What AI automations declare they can access
ComputerMultiverse is a public record of the access that downloadable AI automations declare in their own documentation. Each entry quotes the publisher’s own file, names that file, and carries the date we read it.
An agent skill, an MCP server or an automation workflow installs in about a minute. From that moment it may be holding a token to your mailbox, a path into your documents, or permission to run commands on the machine it sits on. Most of that is written down somewhere. It sits in a manifest, a README, a permissions block or a sample configuration, in files almost nobody opens before clicking install. We open them, and we write down what they say.
That is the whole of it. We record declarations. We do not test software, we do not run anyone’s code, and we publish no opinion on whether a package is worth installing. If a record shows that a package declares it needs a credential and reaches the network, that is a fact about the package’s own documentation. What it means for you is your call, and it depends on what you were going to point it at.
Each figure is counted from the register itself. The records behind them are each carrying the date its own source was read, between 4 August 2026 and 11 August 2026.
Browse the register How a record is compiled
Free everywhere, and here is who pays for it
Independence
Every page on this site is free. There is no registration, no paywall, no premium tier and no member area, and there is no plan to add one. The site is paid for by advertising, and by affiliate commissions on infrastructure and learning products, meaning hosting, servers, security tooling and courses.
No publisher of anything in this register can pay us anything, for any reason. Not for an entry, not for a change to an entry, not for removal, not for position in a list, and not for advertising. There is no rate card, because there is nothing to sell them.
What is in the register
Two families of software, because those are the two that install with the widest reach and the least ceremony.
| Section | What it holds |
|---|---|
| Agent skills | Packaged instructions and tooling loaded into an AI assistant, usually with access to a working directory and whatever the assistant is already signed in to. |
| MCP servers | Long-running connectors that expose a service, a database or a local filesystem to a model over the Model Context Protocol. Most of the register is here. |
| Everything | The full register, in one list, with the declared access shown against each name. |
How to read an entry
Each entry carries a short set of chips. A chip states one capability the software declares about itself, in the publisher’s own terms. means the documentation says it reads or writes local paths. means it asks for a token, a key or an account login. means it says it runs commands or processes.
A chip is a quotation. It is not a score, a rating, a ranking or a recommendation, and nothing on this site orders one package above another. Where the documentation says nothing about a capability, the entry says the documentation is silent, which is a different statement from saying the capability is absent.
Work out what a config grants, before you paste it
Most of the time the thing you are about to install is not in the register yet, because the register is new and the ecosystem is large. So there is a tool for the general case.
The permission reader takes a server configuration block or a manifest, pasted straight in, and describes in plain sentences what that block grants: which directories it reaches, which credentials it wants, what it can run. It works entirely inside your browser. Nothing you paste is sent anywhere, stored or logged, and there is no server behind it.
Alongside it there is a set of written guides on the same subject. Three worth starting with:
- What an MCP server can reach on your computer
- How to read an MCP server config before you paste it
- OAuth scopes in plain English
What a record does not tell you
A record is a reading of a document. It is not an examination of software, and it cannot be one, because we never run the code. A package can declare less than it does. A package can declare more than it does. A published manifest can be out of date, or wrong, or written by someone who did not check. Version 2.0.1 can behave nothing like the version we read.
So a record answers one question only: what did this publisher put in writing, and when. Anything beyond that is not ours to say. The whole method, including how a source is chosen and what happens when it is challenged, is set out on the sourcing page.
If you publish something we have recorded
You do not need a lawyer to get an entry changed. Show us the document, tell us which line is wrong, and if you are right we fix it and log the fix in public. That route is on the corrections page, along with the right of reply, which is a block of your own words on your own entry, printed unedited.
Published by A.I.T. Multiverse Consulting Ltd, Nicosia, Cyprus. This page states the position as at 4 August 2026.