MCP servers › io.github.sadri-dridi › st-nm
MCP server · registry snapshot 2026-10-04 · last tested 2026-10-08
io.github.sadri-dridi/st-nm
USPS state code NM. — the publisher's description
Summary
io.github.sadri-dridi/st-nm is a remote MCP server listed in the official MCP registry at version 1.0.0. On 2026-10-08 ProtocolProbe connected to it in read-only mode and read its inventory: 31 tools, 0 resources and 0 prompts. We did not call its tools, because its operator has not authorized testing. 2 of the 14 checks that apply to it were exercised. Results of the checks are published only after we have verified them and told the publisher.
Not probed (no operator authorization)
We connected and read what the server declares, but did not call its tools, because its operator has not authorized testing. This is our choice, not a block by the server. No security score is given; a check we did not run is never counted as passed.
Key facts
- Runs
- remote (hosted by the publisher)
- Transport
- streamable HTTP
- Sign-in
- none needed to open a session
- Repository
- public
- Topic
- data-and-databasesAI-classified
- Last tested
- 2026-10-08
- Inventory: exercised
- Hidden instructions: exercised
- Real execution: not run · our policy
- Secret leak: not run · nothing to check it against
- Internal addresses: not run · our policy
- Unconfirmed changes: not run · our policy
- Bad input: not run · our policy
- Model requests: not run · nothing to check it against
- Sensitive questions: not run · nothing to check it against
- Folder boundary: not run · our policy
- Log leaks: not run · nothing to check it against
- Hidden content: not run · nothing to check it against
- Fake assistant turns: not applicable
- Token passthrough: not applicable
- Token audience: not applicable
- Sign-in redirect: not run · our policy
- Consent handling: not testable from outside
- Sign-in metadata: not applicable
2 exercised12 not run (reason given)4 not applicable
How fresh this is
- Live-tested
- yes, a real session (not a text-only review)
- Last tested
- 2026-10-08
- Mode
- read-only (no tool calls)
- Registry data
- snapshot 2026-10-04
- Package and repository
- checked 2026-10-06
- Engine
- mcp-runtime-engine@0.1.0 · sdk@1.32.0
Security testing
What did we test, and what did we leave out?
18 checks · features #1, #2Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). 2 of the 14 checks that apply to it were exercised. Results of the checks are published only after we have verified them and told the publisher.
- 1Inventory
tool-listReads the declared tools, resources and prompts.exercised - 2Hidden instructions
description-poisoningLooks for hidden instructions in tool descriptions.exercised
- 3Real execution
real-executionCalls a tool and checks what really happens.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 4Secret leak
canary-leakPlants a fake secret and checks whether it leaks.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 5Internal addresses
ssrfChecks whether a tool can be steered to internal addresses.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 6Unconfirmed changes
write-without-confirmationChecks whether tools that change data act without asking.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 7Bad input
error-handlingSends bad input and watches how the server answers.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 8Model requests
samplingChecks whether the server asks the client's model to act for it.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 9Sensitive questions
elicitation-sensitive-dataChecks whether the server asks users for sensitive data.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 10Folder boundary
root-boundaryChecks whether the server reaches outside the folders it was given.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 11Log leaks
logging-side-channelChecks whether log messages carry data they should not.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 12Hidden content
audience-hidingChecks resources that hide content from the user.This check needs content the server returns, and nothing was read or called.not run · nothing to check it against - 16Sign-in redirect
open-redirectChecks the sign-in redirect for abuse.Testing the sign-in redirect means sending probes to the operator's sign-in service, which we do not do without their authorization.not run · our policy - 17Consent handling
confused-deputyChecks consent handling when one service acts for another.Depends on the operator's own consent screen, which differs per server and cannot be tested from outside.not testable from outside
- 13Fake assistant turns
fake-assistant-turnChecks prompts that pose as the assistant's own words.The server exposes no prompts.not applicable - 14Token passthrough
token-passthroughChecks whether the server forwards a user's token to other services.The server opened a session without sign-in, so there is no token flow to check.not applicable - 15Token audience
token-audience-validationChecks whether tokens meant for another service are accepted.The server opened a session without sign-in, so there is no token flow to check.not applicable - 18Sign-in metadata
oauth-url-schemeChecks the published sign-in metadata for unsafe URLs.No sign-in (OAuth) metadata is published, so there are no sign-in addresses to check.not applicable
Source: our own test, 2026-10-08, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model.
What happened during the test?
Feature #8The steps in order, as the test record holds them.
- 0 msStarted a read-only session with the server's remote endpoint
- 25 msConnected after 0 redirects. No credential was sent or needed.
- Read the inventory: 31 tools, 0 resources, 0 prompts.
- 662 msFinished: 2 checks exercised.
What it is
What does this server offer?
Observed inventory- st-nm
- utc-time
- timezone
- validate-json
- normalize-url
- inspect-robots
- domain-shape
- citation
- compatibility
- status-catalog
- iana-zones
- web-fetch
- fetch-status
- github-repo-shape
- weather-hint
- memory-key-count
- file-path-ok
- browser-url-ok
- think-steps
- search-query-len
- hn-front-count
- lib-docs-hint
- playwright-url-ok
- figma-url-shape
- jira-key-shape
- geo-hint
- calc-eval
- wiki-title-ok
- agent-tool-index
- people-search-index
- agent-ads-index
Tool names are chosen by the publisher.
Does the registry listing match what we found?
Feature #6The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.
| Registry says | We found | Result | Source · date |
|---|---|---|---|
| Remote endpoint agent-observatory-sensor.nolimit-observatory.workers.dev/s/st-nm/mcp | Session opened | matches | our test · 2026-10-08 |
| No credential declared as required | Opened a session without any credential | matches | our test · 2026-10-08 |
| Repository github.com/sadri-dridi/named-mcp-utilities | Opens publicly | matches | api.github.com · 2026-10-06 |
Who made it?
Feature #7 · lineage
Facts about the publisher. We do not turn them into a trust score.
- Namespace
- io.github.sadri-dridi
- GitHub owner
- a personal account (sadri-dridi)
- Repository
- github.com/sadri-dridi/named-mcp-utilities
- Stars
- 0
- Repository age
- 0–30 days
- Last push
- 0–30 days ago
- Archived
- no
Source: the registry entry and api.github.com · 2026-10-06.
Choosing
Common questions about io.github.sadri-dridi/st-nm
Answered from the data aboveDoes io.github.sadri-dridi/st-nm need an API key or sign-in?
It opened a session without any credential on 2026-10-08. The registry entry declares no required credential; no declaration is not a guarantee.
Has io.github.sadri-dridi/st-nm been security tested?
Partly. 2 of the 14 checks that apply to it were exercised. We connected and read what the server declares, but did not call its tools, because its operator has not authorized testing. This is our choice, not a block by the server. No security verdict is published before verification.
Where is the source code of io.github.sadri-dridi/st-nm?
In github.com/sadri-dridi/named-mcp-utilities, which opens publicly.
Reference
How is it classified?
18 fields
One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.
“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.
Cite or correct this page
Sources and corrections
Suggested citation
ProtocolProbe. “io.github.sadri-dridi/st-nm: MCP server record.” Data checked 2026-10-08. https://protocolprobe.com/mcp/servers/io.github.sadri-dridi/st-nm
Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.
As JSON: this record in the API · API documentation.
Something wrong, or is this yours?
If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.
Write to hello@protocolprobe.com · corrections log · methodology