions: sending messages, approving transactions, changing settings, exfiltrating data. There is no sandbox, no per-site scoping, and no meaningful confirmation layer. The blast radius is everything your browser is currently signed into. For a consultant or operator, that is almost never an acceptable trade against the convenience it offers.
secbotSecurity Hold Source
Security concerns identified during review. Exercise caution.
strategic-advisor-orchestratorSecurity Hold Source
Security concerns identified during review. Exercise caution.
t2000Security Hold Source
Exposes on-chain lending, borrowing, swapping, and investing on the Sui blockchain as tools an AI agent can call directly. Blockchain transactions are irreversible — a hallucinated amount, a wrong token address, or a prompt-injected instruction moves real money that no support desk can claw back. Non-custodial framing does not change this; it just means you personally absorb the loss. DeFi protocols themselves also carry smart-contract and oracle risk that most LLMs cannot reason about. Financial actions need human-in-the-loop confirmation and hard spending caps, neither of which this tool enforces.

Not Recommended

These tools were reviewed and rejected for specific reasons beyond just being niche or incomplete.

Linkedin Mcp ServerNot Recommended Source
Scrapes LinkedIn profiles, companies, and jobs via AI
Automates scraping of LinkedIn profiles, companies, and job listings through an AI agent. LinkedIn's User Agreement explicitly prohibits automated data collection, and LinkedIn has successfully pursued scrapers through account termination, cease-and-desist letters, and federal litigation (hiQ Labs, 3taps, and others). Detection is aggressive — behavioral fingerprinting, rate analysis, and device signals routinely flag scraping activity within days. For a consultant, the downside is not hypothetical: a suspended LinkedIn account is a business continuity problem, and using scraped data in client deliverables can create GDPR and CCPA exposure. Use the official LinkedIn API or a sanctioned data partner.
Mcp MindmeshNot Recommended Source
Quantum-inspired swarm orchestrating multiple Claude instances
Markets itself with terms like 'quantum field coherence,' 'ensemble intelligence,' and 'neural swarm' that imply capabilities the code does not deliver — under the hood it is a straightforward multi-model fan-out with a voting step. Overstated claims on an MCP server are a reliability signal in themselves: if the README misrepresents what the tool does, you should assume the same looseness applies to error handling, data handling, and security posture. You also inherit whatever credentials get wired into each underlying provider, multiplied across instances. Real multi-agent orchestration is possible, but it needs honest documentation before it earns a place in a client stack.

Scored Below Standard

These tools were catalogued and evaluated, but their latest evaluation scored a grade of D or F — they fell below the catalog's usable tier on the evidence (trust signals, maintenance, community pulse). This is an evidence-based rating, not a security flag. The stated reason for each comes from its evaluation rationale where one was recorded.

145 GitHub stars; contributors unknown; last commit 9d ago; license AGPL-3.0.
236 GitHub stars; contributors unknown; last commit 4d ago; license SEE LICENSE IN README.md.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license MIT.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license FSL-1.1-Apache-2.0.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 6 GitHub stars; 2 contributors; last commit 263d ago; license no license.
27 GitHub stars; contributors unknown; last commit 0d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 79 GitHub stars; 1 contributors; last commit 124d ago; license no license.
CTXGraded D Source
141 GitHub stars; 2 contributors; last commit 75d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 36 GitHub stars; 1 contributors; last commit 178d ago; license no license.
audit 2026-07-05 stale-eval refresh: Scored from trust signals (evidence-eval-v1): 69 GitHub stars; 1 contributors; last commit 0d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 216 GitHub stars; 1 contributors; last commit 72d ago; license no license.
audit 2026-07-05 stale-eval refresh: Scored from trust signals (evidence-eval-v1): 87 GitHub stars; 1 contributors; last commit 9d ago; license no license.
144 GitHub stars; contributors unknown; last commit 0d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 21 GitHub stars; 3 contributors; last commit 10d ago; license no license.
108 GitHub stars; 1 contributors; last commit 76d ago; license no license.
audit 2026-07-05 stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license MIT.
JoaniumGraded D Source
187 GitHub stars; contributors unknown; last commit 0d ago; license no license.
KageGraded D Source
30 GitHub stars; 2 contributors; last commit 0d ago; license GPL-3.0.
KilnGraded D Source
40 GitHub stars; 5 contributors; last commit 0d ago; license AGPL-3.0.
39 GitHub stars; 1 contributors; last commit 406d ago; license MIT.
128 GitHub stars; 1 contributors; last commit 3d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 162 GitHub stars; 2 contributors; last commit 97d ago; license no license.
138 GitHub stars; 2 contributors; last commit 4d ago; license no license.
224 GitHub stars; 2 contributors; last commit 0d ago; license no license.
200 GitHub stars; contributors unknown; last commit 0d ago; license no license.
audit 2026-07-05 stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license MIT.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
RepomixGraded F Source
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license MIT.
audit 2026-07-05 stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license MIT.
152 GitHub stars; contributors unknown; last commit 0d ago; license no license.
audit 2026-07-05 stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license MIT.
WRAI.THGraded D Source
26 GitHub stars; 5 contributors; last commit 4d ago; license AGPL-3.0.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
126 GitHub stars; contributors unknown; last commit 0d ago; license no license.
53 GitHub stars; 2 contributors; last commit 2d ago; license AGPL-3.0.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 70 GitHub stars; 1 contributors; last commit 15d ago; license CC-BY-4.0.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 39 GitHub stars; 2 contributors; last commit 18d ago; license no license.
32 GitHub stars; contributors unknown; last commit 4d ago; license no license.
27 GitHub stars; contributors unknown; last commit 0d ago; license no license.
29 GitHub stars; 5 contributors; last commit 0d ago; license GPL-3.0.
242 GitHub stars; contributors unknown; last commit 1d ago; license no license.
28 GitHub stars; 1 contributors; last commit 3d ago; license GPL-3.0.
atlasGraded D Source
54 GitHub stars; contributors unknown; last commit 0d ago; license no license.
atrisGraded D Source
67 GitHub stars; contributors unknown; last commit 0d ago; license no license.
29 GitHub stars; 3 contributors; last commit 0d ago; license no license.
26 GitHub stars; contributors unknown; last commit 0d ago; license no license.
49 GitHub stars; 2 contributors; last commit 0d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
33 GitHub stars; 3 contributors; last commit 2d ago; license AGPL-3.0.
56 GitHub stars; 1 contributors; last commit 16d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 17 GitHub stars; 2 contributors; last commit 0d ago; license no license.
70 GitHub stars; 2 contributors; last commit 102d ago; license no license.
cezarGraded D Source
36 GitHub stars; contributors unknown; last commit 0d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 28 GitHub stars; 1 contributors; last commit 1d ago; license no license.
50 GitHub stars; contributors unknown; last commit 0d ago; license no license.
38 GitHub stars; contributors unknown; last commit 0d ago; license no license.
191 GitHub stars; contributors unknown; last commit 0d ago; license no license.
cligateGraded D Source
89 GitHub stars; contributors unknown; last commit 0d ago; license AGPL-3.0.
181 GitHub stars; contributors unknown; last commit 0d ago; license AGPL-3.0.
44 GitHub stars; 1 contributors; last commit 12d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 15 GitHub stars; 3 contributors; last commit 5d ago; license GPL-2.0.
113 GitHub stars; contributors unknown; last commit 0d ago; license GPL-3.0.
25 GitHub stars; contributors unknown; last commit 0d ago; license no license.
47 GitHub stars; 5 contributors; last commit 18d ago; license no license.
221 GitHub stars; contributors unknown; last commit 0d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
cuxGraded D Source
68 GitHub stars; contributors unknown; last commit 0d ago; license GPL-3.0.
68 GitHub stars; 2 contributors; last commit 12d ago; license no license.
56 GitHub stars; contributors unknown; last commit 0d ago; license no license.
55 GitHub stars; contributors unknown; last commit 0d ago; license no license.
151 GitHub stars; contributors unknown; last commit 0d ago; license no license.
46 GitHub stars; contributors unknown; last commit 0d ago; license no license.
135 GitHub stars; contributors unknown; last commit 0d ago; license AGPL-3.0.
36 GitHub stars; 2 contributors; last commit 29d ago; license no license.
36 GitHub stars; 4 contributors; last commit 1d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license MIT.
handoffGraded D Source
60 GitHub stars; contributors unknown; last commit 0d ago; license no license.
hotclipGraded D Source
38 GitHub stars; 1 contributors; last commit 1d ago; license AGPL-3.0.
38 GitHub stars; contributors unknown; last commit 1d ago; license no license.
99 GitHub stars; contributors unknown; last commit 0d ago; license GPL-3.0.
41 GitHub stars; contributors unknown; last commit 0d ago; license no license.
kansokuGraded D Source
268 GitHub stars; contributors unknown; last commit 0d ago; license no license.
kasettoGraded D Source
105 GitHub stars; contributors unknown; last commit 0d ago; license no license.
kimbapGraded D Source
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 16 GitHub stars; 3 contributors; last commit 83d ago; license no license.
47 GitHub stars; 1 contributors; last commit 94d ago; license no license.
32 GitHub stars; 4 contributors; last commit 0d ago; license no license.
36 GitHub stars; contributors unknown; last commit 0d ago; license no license.
52 GitHub stars; contributors unknown; last commit 0d ago; license no license.
mcp-1cGraded D Source
125 GitHub stars; contributors unknown; last commit 0d ago; license no license.
mcpmateGraded D Source
33 GitHub stars; 2 contributors; last commit 0d ago; license AGPL-3.0.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 184 GitHub stars; 1 contributors; last commit 5d ago; license no license.
mxLoreGraded D Source
29 GitHub stars; 1 contributors; last commit 10d ago; license no license.
168 GitHub stars; 3 contributors; last commit 257d ago; license AGPL-3.0.
39 GitHub stars; 1 contributors; last commit 75d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 33 GitHub stars; 2 contributors; last commit 16d ago; license AGPL-3.0.
34 GitHub stars; 1 contributors; last commit 0d ago; license no license.
109 GitHub stars; contributors unknown; last commit 0d ago; license no license.
49 GitHub stars; 5 contributors; last commit 39d ago; license no license.
45 GitHub stars; 2 contributors; last commit 4d ago; license no license.
58 GitHub stars; contributors unknown; last commit 0d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 33 GitHub stars; 2 contributors; last commit 0d ago; license no license.
piyazGraded D Source
118 GitHub stars; contributors unknown; last commit 1d ago; license AGPL-3.0.
32 GitHub stars; 10 contributors; last commit 3d ago; license no license.
137 GitHub stars; contributors unknown; last commit 0d ago; license no license.
28 GitHub stars; 1 contributors; last commit 74d ago; license no license.
reticleGraded D Source
297 GitHub stars; contributors unknown; last commit 0d ago; license no license.
36 GitHub stars; contributors unknown; last commit 0d ago; license no license.
30 GitHub stars; 4 contributors; last commit 0d ago; license no license.
212 GitHub stars; contributors unknown; last commit 2d ago; license no license.
107 GitHub stars; contributors unknown; last commit 1d ago; license no license.
28 GitHub stars; 1 contributors; last commit 0d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 5 GitHub stars; 5 contributors; last commit 1d ago; license EUPL-1.2.
74 GitHub stars; contributors unknown; last commit 0d ago; license Elastic-2.0.
100 GitHub stars; contributors unknown; last commit 1d ago; license AGPL-3.0.
176 GitHub stars; contributors unknown; last commit 0d ago; license AGPL-3.0.
32 GitHub stars; 4 contributors; last commit 20d ago; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 0 GitHub stars; contributors unknown; commit recency unknown; license no license.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 24 GitHub stars; 1 contributors; last commit 88d ago; license AGPL-3.0.
sv-gridGraded D Source
205 GitHub stars; 2 contributors; last commit 0d ago; license no license.
198 GitHub stars; contributors unknown; last commit 7d ago; license AGPL-3.0.
tacitGraded D Source
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 9 GitHub stars; 2 contributors; last commit 5d ago; license no license.
trvlGraded D Source
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 45 GitHub stars; 1 contributors; last commit 6d ago; license no license.
82 GitHub stars; contributors unknown; last commit 2d ago; license GPL-2.0.
ue-mcpGraded D Source
123 GitHub stars; contributors unknown; last commit 1d ago; license no license.
89 GitHub stars; contributors unknown; last commit 7d ago; license no license.
38 GitHub stars; 3 contributors; last commit 16d ago; license no license.
123 GitHub stars; contributors unknown; last commit 0d ago; license no license.
75 GitHub stars; contributors unknown; last commit 2d ago; license GPL-3.0.
32 GitHub stars; 1 contributors; last commit 4d ago; license GPL-3.0.
26 GitHub stars; contributors unknown; last commit 0d ago; license GPL-2.0.
31 GitHub stars; contributors unknown; last commit 2d ago; license no license.
154 GitHub stars; contributors unknown; last commit 5d ago; license AGPL-3.0.
yumeGraded D Source
146 GitHub stars; contributors unknown; last commit 0d ago; license no license.
25 GitHub stars; 1 contributors; last commit 1d ago; license no license.
35 GitHub stars; contributors unknown; last commit 22d ago; license no license.

Tool authors: If you believe your tool was excluded in error or have addressed the concerns listed here, reach out on LinkedIn. We re-evaluate tools when significant changes are made.

Frequently Asked Questions

Why are these Claude tools not recommended?

Each tool on this page was excluded for a specific reason disclosed alongside it — typically a security posture that creates unacceptable blast radius, a terms-of-service violation, overstated marketing relative to what the code delivers, or a design that puts user data or funds at risk. The reasoning for each tool is written out so you can judge for yourself whether it matches your situation.

Does "not recommended" mean these tools are unsafe?

Not always. "Not recommended" means we would not deploy it ourselves or suggest it to a client in our typical consulting context. Some tools carry genuine security concerns; others are simply overstated or carry legal risk like terms-of-service violations. Read the specific reasoning for each tool — context matters.

What is the difference between a security hold and a tool scored below standard?

A security hold is a tool flagged for a specific security concern — for example, an unacceptable blast radius if prompt-injected, or a design that puts credentials or funds at risk. A tool scored below standard was catalogued and evaluated normally, but its latest evaluation graded D or F on the evidence (trust signals, maintenance, community pulse). The first is a risk flag; the second is an evidence-based quality rating. Each tool's section on this page makes clear which kind it is.

How do you decide which Claude tools not to recommend?

We look at blast radius if the tool is prompt-injected, scope of credentials or capabilities it bundles, maintainer identity and responsiveness, license posture, documentation accuracy, and whether the value proposition justifies the risk. Our evaluation framework is published at /evaluate-tools.

Can a tool be re-evaluated if it changes?

Yes. If a maintainer addresses the specific concerns listed on this page, reach out and we will re-evaluate. Tools on this page are not blacklisted forever — they reflect the state of the tool at review time.

Where the rest of the catalog lives: the ranked catalog holds the tools we recommend; Also Catalogued holds usable-but-unranked tools; and The Evaluation File holds everything reviewed but not yet ranked. This page is the fourth tier: reviewed and actively advised against.
Full Catalog · The Evaluation File · Getting Started · Trending · Deployment Playbook · Evaluation Guide · How We Review

Rolling Claude out in your org? Let's talk.

Start a conversation →