Toucan — security grade SAFE, quality 56/100

Security audit verdict: SAFE · quality 56/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by TheAgentArk · MCP Server · ★ 263

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is Toucan safe to install? View the security audit →

About Toucan

🦤 Toucan-1.5M: Toucan-1.5M is the largest fully synthetic tool-agent dataset to date, designed to advance tool use in agentic LLMs. It comprises over 1.5 million trajectories synthesized from 495 real-world Model Context Protocols (MCPs) spanning 2,000+ tools. By leveraging authentic MCP environments, Toucan-1.5M generates diverse, realistic, and challenging tasks requires using multiple tools, with trajectories involving real tool executions across multi-round, multi-turn, sequential, and parallel tool calls. Models fine-tuned on Toucan-1.5M outperform much larger closed-source counterparts on the BFCL V3 benchmark and extend the Pareto frontier on the MCP-Universe benchmark. 📄 Technical Report - Technical details behind Toucan-1.5M 💾 Github Repo - Pipeline to produce Toucan-1.5M 🤗 HF Dataset - Full dataset 🚚 Installation 📝 Data Synthesis Please refer to folder for details. 📚 Citation If you find the data or code useful, please cite: @misc{xu2025toucan, title={TOUCAN: Synthesizing 1.5M Tool-Agentic Dat

Quick Facts

Stars263
Forks17
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score56.2764274576087/100
Open Issues4
Last Updated2025-12-16
Created2025-09-30
Platformsmcp, python
Est. Tokens~1625k

Compatible Skills

These tools work well together with Toucan for enhanced workflows:

  • mint-bench — semantic(0.31)+complementary+same_lang+similar_pop+shared_platform (56%)
  • LLM-MM-Agent — semantic(0.30)+complementary+same_lang+similar_pop+shared_platform (56%)
  • AutoTools — semantic(0.26)+complementary+same_lang+similar_pop+shared_platform (54%)
  • code-act — semantic(0.25)+complementary+same_lang+similar_pop+shared_platform (54%)
  • empower-functions — semantic(0.20)+complementary+same_lang+similar_pop+shared_platform (52%)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is Toucan?

Toucan is Official repo of Toucan: Synthesizing 1.5M Tool-Agentic Data from Real-World MCP Environments. It is categorized as a MCP Server with 263 GitHub stars.

What programming language is Toucan written in?

Toucan is primarily written in Python.

How do I install or use Toucan?

You can find installation instructions and usage details in the Toucan GitHub repository at github.com/TheAgentArk/Toucan. The project has 263 stars and 17 forks, indicating an active community.

What license does Toucan use?

Toucan is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools