AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
Security review

Reviewed before an agent can run it.

An MCP server or skill is executable surface area inside your agent. It runs with your keys, your files, and your context in reach. Most directories scrape thousands of repos and rank them by stars. AgentStack scans every version before it lists, and tells you exactly what it checked. Curated and reviewed, not scraped.

Every version re-scanned on publish. Nothing lists without passing.

What every version is scanned for

Three classes of failure, checked automatically before anything can list.

Prompt injection

Hidden instructions buried in tool descriptions, parameters, or returned content that try to hijack an agent: exfiltrate context, override its system prompt, or trick it into unintended tool calls.

Why it mattersAn agent reads tool descriptions as trusted input. A poisoned one can turn your own assistant against you.

Secret exfiltration

Code that reaches for environment variables, credentials, tokens, or local files and ships them off to a third party, directly or smuggled inside an otherwise normal-looking request.

Why it mattersMCP servers run with your keys and your filesystem in reach. Quiet exfiltration is the highest-impact failure.

Dangerous tool calls

Destructive or over-broad operations: unscoped shell execution, arbitrary network reach, file deletion, or privilege beyond what the listing claims to need.

Why it mattersThe gap between what a tool says it does and what it can actually do is where most real damage lives.

How the review works

  1. 1

    Every version is scanned

    No version reaches the catalog unscanned. Each publish, not just the first, runs through the automated review before it can list publicly.

  2. 2

    A pass auto-publishes + earns the badge

    Clear the scan and the version lists immediately and earns the green verified badge. The full report is published on the listing page: checks run, summary, and version.

  3. 3

    A flag pulls the badge + routes to review

    Anything flagged loses the badge and is held for human review. Findings are shown with severity (HIGH, MEDIUM, LOW) so nothing ambiguous ships silently.

  4. 4

    The report stays public

    The scan report lives on the listing, versioned. You can read exactly what was checked before you point an agent at it.

What "verified" means, and what it doesn't

The green badge means

  • This version passed the automated review at publish time.
  • It was scanned for prompt injection, secret exfiltration, and dangerous tool calls.
  • The full report is public on the listing: checks run, summary, version.
  • It re-passes the scan on every new version, or it loses the badge.

It does not mean

  • That the code is bug-free or that its business logic is correct.
  • That AgentStack endorses the seller or guarantees their service.
  • That no risk exists. No automated review catches everything.
  • That an older, un-updated install carries this version's result.

We'd rather tell you the edges of the guarantee than oversell it. If you ever find something a scan missed, email security@voostack.com. We practice coordinated disclosure and will pull the badge while it's outstanding.

Security FAQ

Is it safe to install listings from AgentStack?

Every version is automatically scanned for prompt injection, secret exfiltration, and dangerous tool calls before it can go live. Only versions that pass list publicly and earn the green verified badge. The full scan report is published on each listing page so you can read what was checked.

What does the green verified badge actually mean?

It means that specific version passed AgentStack’s automated security review at publish time for the listed checks. It is a per-version signal, not a blanket endorsement of the seller or their business logic.

What happens when a listing fails the scan?

A flagged version loses the verified badge and is routed to human review instead of publishing. Findings are recorded with severity levels so a maintainer can see exactly what tripped the scan.

Do you re-scan when a seller ships a new version?

Yes. Every version is scanned on publish. A previously verified listing has to pass again on each update. The badge reflects the version you’re installing, not the listing’s history.

I found a vulnerability in a listing. What do I do?

Email security@voostack.com with the listing slug and details. We practice coordinated disclosure: we’ll triage, work with the seller on a fix, and pull the verified badge while it’s outstanding.

Install what you can actually trust.

Every listing scanned, every report public, one command to install.