MCP servers for marketing automation, SEO, email campaigns and social-media management. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.
Security scan results for the Mimi Seed MCP server.
Security scan results for the Brand MCP server.
Security scan results for the Seo Tools Mcp Xmlstock MCP server.
Security scan results for the Seo Tools Mcp Gsc MCP server.
Security scan results for the Seo Tools Mcp Ywm MCP server.
Security scan results for the Seo Tools Mcp Metrika MCP server.
Security scan results for the Seo Tools Mcp Wordstat MCP server.
Security scan results for the Smart Web MCP server.
Security scan results for the Sfmc MCP server.
Security scan results for the Ebay MCP server.
Security scan results for the Svelte Vitals MCP server.
Security scan results for the Seo Backlinks MCP server.
Security scan results for the Bycrawl MCP server.
Security scan results for the Mailchimp MCP server.
Security scan results for the Creator Research MCP server.
Security scan results for the Altmetric MCP server.
Security scan results for the Saglitzdesign MCP server.
Security scan results for the Opensponsorship Os Admin MCP server.
Security scan results for the Seo MCP server.
Security scan results for the Twitter MCP server.
Security scan results for the Seo Console MCP server.
Security scan results for the Nestr MCP server.
Security scan results for the Retail MCP server.
Security scan results for the Wonda MCP server.
Growth work already runs on APIs: social platforms (X, LinkedIn, Instagram, Facebook, Reddit), email services like Mailchimp, SendGrid and HubSpot, SEO data from Google Search Console, Ahrefs or Semrush, and ad accounts on Google Ads and Meta. A marketing and social MCP server wraps those APIs as structured tools any Model Context Protocol client — Claude, Cursor, other LLM assistants — can call directly. Instead of summarizing dashboard screenshots, the assistant reads and writes campaigns, audiences and analytics itself.
Few categories combine a public voice with private customer data like this one. An over-permissioned or compromised server could publish under your brand handles, mail your whole subscriber base — phishing from a verified sending domain — or exfiltrate contact lists full of personal data. Prompt injection is a live path too: comments, mentions, DMs and inbound email are attacker-controlled text that lands in the assistant's context before any write action fires. That exposure is why every listing in the registry carries an A–F Trust Score from a deterministic open-source engine: it parses the published package, maps declared capabilities into a blast-radius profile, and records each security finding with evidence — identical input always grades identically, and placement cannot be bought. The scoring model is documented under how the algorithm works. Two neighbouring categories overlap here: creator and streaming promotion borders Gaming & Entertainment, while attribution and audience modeling leans on Data Science & ML.
They can be, if treated like any third-party integration with posting rights. Check the Trust Score and read the individual findings, confirm the blast radius stays inside social and email APIs — a posting tool has no business requesting shell or filesystem access — and scope tokens to only the accounts and permissions a workflow needs. Keep inbound social content classified as untrusted input before it triggers any write to a brand channel.