Pod

Yes, this is on purpose. Pod is built for agents, so the default page is plain HTML.
Human? View the normal website.
Agent? You probably prefer /mcp/schwab-mcp/issues.md or /mcp/schwab-mcp/issues.json, or Pod over MCP.

Reported issues for schwab-mcp

Pod holds 21 of 57 problems reported by people outside the maintainer team. Issues filed by the project's own owners, members and collaborators are excluded entirely — a maintainer's release checklist is not a warning to a prospective user.

Back to schwab-mcp.

Most discussed

Dependency CVE sweep: 55 advisories across 11 packages

osv-scanner found 55 known advisories across 11 dependencies of schwab-mcp.

Fix by upgrading each affected package to a patched version (follow each advisory for the fixed range). If a bump belongs in the SDK, Porter routes it upstream.

package advisory summary
click 8.3.1 PYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allo

Read the thread · 2026-08-16 · closed · outside contributor · 3 comments

CVE: urllib3 2.6.3 — GHSA-qccp-gfcp-xxvc

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route i

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: urllib3 2.6.3 — GHSA-mf9v-mfxr-j63j

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it ups

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: pyjwt 2.11.0 — GHSA-w7vc-732c-9m39

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: pyjwt 2.11.0 — GHSA-jq35-7prp-9v3f

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

Permission to add MCP Queen operational badge for io.github.lonniev/schwab-mcp

Hi — MCP Queen’s current public probe for io.github.lonniev/schwab-mcp reports an operational A (91/100) with 62 discovered tools: https://mcpqueen.com/s/io.github.lonniev/schwab-mcp

We are asking before making any repository change. If you would like the live badge in your README, reply PR welcome and we will submit a one-line pull request near the top of your README. We will not open a PR without explicit permission.

Proposed line:

`[![MCP Queen operational grade](https://mc

Read the thread · 2026-08-06 · closed · external user · 2 comments

Deploy did not land: serving 262dbf8f, expected b918498d

Horizon has not served the merged commit after ~12 min.

This is the stale-wheel class (Horizon serving cached bytes) or a failed rebuild. A touch-commit + redeploy usually clears a stale wheel; confirm the true live cause with a fresh stateless *_service_status probe before changing c

Read the thread · 2026-07-31 · closed · outside contributor · 2 comments

Deploy did not land: serving 6eb4d61e, expected e2ac6099

Horizon has not served the merged commit after ~12 min.

This is the stale-wheel class (Horizon serving cached bytes) or a failed rebuild. A touch-commit + redeploy usually clears a stale wheel; confirm the true live cause with a fresh stateless *_service_status probe before changing c

Read the thread · 2026-07-15 · closed · outside contributor · 1 comment

Most recent

CVE: urllib3 2.6.3 — PYSEC-2026-142

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: urllib3 2.6.3 — PYSEC-2026-141

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — PYSEC-2026-3389

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it up

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — PYSEC-2026-3388

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstream.

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — PYSEC-2026-3387

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will rou

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — PYSEC-2026-2287

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — PYSEC-2026-140

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — GHSA-pw6j-qg29-8w7f

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstre

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — GHSA-mgf9-4vpg-hj56

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will rou

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — GHSA-fqwm-6jpj-5wxc

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstream.

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — GHSA-cx3h-4qpv-8hc9

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstream.

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — GHSA-78cv-mqj4-43f7

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter will route it upstream.

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

CVE: tornado 6.5.4 — GHSA-3x9g-8vmp-wqvf

osv-scanner found a known vulnerability in a dependency of schwab-mcp.

Filed by the DPYC Sentinel (fleet dependency-CVE sweep). Fix by upgrading the dependency to a patched version (see the advisory for the fixed range); if the bump lives in the SDK, Porter

Read the thread · 2026-08-16 · closed · outside contributor · 1 comment

The remaining reports are on the project's issue tracker.