mcp-server — security grade SAFE, quality 61/100

Security audit verdict: SAFE · quality 61/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by upstash · MCP Server · ★ 58

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-server safe to install? View the security audit →

About mcp-server

Upstash MCP Server The Upstash MCP server lets your agent manage and debug your Upstash resources directly, across Redis, QStash, Workflow, and Upstash Box. [!TIP] For most workflows, prefer installing the Upstash Skill and letting your agent drive over running the MCP server. Quickstart You'll need your Upstash account email and an API

Quick Facts

Stars58
Forks12
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score60.5262757551557/100
Open Issues1
Last Updated2026-09-01
Created2024-12-13
Platformsmcp, node
Est. Tokens~17k

Compatible Skills

These tools work well together with mcp-server for enhanced workflows:

  • investor-agent — semantic(0.30)+complementary+same_lang+similar_pop+shared_platform (56%)
  • mcp-server — semantic(0.82)+same_lang+similar_pop+shared_platform (55%)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is mcp-server?

mcp-server is Upstash Model Context Server. It is categorized as a MCP Server with 58 GitHub stars.

What programming language is mcp-server written in?

mcp-server is primarily written in TypeScript.

How do I install or use mcp-server?

You can find installation instructions and usage details in the mcp-server GitHub repository at github.com/upstash/mcp-server. The project has 58 stars and 12 forks, indicating an active community.

What license does mcp-server use?

mcp-server is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools