HeadHunter API MCP Server (sargonpiraev/hh-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 167 tools. No publisher has claimed this listing.
Enables AI assistants to access and manage HeadHunter job platform data, including vacancies, resumes, negotiations, and employer settings via 167+ tools.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
sargonpiraev
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
confirm-phone-in-resumeVerify phone with a code
get-manager-settingsManager preferences
get-employer-manager-limitsDaily limit of resume views for current manager
get-employer-addressesDirectory of employer's addresses
get-employer-managersDirectory of employer's managers
add-employer-managerAdding a manager
get-employer-manager-typesDirectory of manager types and privileges
get-manager-accountsManager's work accounts
get-applicant-phone-infoGet information about the applicant's phone number
get-addressGet address by ID
edit-employer-managerEditing a manager
get-employer-managerGetting information about a manager
delete-employer-managerDeleting a manager
send-code-for-verify-phone-in-resumeSend verification code to the phone number on CV
authorizeGetting an access-token
invalidate-tokenAccess token invalidation
get-current-user-infoInfo on current authorized user
edit-current-user-infoEditing information on the authorized user
get-locales-for-resumeThe list of available resume locales
get-localesThe list of available locales
get-positions-suggestionsResume position suggestions
get-educational-institutions-suggestsEducational institution name suggestions
get-area-leaves-suggestsSuggestions for all regions that are leaves in the region tree
get-skill-set-suggestsKey skills suggestions
get-vacancy-positions-suggestsVacancy position suggestions
get-professional-roles-suggestsProfessional role suggestions
get-resume-search-keywords-suggestsSuggestions for resume search key words
get-areas-suggestsSuggestions for all regions
get-vacancy-search-keywordsSuggestions for vacancy search key words
get-fields-of-study-suggestionsSpecialization suggestions
get-registered-companies-suggestsOrganization suggestions
read-resume-profileПолучение схемы резюме-профиля соискателя для резюме
update-resume-profileОбновление резюме-профиля соискателя
create-resume-profileСоздание резюме-профиля соискателя
get-resume-profile-dictionariesПолучение cловарей резюме-профиля
get-payable-api-actionsInformation about active API services for payable methods
get-payable-api-method-accessChecking access to the paid methods
get-saved-vacancy-searchesList of saved vacancy searches
create-saved-vacancy-searchCreating new saved vacancy search
get-vacancy-visitorsVacancy visitors
get-vacancyView a vacancy
edit-vacancyEditing vacancies
get-blacklisted-vacanciesList of hidden vacancies
publish-vacancyPublishing job vacancies
get-vacanciesSearch for vacancies
get-vacancies-related-to-vacancySearch for vacancies related to a vacancy
get-saved-vacancy-searchObtaining single saved vacancy search
update-saved-vacancy-searchUpdating saved vacancy search
delete-saved-vacancy-searchDeleting saved vacancy search
get-vacancies-similar-to-vacancySearch for vacancies similar to a vacancy
get-vacancy-upgrade-listList of vacancy upgrades
get-vacancies-similar-to-resumeSearch for vacancies similar to a resume
get-favorite-vacanciesList of favorited vacancies
add-vacancy-to-blacklistedAdding a vacancy in the blacklist
delete-vacancy-from-blacklistedDeleting a vacancy from the blacklist
get-active-vacancy-listView a published vacancy list
get-hidden-vacanciesDeleted vacancy list
add-vacancy-to-hiddenDeleting vacancies
restore-vacancy-from-hiddenRestoring deleted vacancies
get-vacancy-conditionsConditions for filling out fields when publishing and editing vacancies
get-prolongation-vacancy-infoInformation about vacancy prolongation possibility
vacancy-prolongationVacancy prolongation
add-vacancy-to-archiveArchiving vacancies
get-pref-negotiations-orderViewing preferred options for sorting responses
put-pref-negotiations-orderChanging preferred options for sorting responses
add-vacancy-to-favoriteAdd a vacancy in favorited
delete-vacancy-from-favoriteDelete a vacancy from favorited
get-available-vacancy-typesPossible options available to current manager for publishing of vacancies
get-vacancy-statsVacancy statistics
get-archived-vacanciesArchived vacancy list
get-artifacts-portfolio-conditionsConditions for uploading portfolio
edit-artifactEditing an artifact
delete-artifactDeleting an artifact
load-artifactUploading an artifact
get-artifacts-portfolioGetting portfolios
get-artifact-photos-conditionsConditions for uploading photos
get-artifact-photosGetting photos
get-dictionariesDirectories of fields
get-languagesThe list of all languages
get-educational-institutions-dictionaryBasic information about educational institutions
get-skillsThe list of key skills
get-professional-roles-dictionaryProfessional role directory
get-facultiesList of educational institution faculties
get-industriesIndustries
change-negotiation-actionActions with collection response/invitation
apply-to-vacancyApply for a vacancy
get-negotiationsNegotiation list
get-negotiations-statistics-managerNegotiation statistics for the manager
get-active-negotiationsActive negotiation list
get-negotiation-message-templatesTemplate list for the negotiation
get-collection-negotiations-listNegotiation list of the collection
invite-applicant-to-vacancyInvite applicant for a vacancy
get-negotiation-test-resultsGet test results attached to the vacancy
edit-negotiation-messageEdit messages in the response
post-negotiations-topics-readMark responses as read
hide-active-responseHide response
get-negotiation-itemViewing the response/invitation
put-negotiations-collection-to-next-stateActions with responses/invitations
get-negotiations-statistics-employerNegotiation statistics for the company
send-negotiation-messageSending new message
67 further tools are not listed here. The complete surface is in the source.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
167/167 tools missing one or more hints — confirm-phone-in-resume (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get-manager-settings (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get-employer-manager-limits (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +164 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
131/167 tool handlers declare input schemas (78%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 17 high severity in production deps — @modelcontextprotocol/sdk@1.11.0 (high), @modelcontextprotocol/sdk@1.11.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/sargonpiraev/hh-mcp-server)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check