S&P 500BLOCK
An MCP server and Next.js web app for querying S&P 500 company data from Supabase, with tools for company info, news, officers, and SEC filings, plus embedded MCP App UI resources, Elicitation, and Sampling support.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP (Model Context Protocol) server and Next.js web app for querying S&P 500 company data from Supabase. It exposes MCP tools for company fundamentals, annual financial metrics, historical price data, news sentiment, officers, and SEC filings, plus a web UI and embedded MCP App resources for browsing and testing those tools.
Tools
search_companies is an internal symbol resolver, not an exposed MCP tool. User queries are resolved through getCompanySymbol. For ambiguous matches, elicitation-capable clients are asked to choose a company. Modern clients receive an input_required result; the SDK compatibility layer serves the same flow to 2025-era Streamable HTTP clients. Clients without elicitation support continue with the first match.
Tech Stack
- Workspace: pnpm 10.34.5 + Turborepo
- Runtime: Node 22 (
.nvmrc) - Web app: Next.js 16 App Router, React 19, TypeScript strict mode (
apps/web) - MCP Apps: Vite single-file React pages built from
apps/web-appand served as tool UI resources - MCP: `mcp-h
6e3e70391059OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ui --env LOGO_DEV_TOKEN=${LOGO_DEV_TOKEN} --env SUPABASE_ANON_KEY=${SUPABASE_ANON_KEY} -- npx -y @workspace/[email protected]{
"mcpServers": {
"ui": {
"command": "npx",
"args": [
"-y",
"@workspace/[email protected]"
],
"env": {
"LOGO_DEV_TOKEN": "${LOGO_DEV_TOKEN}",
"SUPABASE_ANON_KEY": "${SUPABASE_ANON_KEY}"
}
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_company_filings | read | Get SEC filings history for a company, supports filtering by symbol, date range, and filing type |
get_company_financials | read | Get annual company financial metrics, grouped for charting and matrix analysis. Supports item, date range, and latest-period filters. |
get_company_info | read | Get complete company basic information including financials, leadership, address, and business summary. Supports both symbol and company name queries. |
get_company_news | read | Get recent company news with sentiment analysis, supports filtering by symbol and sentiment. |
get_company_officers | read | Get company executive officers and their compensation info, supports filtering by symbol |
get_company_price_data | read | Get historical daily OHLCV price data for a company. Returns a plain list of price rows. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (5)
"content": "sk_live_82fa9c4d2f6b4e0a••••••••",
@vitejs/plugin-react, autoprefixer, vite, vite-plugin-singlefile
@modelcontextprotocol/client, @modelcontextprotocol/ext-apps, @modelcontextprotocol/server, @supabase/supabase-js, class-variance-authority, clsx, gsap, lodash-es
@base-ui/react, autoprefixer
apps/web/public/video.mp4
Gates applied: critical_finding, no_behavioural_pass.
6e3e70391059full audit observations/trust-audit/mcp-server/zhensherlock__s-p-500.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6e3e70391059 | BLOCK | D | 69 | first audit |
Questions
What is the S&P 500 MCP server?
An MCP server and Next.js web app for querying S&P 500 company data from Supabase, with tools for company info, news, officers, and SEC filings, plus embedded MCP App UI resources, Elicitation, and Sampling support.
What tools does S&P 500 expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is S&P 500 safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does S&P 500 need?
It reads LOGO_DEV_TOKEN and SUPABASE_ANON_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does S&P 500 run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @workspace/ui at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (6e3e70391059), read on 2026-10-07. The repository is watched and re-audited when it changes.