StataBLOCK
Stata MCP Extension for VS Code, Cursor, and Antigravity IDE
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](./README.md) [](./README.zh-CN.md) [](https://marketplace.visualstudio.com/items?itemName=DeepEcon.stata-mcp) [](https://marketplace.visualstudio.com/items?itemName=DeepEcon.stata-mcp) [](https://open-vsx.org/extension/DeepEcon/stata-mcp) [](https://open-vsx.org/extension/DeepEcon/stata-mcp) [](https://github.com/hanlulong/stata-mcp/releases) [](https://github.com/hanlulong/stata-mcp/blob/main/LICENSE)
This extension provides Stata integration for Visual Studio Code, Cursor, and Antigravity IDE using the Model Context Protocol (MCP). It enables AI-powered Stata development with GitHub Copilot, Cursor, Antigravity, Cline, Claude Code, or Codex.
Features
- Run Stata Commands: Execute selections or entire .do files directly from your editor
- Real-time Output: See Stata results instantly in your editor
- Syntax Highlighting: Full syntax support for Stata .do, .ado, .mata, and .doh files
- AI Assistant Integration: Contextual help and code suggest
265c09938fbbOBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add stata-mcp -- npx -y [email protected]
{
"mcpServers": {
"stata-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
stata_run_selection | write | Stata Run Selection Endpoint\n\nRun selected Stata code and return the output\n\n### Responses:\n\n**200**: Successful Response (Success Response) |
Trust audit
BLOCKgrade F · trust 58/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (24)
exec(command, { maxBuffer: 1024 * 1024 * 10 }, (error, stdout, stderr) => {serverProcess = exec(cmdString, {console.log('Option 1 (may require sudo): curl -LsSf https://astral.sh/uv/install.sh | sudo sh');'/usr/local/bin/uv',
<div class="error" style="display:none;">Failed to load graph: graph1 (path: /Users/.../graph1.png)</div>
return '<!DOCTYPE html><html><body style="background:red;color:white;padding:20px"><h1>TEST</h1><p>graphs: ' + graphCount + '</p></body></html>';
system use found in code, not declared in the description
streamable-http
.vscodeignore
digest = hashlib.sha1(raw_session_id.encode("utf-8", errors="replace")).hexdigest()[:10]digest = hashlib.sha1(raw_session_id.encode("utf-8", errors="replace")).hexdigest()[:10]digest = hashlib.sha1(raw_value.encode("utf-8", errors="replace")).hexdigest()[:10]seed_hash = int(hashlib.md5(seed_input.encode()).hexdigest()[:8], 16)
seed_hash = int(hashlib.md5(seed_input.encode()).hexdigest()[:8], 16) % 2147483647
adm-zip, axios, resolve, @types/glob, @types/mocha, @types/vscode, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
- Get full access to `ServerSession`
curl -LsSf https://astral.sh/uv/install.sh | sh # macOS/Linux
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh # macOS/Linux
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
images/demo.mp4
images/demo_2x.gif
images/pystata.png
Gates applied: no_behavioural_pass.
265c09938fbbfull audit observations/trust-audit/mcp-server/hanlulong__stata.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 265c09938fbb | BLOCK | F | 58 | first audit |
Questions
What is the Stata MCP server?
Stata MCP Extension for VS Code, Cursor, and Antigravity IDE
What tools does Stata expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Stata safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (58/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Stata need?
No credential environment variables were found in its source, so it appears to need none.
How does Stata run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as stata-mcp at 0.5.3.
How current is this page?
The grade is for one exact copy of the source (265c09938fbb), read on 2026-09-30. The repository is watched and re-audited when it changes.