Helm Ai MCP Server

@helm-ai/mcp-server npm v0.22.0

Published by @helm-ai — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.

MCP server for Helm — run your business operations (projects, CRM, billing, automations, AI agents) from Claude or any MCP client

Trust grade
A
94/100
Last scanned get badge →
Trust
A · 94/100
Adoption risk for you: the threat score, then adjusted down for blast radius, publisher verification and how much the scan could see. Deterministic; every point is auditable.
Capability
Moderate
Blast radius if it went rogue — what the server’s tools could reach. Independent of trust.
Coverage
Source
How much the scan could actually inspect. Shallow coverage is stated, never hidden.
Share this Trust Score
𝕏 Share LinkedIn Reddit
A Why this grade threat 99 − adoption risk = 94/100

The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.

1. Threat score — 100 − 1.2 = 99. What the published surface and source actually contain:

PointsWhat was foundCategory
−1.2 Hardcoded JSON Web Token in server code MTC-SRC-008 exfiltration

2. Client adoption risk — 99 − 5 = 94. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:

PointsAdoption-risk factor
−3 capability blast radius (moderate) — client exposure if the model is manipulated
−2 publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read

Capability observations and info notes are shown under Findings but never scored. Open any row's finding below for the file, line and evidence behind a deduction.

Findings 1

low Hardcoded JSON Web Token in server code (dist/index.js)MTC-SRC-008

A hardcoded JSON Web Token (a public-by-design (anon/publishable) key — RLS, not secrecy, protects it) appears in `dist/index.js:8`. Verify whether this is a real credential; if so, remove and rotate it.

Evidence: JSON Web Token: eyJh…(redacted)

Fix: Remove the secret, rotate it, and load credentials from the environment or a secret store.

Location: server dist/index.js

Tools 143

Each tool and what it can reach — statically extracted from the published source.

  • helm__agent_send_emailnetwork egress
  • helm__draft_emailnetwork egress
  • helm__add_accountno sensitive capability
  • helm__add_contactno sensitive capability
  • helm__add_dealno sensitive capability
  • helm__add_form_fieldno sensitive capability
  • helm__add_form_stepno sensitive capability
  • helm__add_line_item_from_productno sensitive capability
  • helm__add_pipelineno sensitive capability
  • helm__add_pipeline_stageno sensitive capability
Show 133 more tools ↓
  • helm__add_taskno sensitive capability
  • helm__add_task_commentno sensitive capability
  • helm__archive_productno sensitive capability
  • helm__attach_product_to_accountno sensitive capability
  • helm__attach_product_to_dealno sensitive capability
  • helm__bulk_create_document_foldersno sensitive capability
  • helm__bulk_move_documents_to_folderno sensitive capability
  • helm__cancel_subscriptionno sensitive capability
  • helm__create_agent_objectiveno sensitive capability
  • helm__create_agent_scheduleno sensitive capability
  • helm__create_agent_watchno sensitive capability
  • helm__create_calendar_eventno sensitive capability
  • helm__create_documentno sensitive capability
  • helm__create_document_folderno sensitive capability
  • helm__create_document_pageno sensitive capability
  • helm__create_email_sequenceno sensitive capability
  • helm__create_estimateno sensitive capability
  • helm__create_formno sensitive capability
  • helm__create_invoiceno sensitive capability
  • helm__create_productno sensitive capability
  • helm__create_product_priceno sensitive capability
  • helm__create_projectno sensitive capability
  • helm__create_sequence_emailno sensitive capability
  • helm__create_subscriptionno sensitive capability
  • helm__create_time_entryno sensitive capability
  • helm__create_workflowno sensitive capability
  • helm__delete_agent_objectiveno sensitive capability
  • helm__delete_agent_scheduleno sensitive capability
  • helm__delete_agent_watchno sensitive capability
  • helm__delete_calendar_eventno sensitive capability
  • helm__delete_contactno sensitive capability
  • helm__delete_dealno sensitive capability
  • helm__delete_draftno sensitive capability
  • helm__delete_email_sequenceno sensitive capability
  • helm__delete_form_fieldno sensitive capability
  • helm__delete_form_stepno sensitive capability
  • helm__delete_pipelineno sensitive capability
  • helm__delete_pipeline_stageno sensitive capability
  • helm__delete_product_priceno sensitive capability
  • helm__delete_sequence_emailno sensitive capability
  • helm__delete_time_entryno sensitive capability
  • helm__delete_workflowno sensitive capability
  • helm__detach_product_from_accountno sensitive capability
  • helm__enroll_in_sequenceno sensitive capability
  • helm__execute_workflowno sensitive capability
  • helm__exit_sequence_enrollmentno sensitive capability
  • helm__get_accountno sensitive capability
  • helm__get_accountsno sensitive capability
  • helm__get_agent_objectivesno sensitive capability
  • helm__get_agent_schedulesno sensitive capability
  • helm__get_agent_watchesno sensitive capability
  • helm__get_calendar_eventno sensitive capability
  • helm__get_calendar_eventsno sensitive capability
  • helm__get_contactno sensitive capability
  • helm__get_contactsno sensitive capability
  • helm__get_dealno sensitive capability
  • helm__get_dealsno sensitive capability
  • helm__get_documentno sensitive capability
  • helm__get_document_blocksno sensitive capability
  • helm__get_document_outlineno sensitive capability
  • helm__get_document_pageno sensitive capability
  • helm__get_document_pagesno sensitive capability
  • helm__get_documentsno sensitive capability
  • helm__get_estimatesno sensitive capability
  • helm__get_formno sensitive capability
  • helm__get_form_statsno sensitive capability
  • helm__get_form_submissionsno sensitive capability
  • helm__get_invoiceno sensitive capability
  • helm__get_invoicesno sensitive capability
  • helm__get_paymentsno sensitive capability
  • helm__get_pipelinesno sensitive capability
  • helm__get_productno sensitive capability
  • helm__get_projectsno sensitive capability
  • helm__get_sequenceno sensitive capability
  • helm__get_subscriptionno sensitive capability
  • helm__get_subscription_mrrno sensitive capability
  • helm__get_taskno sensitive capability
  • helm__get_task_commentsno sensitive capability
  • helm__get_tasksno sensitive capability
  • helm__get_time_entriesno sensitive capability
  • helm__get_workflowno sensitive capability
  • helm__get_workflow_executionsno sensitive capability
  • helm__get_workflow_schemano sensitive capability
  • helm__get_workflowsno sensitive capability
  • helm__list_account_productsno sensitive capability
  • helm__list_document_commentsno sensitive capability
  • helm__list_document_foldersno sensitive capability
  • helm__list_draftsno sensitive capability
  • helm__list_email_sequencesno sensitive capability
  • helm__list_formsno sensitive capability
  • helm__list_product_pricesno sensitive capability
  • helm__list_productsno sensitive capability
  • helm__list_sender_identitiesno sensitive capability
  • helm__list_sequence_enrollmentsno sensitive capability
  • helm__list_subscriptionsno sensitive capability
  • helm__log_activityno sensitive capability
  • helm__move_document_to_folderno sensitive capability
  • helm__patch_documentno sensitive capability
  • helm__pause_sequence_enrollmentno sensitive capability
  • helm__pause_subscriptionno sensitive capability
  • helm__record_paymentno sensitive capability
  • helm__refresh_subscriptionno sensitive capability
  • helm__reorder_pipeline_stagesno sensitive capability
  • helm__reorder_sequence_emailsno sensitive capability
  • helm__resolve_document_commentno sensitive capability
  • helm__resume_sequence_enrollmentno sensitive capability
  • helm__resume_subscriptionno sensitive capability
  • helm__set_form_statusno sensitive capability
  • helm__set_sequence_statusno sensitive capability
  • helm__set_workflow_statusno sensitive capability
  • helm__update_accountno sensitive capability
  • helm__update_account_productno sensitive capability
  • helm__update_agent_objectiveno sensitive capability
  • helm__update_agent_scheduleno sensitive capability
  • helm__update_agent_watchno sensitive capability
  • helm__update_calendar_eventno sensitive capability
  • helm__update_contactno sensitive capability
  • helm__update_dealno sensitive capability
  • helm__update_documentno sensitive capability
  • helm__update_draftno sensitive capability
  • helm__update_email_sequenceno sensitive capability
  • helm__update_form_fieldno sensitive capability
  • helm__update_form_stepno sensitive capability
  • helm__update_invoiceno sensitive capability
  • helm__update_pipelineno sensitive capability
  • helm__update_pipeline_stageno sensitive capability
  • helm__update_productno sensitive capability
  • helm__update_product_priceno sensitive capability
  • helm__update_sequence_emailno sensitive capability
  • helm__update_taskno sensitive capability
  • helm__update_time_entryno sensitive capability
  • helm__update_workflowno sensitive capability
  • helm__upload_attachmentno sensitive capability

What this scan could not see

Versions 10

Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.

VersionScoreFindingsEngineScanned
v0.22.0 latest A 94/100 1 1.13.0 2026-09-07
v0.20.0 A 94/100 1 1.13.0 2026-09-01
v0.18.0 A 94/100 1 1.13.0 2026-08-31
v0.17.0 A 94/100 1 1.13.0 2026-08-25
v0.15.0 A 94/100 1 1.12.1 2026-08-24
Show 5 more versions ↓
v0.14.0 A 94/100 1 1.12.1 2026-08-21
v0.12.0 A 94/100 1 1.12.1 2026-08-14
v0.11.0 A 94/100 1 1.12.1 2026-08-10
v0.10.1 A 94/100 1 1.12.1 2026-08-09
v0.9.0 A 94/100 1 1.12.1 2026-08-02

Embed this score

Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.

MCP Trust Score: A · 94/100
Markdown (GitHub README)
[![MCP Trust Score](https://mcptrustchecker.com/registry/helm-ai-mcp-server/badge.svg)](https://mcptrustchecker.com/registry/helm-ai-mcp-server)
HTML
<a href="https://mcptrustchecker.com/registry/helm-ai-mcp-server"><img src="https://mcptrustchecker.com/registry/helm-ai-mcp-server/badge.svg" alt="MCP Trust Score" height="20"></a>
Prefer shields.io styling? Point it at https://mcptrustchecker.com/registry/helm-ai-mcp-server/badge.json via https://img.shields.io/endpoint?url=…

Verify this score yourself

The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.

npx mcptrustchecker scan @helm-ai/mcp-server --online

Use the free API → How scoring works

More in Communication & Collaboration