WebMCP tool community service
Risk level
medium
40/100

Stacktree

Stacktree is a community-maintained WebMCP tool from Stacktree. Anomity scores its risk at 40 out of 100 (medium).

network:outbound

Analysis summary

Stacktree is a community-maintained WebMCP tool from Stacktree. Anomity scores its risk at 40 out of 100 (medium).

Stacktree is a publishing service exposed through WebMCP: an agent hands it generated HTML and receives a shareable, claimable link in return. It turns "the model made a page" into "the page is live at a URL" in a single tool call.

That is a genuinely useful primitive and a genuinely sharp one. An agent with access to this tool can publish content to the open web autonomously — content it authored, from context it was given, possibly including material it should not have republished. It declares outbound network access. Anyone enabling it for an agent should think of it as granting publish rights, and should expect to need a review step between generation and publication rather than after it.

Why this entry scored 40 out of 100

This profile starts at the catalog's neutral base of 50. Because the entry is community-maintained, trust adjusts the score by -10. The entry declares no high-risk capabilities on its own, so capabilities add nothing. It matches no dangerous capability combinations. The clamped result is 40, placing it in the medium band.

See the full scoring formula →

Findings

  • Established community project Trust offset
    Contribution to score: -10

Capabilities

Every capability the entry declares, with the security implication of each.

  • network:outbound Outbound network
    Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access.