Forge MCP Server (SalesforgeAI/forge-mcp) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 149 tools. No publisher has claimed this listing.
Connects AI assistants to the complete Salesforge product suite, enabling management of workspaces, contacts, sequences, mailboxes, domains, and more across multiple sales tools.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
SalesforgeAI
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
list_sequence_branchesList all branches in a multichannel sequence
list_contactsList contacts in a workspace with optional filters (tags, validation status, pagination)
create_contactCreate a single contact in a workspace
bulk_create_contactsCreate up to 100 contacts in a workspace at once
get_contactGet a contact by ID
list_custom_variablesList all custom variables in a workspace
add_dnc_entriesAdd multiple Do-Not-Contact entries to a workspace (up to 1000). Pass email addresses or domains as plain strings.
enroll_contactsEnroll contacts into a multichannel sequence using filters (lead IDs, tags, ESPs, validation status)
remove_enrollmentsRemove contacts from a multichannel sequence
get_meValidate API key and get current account info (accountId, apiKeyName)
infraforge_get_credit_balanceGet InfraForge credit balance
infraforge_create_credit_balanceCreate/top up InfraForge credit balance
infraforge_update_credit_balanceUpdate InfraForge credit balance settings
infraforge_check_domain_availabilityCheck domain availability in InfraForge
infraforge_check_domain_availability_bulkCheck availability of multiple domains in InfraForge
infraforge_list_domainsList InfraForge domains
infraforge_purchase_domainsPurchase domains in InfraForge
infraforge_get_domain_dnsGet DNS records for an InfraForge domain
infraforge_update_domain_dnsUpdate DNS records for an InfraForge domain
infraforge_bulk_dns_updateBulk update DNS across InfraForge domains
infraforge_get_alternative_domainsGenerate alternative domain suggestions
infraforge_enable_autorenewEnable auto-renewal for an InfraForge domain
infraforge_disable_autorenewDisable auto-renewal for an InfraForge domain
infraforge_list_mailboxesList InfraForge mailboxes
infraforge_get_mailboxGet an InfraForge mailbox by ID
infraforge_update_mailboxUpdate an InfraForge mailbox
infraforge_purchase_mailboxesPurchase new mailboxes in InfraForge
infraforge_delete_mailboxDelete an InfraForge mailbox
infraforge_generate_mailboxesGenerate mailbox configurations for InfraForge
infraforge_bulk_forward_mailboxesBulk set forwarding for InfraForge mailboxes
infraforge_list_workspacesList InfraForge workspaces
infraforge_create_workspaceCreate an InfraForge workspace
infraforge_update_workspaceUpdate an InfraForge workspace
infraforge_delete_workspaceDelete an InfraForge workspace
infraforge_export_mailboxesExport InfraForge mailboxes
infraforge_export_to_salesforgeExport InfraForge mailboxes to Salesforge
leadsforge_enrich_emailsFind email addresses. Async — returns a jobID; poll leadsforge_get_enrichment_job and fetch results with leadsforge_get_enrichment_results.
leadsforge_enrich_phonesFind phone numbers. Async — returns a jobID; poll leadsforge_get_enrichment_job and fetch results with leadsforge_get_enrichment_results.
leadsforge_enrich_linkedinFind LinkedIn profiles. Async — returns a jobID; poll leadsforge_get_enrichment_job and fetch results with leadsforge_get_enrichment_results.
leadsforge_get_enrichment_jobGet status of a LeadsForge enrichment job
leadsforge_get_enrichment_resultsGet results of a LeadsForge enrichment job
leadsforge_search_lookalikesSearch for companies similar to provided domains
leadsforge_get_seniority_filtersGet available seniority filter values for LeadsForge
leadsforge_get_department_filtersGet available department filter values for LeadsForge
leadsforge_get_employee_range_filtersGet available employee range filter values for LeadsForge
leadsforge_get_balanceGet LeadsForge credit balance
leadsforge_searchSearch for leads in LeadsForge. Returns lead previews only — emails/LinkedIn require a follow-up call to leadsforge_enrich_emails / leadsforge_enrich_linkedin with the returned person IDs. For pagination, pass the cursor from the previous response as `cursor` — when cursor is set, filters are ignore…
list_mailboxesList mailboxes in a workspace with optional filters
get_mailboxGet mailbox details by ID
download_email_attachmentsDownload all attachments from an email as a ZIP (returns content-type and base64-encoded data)
download_email_attachmentDownload a single email attachment by content ID (returns content-type and base64-encoded data)
reply_to_emailmailforge_list_domainsList domains in MailForge, optionally filtered by status
mailforge_purchase_domainsPurchase domains in MailForge
mailforge_check_domain_availabilityCheck if a domain is available for purchase in MailForge
mailforge_check_domain_availability_bulkCheck availability of multiple domains in MailForge (max 100)
mailforge_transfer_domainsTransfer domains into MailForge
mailforge_get_domain_dnsGet DNS records for a MailForge domain
mailforge_update_domain_dnsUpdate DNS records for a MailForge domain
mailforge_bulk_dns_updateBulk update DNS across multiple MailForge domains
mailforge_enable_autorenewEnable auto-renewal for a MailForge domain
mailforge_disable_autorenewDisable auto-renewal for a MailForge domain
mailforge_bulk_enable_autorenewEnable auto-renewal for multiple MailForge domains
mailforge_bulk_disable_autorenewDisable auto-renewal for multiple MailForge domains
mailforge_update_domain_forwardsUpdate forwarding settings for MailForge domains
mailforge_purchase_domain_maskingPurchase domain masking for MailForge domains
mailforge_delete_domain_maskingDelete domain masking for a MailForge domain
mailforge_list_mailboxesList all mailboxes in MailForge
mailforge_get_mailboxGet a specific MailForge mailbox by ID
mailforge_purchase_mailboxesPurchase mailboxes in MailForge
mailforge_update_mailboxUpdate a MailForge mailbox
mailforge_delete_mailboxDelete a MailForge mailbox
mailforge_bulk_forward_mailboxesSet forwarding email for multiple MailForge mailboxes
mailforge_adjust_topup_amountAdjust the mailbox top-up amount in MailForge
mailforge_list_workspacesList all workspaces in MailForge
mailforge_create_workspaceCreate a workspace in MailForge
mailforge_update_workspaceUpdate a MailForge workspace name
mailforge_delete_workspaceDelete a MailForge workspace
list_sequence_nodesList all nodes (workflow steps) in a multichannel sequence
get_sequence_nodeGet a specific node by ID
create_action_nodeCreate an action node (email, LinkedIn message, connection request, etc.) in a multichannel sequence. IMPORTANT: branchId is required — get it from list_sequence_branches or list_sequence_nodes (branches array). Delay is set via waitDays (integer, days to wait before executing this node).
update_action_nodeUpdate an existing action node's message content or delay. Delay is set via wait_in_minutes (integer minutes). To update message copy, pass variants with metadata containing subject and message.
create_condition_nodeCreate a condition node (branching logic) in a multichannel sequence. IMPORTANT: branchId is required.
delete_sequence_nodeDelete a node from a multichannel sequence
primeforge_list_domainsList domains in PrimeForge
primeforge_get_domainGet a PrimeForge domain by ID
primeforge_search_domainsSearch available domains for purchase in PrimeForge
primeforge_buy_domainsPurchase domains in PrimeForge
primeforge_delete_domainDelete a PrimeForge domain
primeforge_get_domain_dnsGet DNS records for a PrimeForge domain
primeforge_bulk_dns_updateBulk update DNS records across PrimeForge domains
primeforge_create_mailboxes_for_domainCreate mailboxes for a PrimeForge domain
primeforge_list_mailboxesList PrimeForge mailboxes
primeforge_get_mailboxGet a PrimeForge mailbox by ID
primeforge_update_mailboxUpdate a PrimeForge mailbox
primeforge_delete_mailboxDelete a PrimeForge mailbox
primeforge_list_prewarmed_mailboxesList available pre-warmed mailboxes for purchase
primeforge_purchase_prewarmed_mailboxesPurchase pre-warmed mailboxes
primeforge_list_workspacesList PrimeForge workspaces
primeforge_create_workspaceCreate a PrimeForge workspace
49 further tools are not listed here. The complete surface is in the source.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
INFRAFORGE_API_KEYLEADSFORGE_API_KEYMAILFORGE_API_KEYPRIMEFORGE_API_KEYSALESFORGE_API_KEYPORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
149/149 tools missing one or more hints — list_sequence_branches (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_contacts (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); create_contact (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +146 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
133/149 tool handlers declare input schemas (89%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool handlers catch errors
Only 0/149 tool handlers wrap calls in try/catch (0%)
Wrap each tool handler body in try/catch and return a structured error response.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/salesforgeai/forge-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check