No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by upstash · MCP Server · ★ 58
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcp-server safe to install? View the security audit →
Upstash MCP Server The Upstash MCP server lets your agent manage and debug your Upstash resources directly, across Redis, QStash, Workflow, and Upstash Box. [!TIP] For most workflows, prefer installing the Upstash Skill and letting your agent drive over running the MCP server. Quickstart You'll need your Upstash account email and an API
| Stars | 58 |
| Forks | 12 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 60.5262757551557/100 |
| Open Issues | 1 |
| Last Updated | 2026-09-01 |
| Created | 2024-12-13 |
| Platforms | mcp, node |
| Est. Tokens | ~17k |
These tools work well together with mcp-server for enhanced workflows:
Explore other popular mcp server tools:
mcp-server is Upstash Model Context Server. It is categorized as a MCP Server with 58 GitHub stars.
mcp-server is primarily written in TypeScript.
You can find installation instructions and usage details in the mcp-server GitHub repository at github.com/upstash/mcp-server. The project has 58 stars and 12 forks, indicating an active community.
mcp-server is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: