smartlead-mcp-by-leadmagic
npm
v1.6.2
Published by leadmagic — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
💜 The Premier Model Context Protocol Server for SmartLead's Cold Email Automation Platform - Complete API coverage with 116+ tools for campaign management, lead tracking, smart delivery, and analytics. Beautiful purple-gradient installer, zero-config set
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Untrusted-input tools ([smartlead_fetch_campaign_analytics_by_date_range, smartlead_fetch_all_campaigns_using_lead_id, smartlead_get_all_clients, smartlead_fetch_lead_categories, smartlead_fetch_lead_by_email, smartlead_fetch_all_leads_from_account, smartlead_fetch_leads_from_global_blocklist, smartlead_fetch_lead_message_history, smartlead_download_campaign_data, smartlead_view_download_statistics]) co-exist with external-action tools ([smartlead_add_or_update_campaign_webhook, smartlead_delete_campaign_webhook, smartlead_get_webhooks_publish_summary, smartlead_retrigger_failed_events]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [smartlead_fetch_campaign_analytics_by_date_range, smartlead_fetch_all_campaigns_using_lead_id, smartlead_get_all_clients, smartlead_fetch_lead_catego
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow smartlead_fetch_campaign_analytics_by_date_range → smartlead_add_or_update_campaign_webhook
Each tool and what it can reach — statically extracted from the published source.
smartlead_add_or_update_campaign_webhooknetwork egresssmartlead_delete_campaign_webhooknetwork egresssmartlead_download_campaign_dataingests untrusted inputsmartlead_fetch_all_campaigns_using_lead_idingests untrusted inputsmartlead_fetch_all_leads_from_accountingests untrusted inputsmartlead_fetch_campaign_analytics_by_date_rangeingests untrusted inputsmartlead_fetch_lead_by_emailingests untrusted inputsmartlead_fetch_lead_categoriesingests untrusted inputsmartlead_fetch_lead_message_historyingests untrusted inputsmartlead_fetch_leads_from_global_blocklistingests untrusted inputsmartlead_get_all_clientsingests untrusted inputsmartlead_get_webhooks_publish_summarynetwork egresssmartlead_retrigger_failed_eventsnetwork egresssmartlead_view_download_statisticsingests untrusted inputsmartlead_add_client_to_systemno sensitive capabilitysmartlead_add_email_account_to_campaignno sensitive capabilitysmartlead_add_lead_to_global_blocklistno sensitive capabilitysmartlead_add_leads_to_campaignno sensitive capabilitysmartlead_analytics_campaign_follow_up_reply_rateno sensitive capabilitysmartlead_analytics_campaign_lead_to_reply_timeno sensitive capabilitysmartlead_analytics_campaign_leads_take_for_first_replyno sensitive capabilitysmartlead_analytics_campaign_listno sensitive capabilitysmartlead_analytics_campaign_overall_statsno sensitive capabilitysmartlead_analytics_campaign_response_statsno sensitive capabilitysmartlead_analytics_campaign_status_statsno sensitive capabilitysmartlead_analytics_client_listno sensitive capabilitysmartlead_analytics_client_month_wise_countno sensitive capabilitysmartlead_analytics_client_overall_statsno sensitive capabilitysmartlead_analytics_day_wise_overall_statsno sensitive capabilitysmartlead_analytics_day_wise_positive_reply_statsno sensitive capabilitysmartlead_analytics_lead_category_wise_responseno sensitive capabilitysmartlead_analytics_lead_overall_statsno sensitive capabilitysmartlead_analytics_mailbox_domain_wise_health_metricsno sensitive capabilitysmartlead_analytics_mailbox_name_wise_health_metricsno sensitive capabilitysmartlead_analytics_mailbox_overall_statsno sensitive capabilitysmartlead_analytics_mailbox_provider_wise_overall_performanceno sensitive capabilitysmartlead_analytics_overall_stats_v2no sensitive capabilitysmartlead_analytics_team_board_overall_statsno sensitive capabilitysmartlead_auto_generate_mailboxesno sensitive capabilitysmartlead_create_automated_placement_testno sensitive capabilitysmartlead_create_campaignno sensitive capabilitysmartlead_create_clientno sensitive capabilitysmartlead_create_client_api_keyno sensitive capabilitysmartlead_create_email_accountno sensitive capabilitysmartlead_create_folderno sensitive capabilitysmartlead_create_manual_placement_testno sensitive capabilitysmartlead_delete_campaignno sensitive capabilitysmartlead_delete_client_api_keyno sensitive capabilitysmartlead_delete_folderno sensitive capabilitysmartlead_delete_lead_by_campaignno sensitive capabilitysmartlead_delete_tests_in_bulkno sensitive capabilitysmartlead_export_campaign_datano sensitive capabilitysmartlead_forward_replyno sensitive capabilitysmartlead_get_all_email_accountsno sensitive capabilitysmartlead_get_all_foldersno sensitive capabilitysmartlead_get_blacklistsno sensitive capabilitysmartlead_get_campaignno sensitive capabilitysmartlead_get_campaign_lead_statisticsno sensitive capabilitysmartlead_get_campaign_mailbox_statisticsno sensitive capabilitysmartlead_get_campaign_sequenceno sensitive capabilitysmartlead_get_campaign_sequence_analyticsno sensitive capabilitysmartlead_get_campaign_statisticsno sensitive capabilitysmartlead_get_campaign_statistics_by_date_rangeno sensitive capabilitysmartlead_get_campaign_top_level_analyticsno sensitive capabilitysmartlead_get_campaign_top_level_analytics_by_date_rangeno sensitive capabilitysmartlead_get_campaigns_with_analyticsno sensitive capabilitysmartlead_get_client_api_keysno sensitive capabilitysmartlead_get_dkim_detailsno sensitive capabilitysmartlead_get_domain_blacklistno sensitive capabilitysmartlead_get_domain_listno sensitive capabilitysmartlead_get_email_account_by_idno sensitive capabilitysmartlead_get_email_reply_headersno sensitive capabilitysmartlead_get_folder_by_idno sensitive capabilitysmartlead_get_geo_wise_reportno sensitive capabilitysmartlead_get_ip_blacklist_countno sensitive capabilitysmartlead_get_ip_detailsno sensitive capabilitysmartlead_get_mailbox_countno sensitive capabilitysmartlead_get_mailbox_summaryno sensitive capabilitysmartlead_get_provider_wise_reportno sensitive capabilitysmartlead_get_rdns_reportno sensitive capabilitysmartlead_get_region_wise_provider_idsno sensitive capabilitysmartlead_get_schedule_historyno sensitive capabilitysmartlead_get_sender_account_listno sensitive capabilitysmartlead_get_sender_account_wise_reportno sensitive capabilitysmartlead_get_spam_filter_reportno sensitive capabilitysmartlead_get_spam_test_detailsno sensitive capabilitysmartlead_get_spam_test_email_contentno sensitive capabilitysmartlead_get_spf_detailsno sensitive capabilitysmartlead_get_team_detailsno sensitive capabilitysmartlead_get_vendorsno sensitive capabilitysmartlead_get_warmup_stats_by_email_account_idno sensitive capabilitysmartlead_get_webhooks_by_campaign_idno sensitive capabilitysmartlead_list_all_testsno sensitive capabilitysmartlead_list_campaignsno sensitive capabilitysmartlead_list_email_accounts_per_campaignno sensitive capabilitysmartlead_list_leads_by_campaignno sensitive capabilitysmartlead_pause_lead_by_campaignno sensitive capabilitysmartlead_place_order_for_mailboxesno sensitive capabilitysmartlead_reconnect_failed_email_accountsno sensitive capabilitysmartlead_remove_email_account_from_campaignno sensitive capabilitysmartlead_reply_to_lead_from_master_inboxno sensitive capabilitysmartlead_reset_client_api_keyno sensitive capabilitysmartlead_resume_lead_by_campaignno sensitive capabilitysmartlead_save_campaign_sequenceno sensitive capabilitysmartlead_search_domainno sensitive capabilitysmartlead_stop_automated_testno sensitive capabilitysmartlead_unsubscribe_lead_from_all_campaignsno sensitive capabilitysmartlead_unsubscribe_lead_from_campaignno sensitive capabilitysmartlead_update_campaign_scheduleno sensitive capabilitysmartlead_update_campaign_settingsno sensitive capabilitysmartlead_update_campaign_statusno sensitive capabilitysmartlead_update_email_accountno sensitive capabilitysmartlead_update_email_account_tagno sensitive capabilitysmartlead_update_email_account_warmupno sensitive capabilitysmartlead_update_lead_by_idno sensitive capabilitysmartlead_update_lead_categoryno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.6.2 latest |
A 96/100 | 1 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan smartlead-mcp-by-leadmagic --online
One key, 100+ models — chat with any LLM and generate video, images, speech. Free trial at 370.ai.
Retired compatibility stub for the AgentCanary MCP server. Daily briefs continue on X and Telegram.
A Backstage plugin that provides a chat interface for interacting with the MCP Servers.
Signal-first Bitcoin intelligence: sovereign, hiring & hashrate signals over MCP.
WhatsApp® reminders and rescheduling for Calendly. Public read-only MCP endpoint.
Open Source Generic MCP Client for testing & evaluating mcp servers and agents