MCP servers › io.github.theluckystrike › milestone-schedule
MCP server · registry snapshot 2026-10-04 · last tested 2026-10-08
io.github.theluckystrike/milestone-schedule
Milestone billing from accepted deliverables: due dates, sign-off dates, invoice-ready items. — the publisher's description
Summary
io.github.theluckystrike/milestone-schedule is a remote and local MCP server listed in the official MCP registry at version 0.22.3. On 2026-10-08 ProtocolProbe connected to it in read-only mode and read its inventory: 12 tools, 2 resources and 2 prompts. We did not call its tools, because its operator has not authorized testing. 4 of the 16 checks that apply to it were exercised. Results of the checks are published only after we have verified them and told the publisher.
Open without sign-in
It accepted a session without any credential and lists tools whose names suggest they change data. We did not call them. No security score is given; a check we did not run is never counted as passed.
Key facts
- Runs
- remote and local package
- Transport
- standard input/output, streamable HTTP
- Sign-in
- none needed to open a session
- Package
- MCP bundle
- Repository
- public
- Topic
- finance-and-paymentsAI-classified
- Last tested
- 2026-10-08
- Inventory: exercised
- Hidden instructions: exercised
- Real execution: not run · our policy
- Secret leak: not run · nothing to check it against
- Internal addresses: not run · our policy
- Unconfirmed changes: not run · our policy
- Bad input: not run · our policy
- Model requests: not run · nothing to check it against
- Sensitive questions: not run · nothing to check it against
- Folder boundary: not run · our policy
- Log leaks: not run · nothing to check it against
- Hidden content: exercised
- Fake assistant turns: not run · an error was returned
- Token passthrough: not applicable
- Token audience: not applicable
- Sign-in redirect: not run · our policy
- Consent handling: not testable from outside
- Sign-in metadata: exercised
4 exercised12 not run (reason given)2 not applicable
Worth knowing before you connect it
- 4 tools have a name or declaration suggesting they change data (delivery_schedule_create, deliverable_add, deliverable_delete and 1 more), and the server opened a session without any credential. We did not call them.
Each line comes from a section below, with its source and date.
How fresh this is
- Live-tested
- yes, a real session (not a text-only review)
- Last tested
- 2026-10-08
- Mode
- read-only (no tool calls)
- Registry data
- snapshot 2026-10-04
- Package and repository
- checked 2026-10-06
- Engine
- mcp-runtime-engine@0.1.0 · sdk@1.32.0
Observed fact
This server accepted a session without any credential and lists 4 tools whose name or declaration suggests they change data (delivery_schedule_create, deliverable_add, deliverable_delete, delivery_schedule_delete). That is our reading of the names; we did not call them. Source: our connection, 2026-10-08.
Security testing
What did we test, and what did we leave out?
18 checks · features #1, #2Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). 4 of the 16 checks that apply to it were exercised. Results of the checks are published only after we have verified them and told the publisher.
- 1Inventory
tool-listReads the declared tools, resources and prompts.exercised - 2Hidden instructions
description-poisoningLooks for hidden instructions in tool descriptions.exercised - 12Hidden content
audience-hidingChecks resources that hide content from the user.exercised - 18Sign-in metadata
oauth-url-schemeChecks the published sign-in metadata for unsafe URLs.exercised
- 3Real execution
real-executionCalls a tool and checks what really happens.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 4Secret leak
canary-leakPlants a fake secret and checks whether it leaks.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 5Internal addresses
ssrfChecks whether a tool can be steered to internal addresses.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 6Unconfirmed changes
write-without-confirmationChecks whether tools that change data act without asking.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 7Bad input
error-handlingSends bad input and watches how the server answers.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 8Model requests
samplingChecks whether the server asks the client's model to act for it.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 9Sensitive questions
elicitation-sensitive-dataChecks whether the server asks users for sensitive data.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 10Folder boundary
root-boundaryChecks whether the server reaches outside the folders it was given.This check calls the server's tools. We do not call tools on a server whose operator has not authorized testing.not run · our policy - 11Log leaks
logging-side-channelChecks whether log messages carry data they should not.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against - 13Fake assistant turns
fake-assistant-turnChecks prompts that pose as the assistant's own words.The server returned an error when its prompts were read.not run · an error was returned - 16Sign-in redirect
open-redirectChecks the sign-in redirect for abuse.Testing the sign-in redirect means sending probes to the operator's sign-in service, which we do not do without their authorization.not run · our policy - 17Consent handling
confused-deputyChecks consent handling when one service acts for another.Depends on the operator's own consent screen, which differs per server and cannot be tested from outside.not testable from outside
- 14Token passthrough
token-passthroughChecks whether the server forwards a user's token to other services.The server opened a session without sign-in, so there is no token flow to check.not applicable - 15Token audience
token-audience-validationChecks whether tokens meant for another service are accepted.The server opened a session without sign-in, so there is no token flow to check.not applicable
Source: our own test, 2026-10-08, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model.
What happened during the test?
Feature #8The steps in order, as the test record holds them.
- 0 msStarted a read-only session with the server's remote endpoint
- 263 msConnected after 0 redirects. No credential was sent or needed.
- Read the inventory: 12 tools, 2 resources, 2 prompts.
- 1,825 msFinished: 4 checks exercised.
What it is
What does this server offer?
Observed inventory- delivery_schedule_create
- deliverable_add
- deliverable_status
- deliverable_delete
- delivery_schedule_get
- delivery_schedule_list
- delivery_schedule_delete
- late_report
- delivery_schedule_document
- milestone_payload
- license_status
- license_activate
Tool names are chosen by the publisher. Highlighted names suggest a change to data, by their name or the server's own declaration; that is our reading, since we did not call them.
Does the registry listing match what we found?
Feature #6The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.
| Registry says | We found | Result | Source · date |
|---|---|---|---|
| Remote endpoint mcp.zovo.one/mcp/milestone-schedule | Session opened | matches | our test · 2026-10-08 |
| No credential declared as required | Opened a session without any credential | matches | our test · 2026-10-08 |
| Repository github.com/theluckystrike/mcp-servers | Opens publicly | matches | api.github.com · 2026-10-06 |
Who made it?
Feature #7 · lineage
Facts about the publisher. We do not turn them into a trust score.
- Namespace
- io.github.theluckystrike
- GitHub owner
- a personal account (theluckystrike)
- Repository
- github.com/theluckystrike/mcp-servers
- Stars
- 1
- Repository age
- 31–90 days
- Last push
- 0–30 days ago
- Archived
- no
Source: the registry entry and api.github.com · 2026-10-06.
Choosing
Common questions about io.github.theluckystrike/milestone-schedule
Answered from the data aboveDoes io.github.theluckystrike/milestone-schedule need an API key or sign-in?
It opened a session without any credential on 2026-10-08. The registry entry declares no required credential; no declaration is not a guarantee.
Has io.github.theluckystrike/milestone-schedule been security tested?
Partly. 4 of the 16 checks that apply to it were exercised. It accepted a session without any credential and lists tools whose names suggest they change data. We did not call them. No security verdict is published before verification.
Where is the source code of io.github.theluckystrike/milestone-schedule?
In github.com/theluckystrike/mcp-servers, which opens publicly.
Reference
How is it classified?
18 fields
One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.
“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.
Cite or correct this page
Sources and corrections
Suggested citation
ProtocolProbe. “io.github.theluckystrike/milestone-schedule: MCP server record.” Data checked 2026-10-08. https://protocolprobe.com/mcp/servers/io.github.theluckystrike/milestone-schedule
Quoting is welcome with a link and the check date. Figures are valid for the date shown.
Something wrong, or is this yours?
If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.
Write to hello@protocolprobe.com · corrections log · methodology