Skip to content

MCP servers › com.allstacks › allstacks-mcp

MCP server · registry snapshot 2026-10-04 · last tested 2026-10-09

com.allstacks/allstacks-mcp

Provides 208+ tools for AI-native engineering intelligence via Allstacks API. — the publisher's description

Topic: developer-tools · AI-classifiedversion 0.1.3standard input/output

Summary

com.allstacks/allstacks-mcp is a local MCP server listed in the official MCP registry at version 0.1.3. On 2026-10-09 its published package did not start, so no check could run. None of the 18 checks that apply to it could be exercised. Results of the checks are published only after we have verified them and told the publisher.

Package does not start

The published package does not install or start cleanly today, so no check could run. No security score is given; a check we did not run is never counted as passed.

Key facts

Runs
local package
Transport
standard input/output
Package
PyPI · listed version behind the latest release
Topic
developer-toolsAI-classified
Last tested
2026-10-09
The 18 checks at a glanceour test · 2026-10-09
  1. Inventory: not run · package does not start
  2. Hidden instructions: not run · package does not start
  3. Real execution: not run · package does not start
  4. Secret leak: not run · package does not start
  5. Internal addresses: not run · package does not start
  6. Unconfirmed changes: not run · package does not start
  7. Bad input: not run · package does not start
  8. Model requests: not run · package does not start
  9. Sensitive questions: not run · package does not start
  10. Folder boundary: not run · package does not start
  11. Log leaks: not run · package does not start
  12. Hidden content: not run · package does not start
  13. Fake assistant turns: not run · package does not start
  14. Token passthrough: not run · package does not start
  15. Token audience: not run · package does not start
  16. Sign-in redirect: not run · package does not start
  17. Consent handling: not run · package does not start
  18. Sign-in metadata: not run · package does not start

0 exercised18 not run (reason given)0 not applicable

Worth knowing before you connect it

  • The registry lists 0.1.3; 0.1.6 is newer (3 releases).

Each line comes from a section below, with its source and date.

How fresh this is

Live-tested
attempted, see below
Last tested
2026-10-09
Registry data
snapshot 2026-10-04
Package and repository
checked 2026-10-06
Engine
mcp-runtime-engine@0.1.0 · sdk@1.32.0

Security testing

What did we test, and what did we leave out?

18 checks · features #1, #2

Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). None of the 18 checks that apply to it could be exercised. Results of the checks are published only after we have verified them and told the publisher.

Not run, with the reason · 18
  • 1Inventory
    tool-list
    Reads the declared tools, resources and prompts.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 2Hidden instructions
    description-poisoning
    Looks for hidden instructions in tool descriptions.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 3Real execution
    real-execution
    Calls a tool and checks what really happens.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 4Secret leak
    canary-leak
    Plants a fake secret and checks whether it leaks.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 5Internal addresses
    ssrf
    Checks whether a tool can be steered to internal addresses.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 6Unconfirmed changes
    write-without-confirmation
    Checks whether tools that change data act without asking.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 7Bad input
    error-handling
    Sends bad input and watches how the server answers.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 8Model requests
    sampling
    Checks whether the server asks the client's model to act for it.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 9Sensitive questions
    elicitation-sensitive-data
    Checks whether the server asks users for sensitive data.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 10Folder boundary
    root-boundary
    Checks whether the server reaches outside the folders it was given.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 11Log leaks
    logging-side-channel
    Checks whether log messages carry data they should not.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 12Hidden content
    audience-hiding
    Checks resources that hide content from the user.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 13Fake assistant turns
    fake-assistant-turn
    Checks prompts that pose as the assistant's own words.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 14Token passthrough
    token-passthrough
    Checks whether the server forwards a user's token to other services.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 15Token audience
    token-audience-validation
    Checks whether tokens meant for another service are accepted.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 16Sign-in redirect
    open-redirect
    Checks the sign-in redirect for abuse.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 17Consent handling
    confused-deputy
    Checks consent handling when one service acts for another.The package does not install or start cleanly today, so no check could run.not run · package does not start
  • 18Sign-in metadata
    oauth-url-scheme
    Checks the published sign-in metadata for unsafe URLs.The package does not install or start cleanly today, so no check could run.not run · package does not start

Source: our own test in an isolated sandbox, 2026-10-09, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model.

What happened during the test?

Feature #8

The steps in order, as the test record holds them.

  1. 0 msStarted the published package in an isolated sandbox
  2. The package did not start.
  3. 2,156 msFinished: 0 checks exercised.

What it is

Does the registry listing match what we found?

Feature #6

The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.

Registry saysWe foundResultSource · date
Published package can be startedDid not startdiffersour test · 2026-10-09
Version 0.1.3 on PyPIExists and can be installedmatchesPyPI · 2026-10-06

Can it be installed, and is it up to date?

Version pin · advisories

Listed version

Registry lists
0.1.3
Latest stable
0.1.6
Status
behind the latest release (3 releases, 226 days)
Withdrawn
no

Source: pypi.org · 2026-10-06. About the version the registry lists; a manual install may resolve to a different one.

Integrity, provenance, license

Integrity
sha256-02871deebf9d77a73…

Source: the package registry · 2026-10-06.

Usage

Downloads
312 in the last month

Source: pypistats.org · 2026-10-06.

Choosing

Common questions about com.allstacks/allstacks-mcp

Answered from the data above

Has com.allstacks/allstacks-mcp been security tested?

We tried, but no check could run. None of the 18 checks that apply to it could be exercised. The published package does not install or start cleanly today, so no check could run. No security verdict is published before verification.

Is the listed version current?

No. The registry lists 0.1.3; the latest stable release on PyPI is 0.1.6.

Reference

How is it classified?

18 fields

One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.

TopicAI-classified
developer-tools
AI-classified · 2026-10-08
Pricing modelAI-classified
not checked
no website in the registry entry
Programming language
does not apply
no existing GitHub repository (server declares a `repository` block but it is empty)
Hosting type
local package
registry · 2026-10-04
MCP capability
not checked
not read (no session)
Transport
standard input/output
registry · 2026-10-04
Required credentials
none declared
registry · no declaration is not a guarantee
Package registry
pypi
registry · 2026-10-04
Freshness
181–365 days
registry updatedAt · 2026-10-04
Lifecycle status
active
registry · 2026-10-04
License class
not stated
no license field and no license classifier
Integrity hash
declared (sha256)
package registry · 2026-10-06
Signature / provenance
does not apply
PyPI publishes no registry signature or attestation equivalent to npm dist.signatures
Dependency advisories
not known (our limit)
not resolvable for our pinned target Python 3.12 - our limitation
Popularity
312 downloads a month
package registry · 2026-10-06
Publisher signals
not stated
no readable GitHub owner to describe
Maintenance
not stated
no readable repository
Environment
your machine
where it runs, from the hosting type

“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.

Cite or correct this page

Sources and corrections

Suggested citation

ProtocolProbe. “com.allstacks/allstacks-mcp: MCP server record.” Data checked 2026-10-09. https://protocolprobe.com/mcp/servers/com.allstacks/allstacks-mcp

Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.

As JSON: this record in the API · API documentation.

Something wrong, or is this yours?

If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.

Write to hello@protocolprobe.com · corrections log · methodology