Atlas / MCP servers / zhensherlock / S&P 500

S&P 500BLOCK

mcp/zhensherlock/s-p-500

An MCP server and Next.js web app for querying S&P 500 company data from Supabase, with tools for company info, news, officers, and SEC filings, plus embedded MCP App UI resources, Elicitation, and Sampling support.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
6 6r · 0w · 0d
Transport
streamable-http
License
AGPL-3.0
Stars
107
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server and Next.js web app for querying S&P 500 company data from Supabase. It exposes MCP tools for company fundamentals, annual financial metrics, historical price data, news sentiment, officers, and SEC filings, plus a web UI and embedded MCP App resources for browsing and testing those tools.

Tools

search_companies is an internal symbol resolver, not an exposed MCP tool. User queries are resolved through getCompanySymbol. For ambiguous matches, elicitation-capable clients are asked to choose a company. Modern clients receive an input_required result; the SDK compatibility layer serves the same flow to 2025-era Streamable HTTP clients. Clients without elicitation support continue with the first match.

Tech Stack

  • Workspace: pnpm 10.34.5 + Turborepo
  • Runtime: Node 22 (.nvmrc)
  • Web app: Next.js 16 App Router, React 19, TypeScript strict mode (apps/web)
  • MCP Apps: Vite single-file React pages built from apps/web-app and served as tool UI resources
  • MCP: `mcp-h
Read from source at commit 6e3e70391059OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ui --env LOGO_DEV_TOKEN=${LOGO_DEV_TOKEN} --env SUPABASE_ANON_KEY=${SUPABASE_ANON_KEY} -- npx -y @workspace/[email protected]
claude-desktop
{
  "mcpServers": {
    "ui": {
      "command": "npx",
      "args": [
        "-y",
        "@workspace/[email protected]"
      ],
      "env": {
        "LOGO_DEV_TOKEN": "${LOGO_DEV_TOKEN}",
        "SUPABASE_ANON_KEY": "${SUPABASE_ANON_KEY}"
      }
    }
  }
}
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
get_company_filingsreadGet SEC filings history for a company, supports filtering by symbol, date range, and filing type
get_company_financialsreadGet annual company financial metrics, grouped for charting and matrix analysis. Supports item, date range, and latest-period filters.
get_company_inforeadGet complete company basic information including financials, leadership, address, and business summary. Supports both symbol and company name queries.
get_company_newsreadGet recent company news with sentiment analysis, supports filtering by symbol and sentiment.
get_company_officersreadGet company executive officers and their compensation info, supports filtering by symbol
get_company_price_datareadGet historical daily OHLCV price data for a company. Returns a plain list of price rows.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (5)

CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
sp500-mcp-product-ui.pen:18645
"content": "sk_live_82fa9c4d2f6b4e0a••••••••",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/web-app/package.json
@vitejs/plugin-react, autoprefixer, vite, vite-plugin-singlefile
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/client, @modelcontextprotocol/ext-apps, @modelcontextprotocol/server, @supabase/supabase-js, class-variance-authority, clsx, gsap, lodash-es
Why it matters. 47 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/ui/package.json
@base-ui/react, autoprefixer
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
apps/web/public/video.mp4
apps/web/public/video.mp4
Why it matters. 2797721 bytes not read

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6e3e70391059full audit observations/trust-audit/mcp-server/zhensherlock__s-p-500.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076e3e70391059BLOCKD69first audit
06

Questions

What is the S&P 500 MCP server?

An MCP server and Next.js web app for querying S&P 500 company data from Supabase, with tools for company info, news, officers, and SEC filings, plus embedded MCP App UI resources, Elicitation, and Sampling support.

What tools does S&P 500 expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is S&P 500 safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does S&P 500 need?

It reads LOGO_DEV_TOKEN and SUPABASE_ANON_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does S&P 500 run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @workspace/ui at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (6e3e70391059), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement