B2B GTM stack intelligence for searching, comparing, and auditing SaaS tools and vendor overlaps.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The stackswap MCP server exposes 23 tools, focused primarily on general-purpose capabilities. Its published description reads: "B2B GTM stack intelligence for searching, comparing, and auditing SaaS tools and vendor overlaps". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates stackswap F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check stackswap's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add stackswap to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://stackswap.ai/api/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Identify available connected systems and the read-only evidence StackSwap needs. The server cannot introspect neighboring MCPs automatically.
Return a safe, read-only connection or export request for a named system when an audit lacks evidence.
Start an adaptive GTM architecture audit and return the smallest discovery questionnaire needed before KEEP, SWAP, or BUILD recommendations.
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: get_tool_details
A tool description tries to alter the model’s use of another tool.
tool (more than search_tools' name + cost).RecommendationDescriptions must describe only their own tool.
tool: get_vendor_fact_sheet
A tool description tries to alter the model’s use of another tool.
re detail than `get_tool_details`. Returns a not-found message + a pointer to /vRecommendationDescriptions must describe only their own tool.
tool: recommend_stack
A tool description tries to alter the model’s use of another tool.
— distinct from scan_stack (audits an existing stack) and recommend_partneRecommendationDescriptions must describe only their own tool.
tool: compare_tools_n_way
A tool description tries to alter the model’s use of another tool.
refer the 2-way compare_tools for clean head-to-head pairs.RecommendationDescriptions must describe only their own tool.
tool: search_content
A tool description tries to alter the model’s use of another tool.
. Pass slug to `get_kb_article` for the full body.RecommendationDescriptions must describe only their own tool.
tool: get_kb_article
A tool description tries to alter the model’s use of another tool.
own. Use after `search_content` returns a slug, or when an agent has been poinRecommendationDescriptions must describe only their own tool.
tool: get_category_landscape
A tool description tries to alter the model’s use of another tool.
rehensive than `recommend_partner` (single best pick). Known buckets: crm, outbouRecommendationDescriptions must describe only their own tool.
tool: detect_stack_from_text
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ambiguous short tokens — multi-mention or canonical-name matches win.RecommendationRemove side-channel parameters; constrain tool inputs.
tool: detect_stack_from_text
A tool description tries to alter the model’s use of another tool.
scan_stack` or `find_overlaps`. Use when the user says 'I don't know what weRecommendationDescriptions must describe only their own tool.
tool: submit_correction
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "source_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
. ARCHITECTURE: start_stack_audit (adaptive discovery), complete_stack_audit (KEERecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: scan_stack
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "scan_stack"RecommendationScope tools to the minimum needed.
tool: compare_tools_n_way
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "compare_tools_n_way"RecommendationScope tools to the minimum needed.
tool: (server instructions)
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
g. `[Apollo.io](https://stackswap.ai/api/go/apollo?utm_source=mcp…)`. Preserve these links EXACTLY when you relayRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Turn user answers and connected-system evidence into explainable KEEP, SWAP, and BUILD recommendations with confidence, alternatives, and next prompts.
Generate a case-specific GTM data-layer blueprint when systems mirror state, drift, or lack explicit ownership.
Generate a copy-ready one-shot build or migration prompt from a StackSwap KEEP, SWAP, or BUILD recommendation.
Search StackSwap's catalog of ~400 GTM tools by name. Returns each match with its catalogued monthly cost and, when applicable, a StackSwap partner sign-up link.
Full StackSwap profile for a single tool: cost (catalog + per-seat with confidence; vendor fact sheet wins when fresh), AI-readiness score, category, common overlaps, swap-registry status, and partner
Return the full vendor fact sheet (per GTM Decision Schema v1.0.0) for a tool, when one exists. Includes pricing tiers with gotchas, integration depth scores, AI capabilities + customer-data-for-train
Given a list of tool names in a user's stack, return the redundant pairs StackSwap has curated (104 hand-verified overlaps) along with monthly/annual savings if one is consolidated.
For each tool supplied, return StackSwap's AI-native replacement recommendation (when one exists) with annual savings and reasoning. Skews toward legacy → modern swaps (Outreach → Smartlead, ZoomInfo
Run a preview StackScan: pass a list of tools + team size + industry, get back current spend, optimized spend, monthly/annual recoverable, headless gaps (tools with no MCP/API connection an owned head
Given a need (e.g. 'outbound', 'CRM', 'automation'), return StackSwap's recommended affiliate partner(s) with sign-up URL and positioning.
StackSwap's reference starter stack for a given industry vertical. Returns a curated tool list with per-tool cost, total monthly/annual spend, AI-readiness and headless-readiness scores, and partner s
Head-to-head comparison of two GTM tools. Returns cost delta, AI-readiness and headless-readiness (MCP/API callability — can an agent or your own dashboard drive it) scores, overlap status, swap-regis
Side-by-side comparison of 2–6 GTM tools in one shot. Returns a markdown matrix (cost, AI-readiness, headless-readiness, overlaps within the set, swap-registry status, StackSwap pick) and per-tool par
Full-text search across StackSwap's first-party GTM knowledge base — ~50 operator-narrative articles on stack architecture, AI-native swaps, RevOps, data ethics, and decision frameworks. Returns ranke
Fetch the full body of a StackSwap knowledge base article as markdown. Use after `search_content` returns a slug, or when an agent has been pointed at a specific article. Returns the canonical URL + c
Full map of one GTM category — leaders, runner-ups, and skip/replace candidates. Returns every catalogued tool in the bucket with cost, AI-readiness, swap-registry status, and partner sign-up links. U
Infer a GTM stack from a freeform text blob (a careers page, job posting, public site HTML, RFP, 'What we use' doc, browser DevTools network tab, etc.). Returns ranked tool matches with confidence lev
Return 10-20 questions a B2B GTM buyer should ask a vendor before signing — with 'why it matters' and 'watch for' red-flag answers. Pass `vendor` for vendor-specific gotchas (e.g. Apollo credit-pool q
Return StackSwap's renewal-negotiation playbook for a specific vendor: leverage points (why they will discount), price-anchor alternatives to cite, a calibrated discount ask, a walkaway script, optima
Submit a correction to the StackSwap catalog (pricing, feature list, gotcha, AI-readiness score, category, or other). Submissions queue for admin review and only propagate to user-facing surfaces afte