MCP servers › io.github.nolindnaidoo › dates-le
MCP server · registry snapshot 2026-10-04 · last tested 2026-10-08
io.github.nolindnaidoo/dates-le
Extract dates and timestamps from logs, data files and code, with their format and position. — the publisher's description
Summary
io.github.nolindnaidoo/dates-le is a local MCP server listed in the official MCP registry at version 2.4.2. On 2026-10-08 ProtocolProbe started its published package in an isolated sandbox in read-only mode and read its inventory: 1 tool, 0 resources and 0 prompts. This test round was read-only, so its tools were not called. 2 of the 12 checks that apply to it were exercised. Results of the checks are published only after we have verified them and told the publisher.
Not probed (read-only run)
We started the package in an isolated sandbox and read what it declares, but this test round was read-only, so its tools were not called. No security score is given; a check we did not run is never counted as passed.
Key facts
- Runs
- local package
- Transport
- standard input/output
- Package
- npm · listed version behind the latest release
- License
- MIT
- Dependencies
- no known high or critical advisories
- Repository
- public
- Topic
- developer-toolsAI-classified
- Last tested
- 2026-10-08
- Inventory: exercised
- Hidden instructions: exercised
- Real execution: not run · our policy
- Secret leak: not run · nothing to check it against
- Internal addresses: not run · our policy
- Unconfirmed changes: not run · our policy
- Bad input: not run · our policy
- Model requests: not run · nothing to check it against
- Sensitive questions: not run · nothing to check it against
- Folder boundary: not run · our policy
- Log leaks: not run · nothing to check it against
- Hidden content: not run · nothing to check it against
- Fake assistant turns: not applicable
- Token passthrough: not applicable
- Token audience: not applicable
- Sign-in redirect: not applicable
- Consent handling: not applicable
- Sign-in metadata: not applicable
2 exercised10 not run (reason given)6 not applicable
Worth knowing before you connect it
- The registry lists 2.4.2; 2.4.3 is newer (1 release).
Each line comes from a section below, with its source and date.
How fresh this is
- Live-tested
- yes, a real session (not a text-only review)
- Last tested
- 2026-10-08
- Mode
- read-only (no tool calls)
- Registry data
- snapshot 2026-10-04
- Package and repository
- checked 2026-10-06
- Engine
- mcp-runtime-engine@0.1.0 · sdk@1.32.0
Security testing
What did we test, and what did we leave out?
18 checks · features #1, #2Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). 2 of the 12 checks that apply to it were exercised. Results of the checks are published only after we have verified them and told the publisher.
- 1Inventory
tool-listReads the declared tools, resources and prompts.exercised - 2Hidden instructions
description-poisoningLooks for hidden instructions in tool descriptions.exercised
- 3Real execution
real-executionCalls a tool and checks what really happens.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy - 4Secret leak
canary-leakPlants a fake secret and checks whether it leaks.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 5Internal addresses
ssrfChecks whether a tool can be steered to internal addresses.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy - 6Unconfirmed changes
write-without-confirmationChecks whether tools that change data act without asking.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy - 7Bad input
error-handlingSends bad input and watches how the server answers.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy - 8Model requests
samplingChecks whether the server asks the client's model to act for it.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 9Sensitive questions
elicitation-sensitive-dataChecks whether the server asks users for sensitive data.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 10Folder boundary
root-boundaryChecks whether the server reaches outside the folders it was given.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy - 11Log leaks
logging-side-channelChecks whether log messages carry data they should not.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 12Hidden content
audience-hidingChecks resources that hide content from the user.This check needs content the server returns, and nothing was read or called.not run · nothing to check it against
- 13Fake assistant turns
fake-assistant-turnChecks prompts that pose as the assistant's own words.The server exposes no prompts.not applicable - 14Token passthrough
token-passthroughChecks whether the server forwards a user's token to other services.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable - 15Token audience
token-audience-validationChecks whether tokens meant for another service are accepted.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable - 16Sign-in redirect
open-redirectChecks the sign-in redirect for abuse.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable - 17Consent handling
confused-deputyChecks consent handling when one service acts for another.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable - 18Sign-in metadata
oauth-url-schemeChecks the published sign-in metadata for unsafe URLs.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable
Source: our own test in an isolated sandbox, 2026-10-08, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model.
What happened during the test?
Feature #8The steps in order, as the test record holds them.
- 0 msStarted the published package in an isolated sandbox (read-only mode)
- 7,482 msConnected after 0 redirects.
- Read the inventory: 1 tool, 0 resources, 0 prompts.
- 26,546 msFinished: 2 checks exercised.
What it is
What does this server offer?
Observed inventory- extract_dates
Tool names are chosen by the publisher.
Does the registry listing match what we found?
Feature #6The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.
| Registry says | We found | Result | Source · date |
|---|---|---|---|
| Published package can be started | Started and answered | matches | our test · 2026-10-08 |
| Version 2.4.2 on npm | Exists and can be installed | matches | npm · 2026-10-06 |
| Repository github.com/nolindnaidoo/dates-le | Opens publicly | matches | api.github.com · 2026-10-06 |
Can it be installed, and is it up to date?
Version pin · advisories
Listed version
- Registry lists
- 2.4.2
- Latest stable
- 2.4.3
- Status
- behind the latest release (1 releases, 2 days)
- Withdrawn
- no
Source: registry.npmjs.org · 2026-10-06. About the version the registry lists; a manual install may resolve to a different one.
Dependency advisories
Counted in the full dependency tree as resolved on 2026-10-08 (npm audit). Bars share one scale. The package itself has no known vulnerability (OSV.dev).
Integrity, provenance, license
- Integrity
- sha512-zxvvqipPEmb9sTZRA…
- Signature
- signed
- License
- MIT
Source: the package registry · 2026-10-06.
Usage
- Downloads
- 955 in the last month
Source: api.npmjs.org · 2026-10-06.
Who made it?
Feature #7 · lineage
Facts about the publisher. We do not turn them into a trust score.
- Namespace
- io.github.nolindnaidoo
- GitHub owner
- a personal account (nolindnaidoo)
- Build record
- signed
- Repository
- github.com/nolindnaidoo/dates-le
- Stars
- 1
- Repository age
- 181–365 days
- Last push
- 0–30 days ago
- Archived
- no
Source: the registry entry and api.github.com · 2026-10-06.
Choosing
Common questions about io.github.nolindnaidoo/dates-le
Answered from the data aboveHas io.github.nolindnaidoo/dates-le been security tested?
Partly. 2 of the 12 checks that apply to it were exercised. We started the package in an isolated sandbox and read what it declares, but this test round was read-only, so its tools were not called. No security verdict is published before verification.
Is the listed version current?
No. The registry lists 2.4.2; the latest stable release on npm is 2.4.3.
Where is the source code of io.github.nolindnaidoo/dates-le?
In github.com/nolindnaidoo/dates-le, which opens publicly.
Reference
How is it classified?
18 fields
One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.
“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.
Cite or correct this page
Sources and corrections
Suggested citation
ProtocolProbe. “io.github.nolindnaidoo/dates-le: MCP server record.” Data checked 2026-10-08. https://protocolprobe.com/mcp/servers/io.github.nolindnaidoo/dates-le
Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.
As JSON: this record in the API · API documentation.
Something wrong, or is this yours?
If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.
Write to hello@protocolprobe.com · corrections log · methodology