Atlas / MCP servers / gvaibhav / TAM

TAMBLOCK

mcp/gvaibhav/tam

A comprehensive Model Context Protocol (MCP) server for market sizing analysis, TAM/SAM calculations, and industry research. Built with TypeScript, Express.js, and following the MCP specification.

Verdict
BLOCK
Grade
F
Trust score
59 /100
Exposed tools
68 68r · 0w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/gvaibhav/TAM-MCP-Server/blob/main/LICENSE) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.org/)

A Model Context Protocol server providing market research and business analysis capabilities through 28 tools, 15 business prompts, and integration with 8 economic data sources.

Overview

This MCP server provides comprehensive market research capabilities including:

  • 28 Tools: Market analysis, data access, and business intelligence tools
  • 15 Prompts: Professional business analysis templates for funding, strategy, and research
  • Data Integration: Alpha Vantage, BLS, Census, FRED, IMF, Nasdaq Data Link, OECD, World Bank
  • Smart Defaults: Pre-configured parameters for immediate use without setup
  • Multiple Transports: STDIO, Streamable HTTP, and SSE support

Capabilities

Market Analysis Tools

  • Total Addressable Market (TAM) and Serviceable Addressable Market (SAM) calculations
  • Market size estimation and forecasting
  • Industry analysis and competitive intelligence
  • Market segmentation and opportunity identification
  • Data validation and cross-source verification

Business Intelligence Prompts

  • Startup funding pitch preparation
  • Private equity investment analysis
  • Corporate strategy and market entry
  • Crisis management and regulatory impact assessment
  • ESG and sustainability analysis

Data Access

  • Real-time financial and economic data retrieval
  • Multi-source data aggregation and comparison
  • Intelligent routing based on data type and availability
  • Comprehensive caching for performance optimization

MCP Protocol Features

  • Real-time Notifications: 6 types of business-specific notifications for market intelligence, data source
Read from source at commit 7ed8207fcb8cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add tam-mcp-server --env ALPHA_VANTAGE_API_KEY=${ALPHA_VANTAGE_API_KEY} --env BLS_API_KEY=${BLS_API_KEY} --env CENSUS_API_KEY=${CENSUS_API_KEY} --env COINGECKO_API_KEY=${COINGECKO_API_KEY} -- npx -y @gvaibhav/[email protected]
claude-desktop
{
  "mcpServers": {
    "tam-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@gvaibhav/[email protected]"
      ],
      "env": {
        "ALPHA_VANTAGE_API_KEY": "${ALPHA_VANTAGE_API_KEY}",
        "BLS_API_KEY": "${BLS_API_KEY}",
        "CENSUS_API_KEY": "${CENSUS_API_KEY}",
        "COINGECKO_API_KEY": "${COINGECKO_API_KEY}"
      }
    }
  }
}
03

Exposed tools (68)

68 read · 0 write · 0 destructive.

ToolRiskDescription
TechnologyreadTechnology industry
affected_industryreadPrimary affected industry (e.g.,
affected_sectorreadAffected sector (e.g.,
analysis_depthreadAnalysis depth (e.g.,
analysis_focusreadAnalysis focus (e.g.,
analysis_typereadAnalysis type (e.g.,
asset_classreadPrimary asset class (e.g.,
asset_management_researchread📈 Institutional asset management research report. Comprehensive sector analysis for portfolio managers and research teams with risk-adjusted return projections.
best_practices_guideread⭐ Best practices for market analysis with the TAM MCP Server. Professional workflows, data interpretation, and strategic insights.
business_modelreadBusiness model (e.g.,
company_namereadName of the startup seeking funding
company_symbolreadStock symbol or company identifier (e.g.,
competitive_focusreadCompetitive analysis focus (e.g.,
competitive_intelligenceread🎯 Competitive landscape analysis with market positioning and strategic insights. Focused competitor assessment for strategic planning.
compliance_scopereadCompliance scope (e.g.,
corporate_strategy_entryread🏢 Fortune 500 market entry strategy analysis. Board-level presentation for new market opportunities, strategic partnerships, and competitive positioning.
crisis_management_analysisread🚨 Emergency market analysis for crisis response teams. Rapid assessment of market disruptions, supply chain impacts, and strategic response options.
crisis_typereadType of crisis (e.g.,
deal_sizereadExpected deal size in USD (e.g.,
disruption_timelinereadExpected disruption timeline (e.g.,
entry_modereadPreferred entry mode (e.g.,
entry_strategyreadPreferred entry strategy (e.g.,
esg_focusreadESG focus area (e.g.,
esg_sustainability_analysisread🌱 ESG and sustainability market analysis for sustainable investing and corporate responsibility teams. Environmental, social, and governance impact assessment.
expansion_timelinereadExpansion timeline (e.g.,
experience_levelreadUser experience level (e.g.,
fund_focusreadFund investment focus (e.g.,
funding_stagereadFunding stage (e.g.,
geographic_focusreadGeographic market focus (e.g.,
geographic_scopereadGeographic investment scope (e.g.,
imf_getDatasetreadRetrieves comprehensive economic and financial datasets from the International Monetary Fund. 🌍 **What it does:** - Accesses IMF
implementation_timelinereadImplementation timeline (e.g.,
industry_applicationreadTarget industry application (e.g.,
industry_focusreadTarget industry (e.g.,
industry_keywordreadIndustry or market keyword (e.g.,
industry_scopereadIndustry scope (e.g.,
industry_sectorreadPrimary industry sector (e.g.,
international_expansionread🌍 Global market entry strategy with cultural, regulatory, and competitive analysis. Comprehensive market opportunity assessment for international expansion.
investment_horizonreadInvestment time horizon (e.g.,
investment_screeningread💎 Investment opportunity screening with fundamental and market analysis. Quick evaluation for investment committees and portfolio managers.
investment_sectorreadInvestment sector focus (e.g.,
investment_thesisreadPrimary investment thesis (e.g.,
market_opportunity_scanread🔍 Rapid market opportunity identification for time-sensitive decisions. Quick assessment of market size, growth trends, and competitive dynamics.
metrics_priorityreadPriority metrics (e.g.,
oecd_getDatasetreadRetrieves comprehensive datasets from the Organisation for Economic Co-operation and Development (OECD). 🌍 **What it does:** - Accesses OECD
portfolio_themereadPortfolio theme or thesis (e.g.,
private_equity_researchread📊 Investment committee package for private equity deals. Comprehensive market analysis, competitive dynamics, and value creation opportunities with risk assessment.
regulatory_changereadType of regulatory change (e.g.,
regulatory_impact_assessmentread⚖️ Regulatory change impact analysis for compliance and strategy teams. Assessment of policy changes on market dynamics and business operations.
reporting_frameworkreadReporting framework (e.g.,
risk_profilereadRisk tolerance (e.g.,
screening_criteriareadScreening criteria (e.g.,
sector_focusreadSector or theme focus (e.g.,
stakeholder_focusreadPrimary stakeholder concern (e.g.,
startup_funding_pitchread🚀 Comprehensive startup funding presentation with TAM/SAM analysis. Perfect for Series A-C funding rounds, includes market validation, competitive landscape, and financial projections.
target_amountreadTarget funding amount in USD (e.g.,
target_companyreadName or description of target company
target_countryreadTarget country or region (e.g.,
target_marketreadTarget market or industry to enter (e.g.,
technology_disruption_analysisread⚡ Technology disruption impact assessment for innovation teams. Analysis of emerging technologies and their market transformation potential.
technology_focusreadTechnology area (e.g.,
timelinereadStrategic timeline (e.g.,
tool_categoryreadTool category (e.g.,
tool_guidanceread📚 Interactive guide to TAM MCP Server tools with usage examples and best practices. Perfect for new users and advanced workflows.
urgency_levelreadResponse urgency (e.g.,
use_casereadSpecific use case (e.g.,
venture_capital_thesisread💰 VC investment thesis development with market trends, competitive landscape, and portfolio fit analysis. Ideal for investment committee presentations.
worldBank_getIndicatorDatareadRetrieves development indicators and economic data from the World Bank
04

Trust audit

BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (23)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
doc/TOOL-SYSTEM-SELECTION-GUIDE.md:1
# Tool System Selection Guide
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
doc/consumer/default-values-guide.md:1
# Default Values Implementation Guide
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
doc/guides/NOTIFICATIONS-IMPLEMENTATION.md:1
# TAM MCP Server - Notifications Implementation Summary
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
doc/reference/CHANGELOG.md:1
# Changelog
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/services/dataSources/alphaVantageService.test.ts:13
const apiKey = 'test_alpha_vantage_api_key';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/services/dataSources/alphaVantageService.test.ts:81
apikey: 'test_alpha_vantage_api_key'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/services/dataSources/alphaVantageService.test.ts:168
apikey: 'test_alpha_vantage_api_key'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/services/dataSources/alphaVantageService.test.ts:199
apikey: 'test_alpha_vantage_api_key'
LOWInventory / provenance · inv.hidden_file · CWE-1104
config/.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
doc/contributor/contributing.md
doc/contributor/contributing.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
doc/contributor/security.md
doc/contributor/security.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
doc/contributor/testing.md
doc/contributor/testing.md
Why it matters. link not followed
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/scripts/analyze-nasdaq-tier.mjs:14
console.log('API Key:', apiKey ? 'SET' : 'NOT SET');
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/scripts/test-alphavantage.mjs:14
console.log('API Key status:', apiKey ? 'SET' : 'NOT SET');
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/scripts/test-fred.mjs:14
console.log('API Key status:', apiKey ? 'SET' : 'NOT SET');
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/scripts/test-nasdaq.mjs:14
console.log('API Key status:', apiKey ? 'SET' : 'NOT SET');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
config/redis-examples/basic-redis-config.js:1
import { EnhancedDataService } from '../../src/services/EnhancedDataService.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/datasources/AlphaVantageService.ts:2
import { logger } from "../../utils/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/datasources/AlphaVantageService.ts:3
import { DataSourceService } from "../../types/dataSources.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/datasources/BlsService.ts:2
import { logger } from "../../utils/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/datasources/BlsService.ts:3
import { DataSourceService } from "../../types/dataSources.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, dotenv, express, ioredis, node-cache, winston, zod
Why it matters. 25 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
doc/BACKEND-API-TESTING.md:395
# Add to crontab for hourly health checks
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7ed8207fcb8cfull audit observations/trust-audit/mcp-server/gvaibhav__tam.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087ed8207fcb8cBLOCKF59first audit
06

Questions

What is the TAM MCP server?

A comprehensive Model Context Protocol (MCP) server for market sizing analysis, TAM/SAM calculations, and industry research. Built with TypeScript, Express.js, and following the MCP specification.

What tools does TAM expose?

68 in total: 68 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is TAM safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (59/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does TAM need?

It reads ALPHA_VANTAGE_API_KEY, BLS_API_KEY, CENSUS_API_KEY, COINGECKO_API_KEY, FINNHUB_API_KEY, FRED_API_KEY, NASDAQ_API_KEY, NASDAQ_DATA_LINK_API_KEY and REDIS_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does TAM run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @gvaibhav/tam-mcp-server at 1.0.1.

How current is this page?

The grade is for one exact copy of the source (7ed8207fcb8c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement