hunaras-mcp (shaxbozaka/hunaras-mcp) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 24 tools. No publisher has claimed this listing.
MCP server for Hunaras, an AI-native recruiting platform that enables candidates and employers to manage jobs, applications, assessments, and talent sourcing through natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
shaxbozaka
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
apply_to_jobSubmit an application to a job on Hunaras. You must have completed at least one AI interview first.
get_assessment_detailsGet detailed AI assessment report for a specific interview.
get_job_detailsGet full details of a specific job posting on Hunaras.
get_my_applicationsList all your job applications with current statuses.
get_my_appointmentsList your meeting proposals from employers.
get_my_assessmentsList your AI interview assessments with scores and recommendations.
get_my_notificationsList your notifications.
get_my_profileView your Hunaras candidate profile, including assessment scores and visibility status.
get_my_ratingsView ratings you've received from employers.
get_pending_ratingsSee which employers you can rate based on your interactions.
mark_notifications_readMark notifications as read — one specific notification or all at once.
rate_employerRate an employer after your interview or job experience.
respond_to_appointmentRespond to a meeting proposal — accept, reschedule, or reject.
search_jobsSearch for jobs on Hunaras using AI semantic search. Find jobs matching your skills, experience, and interests.
sync_linkedinSync your profile with LinkedIn data.
update_profileUpdate your Hunaras candidate profile. Only provided fields are updated.
update_visibilityToggle your visibility in the Hunaras talent pool. When visible, employers with Pro subscriptions can discover you via search.
create_jobPost a new job listing on Hunaras. Free tier: max 2 active jobs. Pro: unlimited.
get_candidate_profileGet a candidate's full profile, assessment scores, and skills. Counts as a "reveal" (Free tier: 1 reveal, Pro: unlimited).
hunt_candidatesSearch LinkedIn for external candidates to source. Pro subscription required. Results are NOT saved to the database.
invite_candidateRequest Hunaras to reach out to an external candidate (e.g. from LinkedIn). Pro subscription required. Max 20 invites per day.
list_my_jobsList all your job postings with application counts and status.
search_candidatesSearch the Hunaras talent pool for candidates matching a query using AI semantic search. Pro subscription required.
get_market_insightsGet job market insights from Hunaras — active jobs, candidate pool size, job type distribution, and salary ranges.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
HUNARAS_API_KEY"": "hnar_your_api_key_here"HUNARAS_API_URLNo https://hunaras.com API base URL (for self-hosted instances)Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
24/24 tools missing one or more hints — apply_to_job (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_assessment_details (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_job_details (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +21 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
18/24 tool handlers declare input schemas (75%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool handlers catch errors
Only 10/24 tool handlers wrap calls in try/catch (42%)
Wrap each tool handler body in try/catch and return a structured error response.
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/shaxbozaka/hunaras-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check