AgentStackBLOCK
AgentStack is a production-grade multi-agent framework built on Mastra, delivering 50+ enterprise tools, 25+ specialized agents, and A2A/MCP orchestration for scalable AI systems. Focuses on financial intelligence, RAG pipelines, observability, and secure governance. ACP Openclaw, Gemini CLI, Openco
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Configuration
Development
[](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://nextjs.org/) [](https://react.dev/) [](LICENSE)
[](src/mastra/agents) [](src/mastra/tools) [](src/mastra/workflows) [](src/mastra/networks) [](ui/)
[](https://vitest.dev/) [](https://zod.dev/) [](https://eslint.org/)
[](https://github.com/ssdeanx/AgentStack) [
20 read · 6 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Bias | read | Detects biased language/opinions |
Changelog | read | Generate changelogs from git commits |
Completeness | read | Evaluates coverage of input elements |
Dane | read | Personal assistant and best friend |
Editor | read | A versatile content editor that improves clarity, coherence, and quality across various content types including technical writing, documentation, emails, reports, and creative content. |
Explorer | read | Quick exploration and discovery of codebase patterns |
Factuality | read | Evaluates if the claims in the output are factual and supported by evidence |
a2aCoordinator | read | A2A Coordinator that orchestrates multiple specialized agents in parallel. Routes tasks dynamically, coordinates workflows, and synthesizes results using the A2A protocol. |
brainstorm_ideas | read | Brainstorm new ideas based on a note. This can be useful for generating new ideas or solutions to problems. |
coding-feature-development | read | Full feature development: architecture → implementation → review → testing |
comprehensive-code-review | read | Multi-agent code review: architecture + quality + security + testing |
content-pipeline | write | Content creation pipeline: research → write → edit → evaluate |
copywriter-agent | read | An expert copywriter agent that creates engaging, high-quality content across multiple formats including blog posts, marketing copy, social media content, technical writing, and business communications. |
create_issue | write | Create an issue in the current workspace. |
deploy_project | write | Deploy a project to production. |
full-feature-development | read | Complete feature development: architecture → implementation → review → testing |
knowledge-indexing | read | Process documents or codebases into vector store for RAG |
list_projects | read | List projects the current user can access. |
multi-agent-research | read | Coordinate multi-agent research with knowledge extraction |
parallel-coding-analysis | read | Quick parallel analysis of code structure and issues |
parallel-financial-analysis | write | Run parallel financial analysis across crypto and stock agents |
rag-query | write | Execute RAG query: retrieve → rerank → answer → verify |
safe-refactoring | read | Safe code modernization with sandbox verification |
safe-refactoring-with-tests | read | Refactor code safely with sandbox verification and test generation |
sandbox-code-execution | write | Execute and test code in isolated E2B sandbox environment |
summarize_note | read | Give me a TL;DR of the note. This can be useful for quickly understanding the main points of a note. |
Trust audit
BLOCKgrade F · trust 39/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const component = eval(name);
| A-08 | Automated / large-scale attacks | Using gradient-based or PAIR-style methods to mass-generate jailbreak prompts | prompt_injection_report §3.5 & compass_artifa
gsap.to('[data-beacon-wave]', {gsap.to('[data-beacon-core]', {aria-label="Animated fractal beacon"
<circle data-beacon-wave cx="60" cy="60" r="13" stroke="currentColor" strokeOpacity="0.35" strokeWidth="2" />
<circle data-beacon-wave cx="60" cy="60" r="24" stroke="currentColor" strokeOpacity="0.28" strokeWidth="2" />
CHROME_CDP_URL='http://127.0.0.1:9222'
CHROME_REMOTE_DEBUGGING_URL='http://127.0.0.1:9222'
#http://127.0.0.1:3000/api/auth/callback/google
DATABASE_URL=postgresql://postgres:password@localhost:5432/mastra
DATABASE_URL=postgresql://postgres:password@localhost:5432/mastra
const API_KEY = 'sk_live_abc123xyz789'
const API_KEY = 'sk_live_abc123xyz789'
browser.zip
.markdownlint.json
.yamllint.yaml
import { mastra } from '../../../src/mastra'import { ChatProvider } from '../../providers/chat-context'import { CodeLayout } from '../../components/code-layout'import { ChatLayout } from '../../components/chat-layout'import { ChatProvider } from '../../providers/chat-context'CHROME_CDP_URL=http://127.0.0.1:9222
CHROME_REMOTE_DEBUGGING_URL=http://127.0.0.1:9222
Gates applied: instruction_override, no_behavioural_pass, no_license.
5f60a6a7be34full audit observations/trust-audit/mcp-server/ssdeanx__agentstack.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 5f60a6a7be34 | BLOCK | F | 39 | first audit |
Questions
What is the AgentStack MCP server?
AgentStack is a production-grade multi-agent framework built on Mastra, delivering 50+ enterprise tools, 25+ specialized agents, and A2A/MCP orchestration for scalable AI systems. Focuses on financial intelligence, RAG pipelines, observability, and secure governance. ACP Openclaw, Gemini CLI, Openco
What tools does AgentStack expose?
26 in total: 20 read-only, 6 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is AgentStack safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (39/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does AgentStack need?
It reads AI_GATEWAY_API_KEY, ALPHA_VANTAGE_API_KEY, AMPERSAND_API_KEY, ANTHROPIC_API_KEY, ARCADE_API_KEY, BETTER_AUTH_PRODUCTION_URL, BETTER_AUTH_SECRET, BETTER_AUTH_TRUSTED_ORIGIN, BETTER_AUTH_URL, CLOUDFLARE_API_TOKEN, COMPOSIO_API_KEY and CONVEX_ADMIN_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (5f60a6a7be34), read on 2026-10-08. The repository is watched and re-audited when it changes.