outreacher (technicallypete/outreacher) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 15 tools. No publisher has claimed this listing.
AI-powered lead qualification system with an MCP server for Claude Desktop, enabling campaign management, lead search, status updates, and CSV import.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
technicallypete
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
get_campaignGet details (id, name, slug) for the current campaign, or a specified one.
list_campaignsList all campaigns for the current organization, or a specified org.
create_campaignCreate a new campaign under the current organization (or a specified org).
rename_campaignRename a campaign. The slug is kept unchanged so existing references stay stable.
search_companiesSearch companies within the current campaign. All filters are optional. Returns up to 50 results.
get_companyGet full details for a single company, including all enriched fields and AI-generated intel.
create_followup_noteAppend a follow-up note to a lead.
debug_envReports which environment variables are set in the MCP server process. Use this to verify configuration.
get_leadGet full details for a single lead, including company info and all notes.
import_csvimport_csv_fileDEPRECATED. Use import_csv for all imports.
import_leadsimport_leads_fileRARELY NEEDED. Only use when the file is physically on the MCP server's filesystem. If the user gave you a file or you can read it yourself, use import_leads with the text content instead. GOJIBERRY FORMAT ONLY.
search_leadsSearch leads by name, email, status, or company. All filters are optional and AND-ed together.
update_lead_statusUpdate the status of a lead.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Next.js is vulnerable to RCE in React flight protocol
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
ANTHROPIC_API_KEYCHAT_LLM_MODELCHAT_LLM_PROVIDERMCP_URLOPENAI_API_KEYRESEND_API_KEYRESEND_FROMDATABASE_URLTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
15/15 tools missing one or more hints — get_campaign (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); list_campaigns (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); create_campaign (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +12 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 3/15 tools referenced in tests (20%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
5 critical, 18 high severity in production deps — next@15.3.0 (critical), next@15.3.0 (critical)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/technicallypete/outreacher)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check