Skip to content

MCP servers › ai.saifs › demand-forecasting

MCP server · registry snapshot 2026-10-04 · last tested 2026-10-08

ai.saifs/demand-forecasting

Forecast product demand using historical sales and market signals. — the publisher's description

Topic: commerce-and-marketing · AI-classifiedversion 1.0.0streamable HTTP

Summary

ai.saifs/demand-forecasting is a remote MCP server listed in the official MCP registry at version 1.0.0. On 2026-10-08 it required sign-in before listing anything, so we could not read its inventory. We never use a credential its operator did not give us. 1 of the 18 checks that apply to it was exercised. Results of the checks are published only after we have verified them and told the publisher.

Needs the operator's credential

The server requires sign-in. We never use a credential its operator did not give us, so most checks could not run. No security score is given; a check we did not run is never counted as passed.

Key facts

Runs
remote (hosted by the publisher)
Transport
streamable HTTP
Sign-in
required
Topic
commerce-and-marketingAI-classified
Last tested
2026-10-08
The 18 checks at a glanceour test · 2026-10-08
  1. Inventory: not run · needs the operator's credential
  2. Hidden instructions: not run · needs the operator's credential
  3. Real execution: not run · needs the operator's credential
  4. Secret leak: not run · needs the operator's credential
  5. Internal addresses: not run · needs the operator's credential
  6. Unconfirmed changes: not run · needs the operator's credential
  7. Bad input: not run · needs the operator's credential
  8. Model requests: not run · needs the operator's credential
  9. Sensitive questions: not run · needs the operator's credential
  10. Folder boundary: not run · needs the operator's credential
  11. Log leaks: not run · needs the operator's credential
  12. Hidden content: not run · needs the operator's credential
  13. Fake assistant turns: not run · needs the operator's credential
  14. Token passthrough: not run · needs the operator's credential
  15. Token audience: not run · needs the operator's credential
  16. Sign-in redirect: not run · our policy
  17. Consent handling: not testable from outside
  18. Sign-in metadata: exercised

1 exercised17 not run (reason given)0 not applicable

How fresh this is

Live-tested
attempted, see below
Last tested
2026-10-08
Registry data
snapshot 2026-10-04
Package and repository
checked 2026-10-06
Engine
mcp-runtime-engine@0.1.0 · sdk@1.32.0

Security testing

What did we test, and what did we leave out?

18 checks · features #1, #2

Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). 1 of the 18 checks that apply to it was exercised. Results of the checks are published only after we have verified them and told the publisher.

Exercised · 1
  • 18Sign-in metadata
    oauth-url-scheme
    Checks the published sign-in metadata for unsafe URLs.exercised
Not run, with the reason · 17
  • 1Inventory
    tool-list
    Reads the declared tools, resources and prompts.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 2Hidden instructions
    description-poisoning
    Looks for hidden instructions in tool descriptions.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 3Real execution
    real-execution
    Calls a tool and checks what really happens.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 4Secret leak
    canary-leak
    Plants a fake secret and checks whether it leaks.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 5Internal addresses
    ssrf
    Checks whether a tool can be steered to internal addresses.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 6Unconfirmed changes
    write-without-confirmation
    Checks whether tools that change data act without asking.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 7Bad input
    error-handling
    Sends bad input and watches how the server answers.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 8Model requests
    sampling
    Checks whether the server asks the client's model to act for it.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 9Sensitive questions
    elicitation-sensitive-data
    Checks whether the server asks users for sensitive data.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 10Folder boundary
    root-boundary
    Checks whether the server reaches outside the folders it was given.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 11Log leaks
    logging-side-channel
    Checks whether log messages carry data they should not.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 12Hidden content
    audience-hiding
    Checks resources that hide content from the user.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 13Fake assistant turns
    fake-assistant-turn
    Checks prompts that pose as the assistant's own words.The server requires sign-in, and we never use a credential its operator did not give us.not run · needs the operator's credential
  • 14Token passthrough
    token-passthrough
    Checks whether the server forwards a user's token to other services.Needs a real token issued by the server's own sign-in service, which only its operator can give us.not run · needs the operator's credential
  • 15Token audience
    token-audience-validation
    Checks whether tokens meant for another service are accepted.Needs a real token issued by the server's own sign-in service, which only its operator can give us.not run · needs the operator's credential
  • 16Sign-in redirect
    open-redirect
    Checks the sign-in redirect for abuse.Testing the sign-in redirect means sending probes to the operator's sign-in service, which we do not do without their authorization.not run · our policy
  • 17Consent handling
    confused-deputy
    Checks consent handling when one service acts for another.Depends on the operator's own consent screen, which differs per server and cannot be tested from outside.not testable from outside

Source: our own test, 2026-10-08, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model.

What happened during the test?

Feature #8

The steps in order, as the test record holds them.

  1. 0 msStarted a session with the server's remote endpoint
  2. The server asked for sign-in before listing anything.
  3. 2,780 msFinished: 1 check exercised.

What it is

Does the registry listing match what we found?

Feature #6

The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.

Registry saysWe foundResultSource · date
Remote endpoint demand-forecaster-mcp.saifs.ai/mcpEndpoint answered and asked for sign-inmatchesour test · 2026-10-08
No credential declared as requiredRequired sign-indiffersour test · 2026-10-08

Choosing

Common questions about ai.saifs/demand-forecasting

Answered from the data above

Does ai.saifs/demand-forecasting need an API key or sign-in?

It required sign-in on 2026-10-08. The registry entry declares no required credential; no declaration is not a guarantee.

Has ai.saifs/demand-forecasting been security tested?

Partly. 1 of the 18 checks that apply to it was exercised. The server requires sign-in. We never use a credential its operator did not give us, so most checks could not run. No security verdict is published before verification.

Reference

How is it classified?

18 fields

One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.

TopicAI-classified
commerce-and-marketing
AI-classified · 2026-10-08
Pricing modelAI-classified
no value
No value: the AI answer was held back because the quoted text did not clearly support it.
Programming language
does not apply
no existing GitHub repository (server declares no repository link, so there is nothing to fetch)
Hosting type
remote (hosted by the publisher)
registry · 2026-10-04
MCP capability
not checked
not read (no session)
Transport
streamable HTTP
registry · 2026-10-04
Required credentials
none declared
registry · no declaration is not a guarantee
Package registry
does not apply
remote-only server: no package is shipped, so there is no package registry
Freshness
31–90 days
registry updatedAt · 2026-10-04
Lifecycle status
active
registry · 2026-10-04
License class
does not apply
remote-only server: ships no package, so there is nothing to look up in a package registry
Integrity hash
does not apply
remote-only server: ships no package, so there is nothing to look up in a package registry
Signature / provenance
does not apply
remote-only server: ships no package, so there is nothing to look up in a package registry
Dependency advisories
does not apply
ships no package, so there are no dependencies to audit
Popularity
does not apply
remote-only server: ships no package, so there is nothing to look up in a package registry
Publisher signals
not stated
no readable GitHub owner to describe
Maintenance
does not apply
server declares no repository link, so there is nothing to fetch
Environment
the publisher's infrastructure
where it runs, from the hosting type

“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.

Cite or correct this page

Sources and corrections

Suggested citation

ProtocolProbe. “ai.saifs/demand-forecasting: MCP server record.” Data checked 2026-10-08. https://protocolprobe.com/mcp/servers/ai.saifs/demand-forecasting

Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.

As JSON: this record in the API · API documentation.

Something wrong, or is this yours?

If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.

Write to hello@protocolprobe.com · corrections log · methodology