HeadHunter API MCP Server (sargonpiraev/hh-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 167 tools. No publisher has claimed this listing.

D
Caution
56/100

HeadHunter API MCP Server

Enables AI assistants to access and manage HeadHunter job platform data, including vacancies, resumes, negotiations, and employer settings via 167+ tools.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

sargonpiraev

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 17 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// tools this server exposes167 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

confirm-phone-in-resume

Verify phone with a code

get-manager-settings

Manager preferences

get-employer-manager-limits

Daily limit of resume views for current manager

get-employer-addresses

Directory of employer's addresses

get-employer-managers

Directory of employer's managers

add-employer-manager

Adding a manager

get-employer-manager-types

Directory of manager types and privileges

get-manager-accounts

Manager's work accounts

get-applicant-phone-info

Get information about the applicant's phone number

get-address

Get address by ID

edit-employer-manager

Editing a manager

get-employer-manager

Getting information about a manager

delete-employer-manager

Deleting a manager

send-code-for-verify-phone-in-resume

Send verification code to the phone number on CV

authorize

Getting an access-token

invalidate-token

Access token invalidation

get-current-user-info

Info on current authorized user

edit-current-user-info

Editing information on the authorized user

get-locales-for-resume

The list of available resume locales

get-locales

The list of available locales

get-positions-suggestions

Resume position suggestions

get-educational-institutions-suggests

Educational institution name suggestions

get-area-leaves-suggests

Suggestions for all regions that are leaves in the region tree

get-skill-set-suggests

Key skills suggestions

get-vacancy-positions-suggests

Vacancy position suggestions

get-professional-roles-suggests

Professional role suggestions

get-resume-search-keywords-suggests

Suggestions for resume search key words

get-areas-suggests

Suggestions for all regions

get-vacancy-search-keywords

Suggestions for vacancy search key words

get-fields-of-study-suggestions

Specialization suggestions

get-registered-companies-suggests

Organization suggestions

read-resume-profile

Получение схемы резюме-профиля соискателя для резюме

update-resume-profile

Обновление резюме-профиля соискателя

create-resume-profile

Создание резюме-профиля соискателя

get-resume-profile-dictionaries

Получение cловарей резюме-профиля

get-payable-api-actions

Information about active API services for payable methods

get-payable-api-method-access

Checking access to the paid methods

get-saved-vacancy-searches

List of saved vacancy searches

create-saved-vacancy-search

Creating new saved vacancy search

get-vacancy-visitors

Vacancy visitors

get-vacancy

View a vacancy

edit-vacancy

Editing vacancies

get-blacklisted-vacancies

List of hidden vacancies

publish-vacancy

Publishing job vacancies

get-vacancies

Search for vacancies

get-vacancies-related-to-vacancy

Search for vacancies related to a vacancy

get-saved-vacancy-search

Obtaining single saved vacancy search

update-saved-vacancy-search

Updating saved vacancy search

delete-saved-vacancy-search

Deleting saved vacancy search

get-vacancies-similar-to-vacancy

Search for vacancies similar to a vacancy

get-vacancy-upgrade-list

List of vacancy upgrades

get-vacancies-similar-to-resume

Search for vacancies similar to a resume

get-favorite-vacancies

List of favorited vacancies

add-vacancy-to-blacklisted

Adding a vacancy in the blacklist

delete-vacancy-from-blacklisted

Deleting a vacancy from the blacklist

get-active-vacancy-list

View a published vacancy list

get-hidden-vacancies

Deleted vacancy list

add-vacancy-to-hidden

Deleting vacancies

restore-vacancy-from-hidden

Restoring deleted vacancies

get-vacancy-conditions

Conditions for filling out fields when publishing and editing vacancies

get-prolongation-vacancy-info

Information about vacancy prolongation possibility

vacancy-prolongation

Vacancy prolongation

add-vacancy-to-archive

Archiving vacancies

get-pref-negotiations-order

Viewing preferred options for sorting responses

put-pref-negotiations-order

Changing preferred options for sorting responses

add-vacancy-to-favorite

Add a vacancy in favorited

delete-vacancy-from-favorite

Delete a vacancy from favorited

get-available-vacancy-types

Possible options available to current manager for publishing of vacancies

get-vacancy-stats

Vacancy statistics

get-archived-vacancies

Archived vacancy list

get-artifacts-portfolio-conditions

Conditions for uploading portfolio

edit-artifact

Editing an artifact

delete-artifact

Deleting an artifact

load-artifact

Uploading an artifact

get-artifacts-portfolio

Getting portfolios

get-artifact-photos-conditions

Conditions for uploading photos

get-artifact-photos

Getting photos

get-dictionaries

Directories of fields

get-languages

The list of all languages

get-educational-institutions-dictionary

Basic information about educational institutions

get-skills

The list of key skills

get-professional-roles-dictionary

Professional role directory

get-faculties

List of educational institution faculties

get-industries

Industries

change-negotiation-action

Actions with collection response/invitation

apply-to-vacancy

Apply for a vacancy

get-negotiations

Negotiation list

get-negotiations-statistics-manager

Negotiation statistics for the manager

get-active-negotiations

Active negotiation list

get-negotiation-message-templates

Template list for the negotiation

get-collection-negotiations-list

Negotiation list of the collection

invite-applicant-to-vacancy

Invite applicant for a vacancy

get-negotiation-test-results

Get test results attached to the vacancy

edit-negotiation-message

Edit messages in the response

post-negotiations-topics-read

Mark responses as read

hide-active-response

Hide response

get-negotiation-item

Viewing the response/invitation

put-negotiations-collection-to-next-state

Actions with responses/invitations

get-negotiations-statistics-employer

Negotiation statistics for the company

send-negotiation-message

Sending new message

67 further tools are not listed here. The complete surface is in the source.

// known CVEs in dependencies17 high13 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.11.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.11.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.11.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.7.7GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.7.7GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

167/167 tools missing one or more hints — confirm-phone-in-resume (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get-manager-settings (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get-employer-manager-limits (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +164 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

131/167 tool handlers declare input schemas (78%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 17 high severity in production deps — @modelcontextprotocol/sdk@1.11.0 (high), @modelcontextprotocol/sdk@1.11.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/sargonpiraev/hh-mcp-server?variant=verified)](https://m8ven.ai/mcp/sargonpiraev/hh-mcp-server)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: b97203698cc99a6b120b8646a9314018988b9519
code hash: 4ff5f0f3bb3eaf931fecf26358928a9e5a6baf729f8a475ce68374b66484c79f
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client