Is DalalOS MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highWrite-action tools reachable without authentication
Public scan report
scanner v0.1.9 · 2026-09-25 · same rubric, same numbers if you re-run it
1 high1 low
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 1700ms20/20
- Tool poisoning60 tool descriptions checked13/15
- Auth qualityopen endpoint exposes 2 write-action tools with no auth3/15
- Maintenancerepository not readable: repo not found3/15
- Maintainer identityno repository or website to verify2/10
Findings (2)
- highWrite-action tools reachable without authentication
auth.open-write - lowUnusually long tool description (over 2,000 characters)
poison.long-descriptiontool get_financials: …Get consolidated financials (P&L + balance sheet), TTM, and computed margins. Accepts an NSE symbol, ISIN, or BSE code. `period_type` is "quarterly" (default) or "annual". Banks/NBFCs/insurers return an interest-income template (NII / interest income) instead of Revenue / EBITDA. Returns raw line items and mechanically-computed ratios only — no valuation verdicts. Also includes a `growth` section (annual YoY plus 3y/5y CAGR for revenue / net income / EBITDA / EPS) — a single summary block layered on top of these levels, NOT a per-period series; for a period-by-period QoQ/YoY growth, margin-delta, and reportable-segment trend series instead, see `get_financial_trends`. The `growth` section here is sign-aware (a loss base/endpoint is Not Meaningful rather than a garbage %), EPS share-adjusted across splits/bonuses, with a `base_effect` flag when a tiny prior-year base inflates the YoY. A `null` inside a present growth metric (as opposed to the metric being absent, which means <2 annual periods are cached) means the growth figure is Not Meaningful for that metric this period — most commonly because the prior-year base (or a CAGR endpoint) was a loss, making a percentage change mathematically undefined or misleading; it is not a data gap. When that is the cause, a sibling `*_not_meaningful_reason` field (e.g. `yoy_not_meaningful_reason: "prior_period_loss"`) makes it explicit rather than leaving the `null` to be misread as "no data available". Also carries three multi-period histories (independent of `period_type`/`limit` — always the full annual history): `interest_coverage_history` (per-year interest-coverage trend, general-only, omitted for banks/NBFCs/insurers or a newly-listed filer), `book_value_history` (per-year book value per share plus a P/B "band" against the actual historical price near each period, not general-only), and `working_capital_ratios` (always present: general filers get inventory/receivable/payable days and cash conversion cycle when the latest annual inputs are available; financial institutions receive an explicit not-applicable note). Cash flow: each period carries `cash_flow_available` — Indian BSE-XBRL quarterly filings never include a cash-flow statement (only annual filings do), so it is `false` on every period for the default `period_type="quarterly"`; a top-level `cash_flow_note` explains this when no displayed period has cash-flow data. Call with `period_type="annual"` for populated `operating_cash_flow`/`free_cash_flow`/`capex` figures. Provenance: each period carries `source` — `"bse-xbrl"` for a post-listing exchange filing, or `"drhp"` for a newly-listed company's pre-listing years (restated figures from its IPO prospectus, audited per SEBI ICDR requirements). The envelope's own `source` is the shared value, or `"mixed"` when a window straddles both; a `drhp_periods_note` explains it further whenever any displayed period is DRHP-sourced. …
Overall 55/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON