Atlas / MCP servers / deploystackio / DeployStack

DeployStackBLOCK

mcp/deploystackio/deploystack

Open source MCP hosting - deploy MCP servers to HTTP endpoints for n8n, Dify, Voiceflow, and any MCP client.

Verdict
BLOCK
Grade
F
Trust score
45 /100
Exposed tools
14 10r · 4w · 0d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
64
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🚀 Try it out · 🌐 Website · 📚 Documentation · Roadmap · Discord

Deploy MCP servers from GitHub to HTTP endpoints in 30 seconds. Works with n8n, Dify, Voiceflow, Langflow, Claude Code, Cursor, and any MCP client.

The Problem

Most MCP servers are stdio-only. But workflow automation platforms need HTTP endpoints.

Current workarounds are painful:

  • mcp-remote requires local Node.js setup
  • Docker containers need DevOps expertise
  • DIY hosting (Fly.io, Railway) takes hours
Read from source at commit 23b5e5727cd6OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add satellite --env COOKIE_SECRET=${COOKIE_SECRET} --env DEPLOYSTACK_ENCRYPTION_SECRET=${DEPLOYSTACK_ENCRYPTION_SECRET} --env DEPLOYSTACK_REGISTRATION_TOKEN=${DEPLOYSTACK_REGISTRATION_TOKEN} --env JWT_SECRET=${JWT_SECRET} -- npx -y @deploystack/[email protected]
claude-desktop
{
  "mcpServers": {
    "satellite": {
      "command": "npx",
      "args": [
        "-y",
        "@deploystack/[email protected]"
      ],
      "env": {
        "COOKIE_SECRET": "${COOKIE_SECRET}",
        "DEPLOYSTACK_ENCRYPTION_SECRET": "${DEPLOYSTACK_ENCRYPTION_SECRET}",
        "DEPLOYSTACK_REGISTRATION_TOKEN": "${DEPLOYSTACK_REGISTRATION_TOKEN}",
        "JWT_SECRET": "${JWT_SECRET}"
      }
    }
  }
}
03

Exposed tools (14)

10 read · 4 write · 0 destructive.

ToolRiskDescription
NamereadDescription
TEST_VARreadTest variable
create_issuewriteCreate GitHub issue
discover_mcp_toolsreadSearch for MCP tools using 1-3 keywords only. Examples:
example_toolreadExample tool
execute_mcp_toolwriteExecute a discovered MCP tool by its path. Use after discovering tools with discover_mcp_tools. The tool_path format is
list_mcp_resourcesreadList all available MCP resources across all connected servers. Resources are server-provided data like files, UI components, or configuration that can be read with read_mcp_resource.
prompt1readFirst prompt
querywriteExecute database query
read_filereadRead contents of a file
read_mcp_resourcereadRead the content of an MCP resource by its URI. Use list_mcp_resources first to discover available resources and their URIs.
test-promptreadA test prompt
test-reporeadTest repository
write_filewriteWrite content to a file
04

Trust audit

BLOCKgrade F · trust 45/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (14 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
services/backend/src/lib/security/build-script-validation.ts:39
{ pattern: /\bnode\s+--eval\b/i, reason: 'node --eval (code execution from string)' },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
services/backend/src/lib/security/build-script-validation.ts:42
{ pattern: /\beval\s*\(/, reason: 'eval() call (code execution from string)' },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
services/backend/src/lib/security/build-script-validation.ts:59
{ pattern: /\bexec\s*\(/, reason: 'exec() (code execution from string)' },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
services/satellite/src/config/security-validation.ts:280
{ pattern: /\bnode\s+--eval\b/i, reason: 'node --eval (code execution from string)' },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
services/satellite/src/config/security-validation.ts:283
{ pattern: /\beval\s*\(/, reason: 'eval() call (code execution from string)' },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
services/backend/drizzle.config.ts:31
ssl: process.env.POSTGRES_SSL === 'true' ? { rejectUnauthorized: false } : false
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
services/backend/src/db/index.ts:87
ssl: config.ssl ? { rejectUnauthorized: false } : false,
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMAuth / authz · auth.debug_bypass · CWE-287, CWE-862
services/backend/src/services/passwordResetService.ts:392
// Check if admin is trying to reset their own password
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
services/satellite/src/server.ts:79
logger.info({ operation: 'registration_token_validated', tokenType }, `Registration token validated: ${tokenType} satellite token`);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
services/backend/src/global-settings/github-oauth.ts:40
key: 'github.oauth.callback_url',
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
services/backend/src/global-settings/index.ts:629
GlobalSettingsService.get('github.oauth.callback_url'),
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
services/backend/src/lib/security/build-script-validation.ts:23
{ pattern: /\bcurl\b/i, reason: 'curl command (network exfiltration risk)' },
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
services/backend/src/lib/security/build-script-validation.ts:24
{ pattern: /\bwget\b/i, reason: 'wget command (network exfiltration risk)' },
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
services/backend/src/lib/security/build-script-validation.ts:25
{ pattern: /\bnc\b/, reason: 'netcat (network exfiltration risk)' },
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
services/backend/drizzle/migrations/0024_curious_dreaming_celestial.sql:1
ALTER TABLE "satellites" ALTER COLUMN "satellite_url" SET DEFAULT 'http://127.0.0.1:3001';--> statement-breakpoint
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
services/backend/src/db/schema-tables/satellites.ts:21
satellite_url: text('satellite_url').notNull().default('http://127.0.0.1:3001'), // Publicly accessible satellite URL
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
services/backend/src/routes/oauth2/register.ts:168
if (uri === 'http://127.0.0.1:33418' || uri === 'https://vscode.dev/redirect') {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
services/backend/src/routes/oauth2/register.ts:172
if (uri.startsWith('http://127.0.0.1:') || uri.startsWith('http://localhost:')) {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
services/backend/src/routes/satellites/manage/update.ts:44
description: 'Satellite URL (e.g., http://127.0.0.1:3001)'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
services/backend/tests/unit/db/config.test.ts:82
password: 'complex_password_123',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
services/backend/tests/unit/routes/auth/resetPassword.test.ts:42
token: 'valid-reset-token-123',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
services/backend/tests/unit/routes/auth/resetPassword.test.ts:209
token: 'different-token-format-456',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
services/backend/tests/unit/routes/auth/verifyEmail.test.ts:70
token: 'valid-verification-token-123',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
services/backend/tests/unit/routes/auth/verifyEmail.test.ts:213
token: 'different-token-format-456',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
services/backend/tests/e2e/15-cloud-credentials.e2e.test.ts:167
service_account_key: '{\n  "type": "service_account",\n  "project_id": "test-project-123",\n  "private_key_id": "test-key-id-123456",\n  "private_key": "-----BEGIN PRIVATE KEY-----\\nMIIEvQIBADANBgkqh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 23b5e5727cd6full audit observations/trust-audit/mcp-server/deploystackio__deploystack.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0723b5e5727cd6BLOCKF45first audit
06

Questions

What is the DeployStack MCP server?

Open source MCP hosting - deploy MCP servers to HTTP endpoints for n8n, Dify, Voiceflow, and any MCP client.

What tools does DeployStack expose?

14 in total: 10 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is DeployStack safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (45/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does DeployStack need?

It reads COOKIE_SECRET, DEPLOYSTACK_ENCRYPTION_SECRET, DEPLOYSTACK_REGISTRATION_TOKEN, JWT_SECRET and POSTGRES_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does DeployStack run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @deploystack/satellite at 0.22.3.

How current is this page?

The grade is for one exact copy of the source (23b5e5727cd6), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement