Plain.com MCP Server (tellahq/plain-mcp) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 78 tools. No publisher has claimed this listing.

D
Caution
56/100

Plain.com MCP Server

Provides comprehensive access to the Plain.com API with over 70 tools for managing support threads, customers, and help centers. It enables users to handle communications, automate support workflows, and manage documentation directly through natural language.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

tellahq

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 1 credential: PLAIN_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes78 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

list_help_centers

List all help centers in the workspace

get_help_center

Get details of a specific help center

create_help_center

Create a new help center

update_help_center

Update an existing help center

delete_help_center

Delete a help center

update_help_center_custom_domain

Set a custom domain for a help center

verify_help_center_custom_domain

Verify DNS ownership of a custom domain for a help center

list_help_center_articles

List articles in a help center

get_help_center_article

Get a specific help center article by ID

get_help_center_article_by_slug

Get a help center article by its URL slug

upsert_help_center_article

Create or update a help center article

delete_help_center_article

Delete a help center article

generate_help_center_article

Auto-generate a help center article from a support thread using AI

list_help_center_article_groups

List article groups (categories) in a help center

get_help_center_article_group

Get a specific article group by ID

create_help_center_article_group

Create a new article group (category) in a help center

update_help_center_article_group

Update an article group

delete_help_center_article_group

Delete an article group

get_help_center_index

Get the navigation index/structure of a help center

update_help_center_index

Update the navigation index/structure of a help center

create_knowledge_source

Create a knowledge source for AI to reference

delete_knowledge_source

Delete a knowledge source

upsert_customer

Create or update a customer

delete_customer

Delete a customer

mark_customer_as_spam

Mark a customer as spam

unmark_customer_as_spam

Remove spam marking from a customer

get_customer

Get detailed customer information by ID

create_customer_event

Create a custom event on a customer timeline

create_thread

Create a new support thread for a customer

assign_thread

Assign a thread to a user

unassign_thread

Remove assignment from a thread

change_thread_priority

Change the priority of a thread

update_thread_title

Update the title of a thread

delete_thread

Permanently delete a thread

create_thread_event

Create a custom event on a thread timeline

list_label_types

List all available label types

create_label_type

Create a new label type

add_labels_to_thread

Add labels to a thread

remove_labels_from_thread

Remove labels from a thread

upsert_company

Create or update a company

delete_company

Delete a company

upsert_tenant

Create or update a tenant

delete_tenant

Delete a tenant

list_snippets

List all snippets (canned responses)

create_snippet

Create a new snippet (canned response)

update_snippet

Update an existing snippet

delete_snippet

Delete a snippet

list_webhooks

List all webhook targets

create_webhook

Create a new webhook target

update_webhook

Update a webhook target

delete_webhook

Delete a webhook target

list_users

List workspace users

get_workspace

Get current workspace information

send_email

Send a new email to a customer (starts a new thread)

send_chat

Send a chat message to a customer

list_autoresponders

List all autoresponders

create_autoresponder

Create a new autoresponder

delete_autoresponder

Delete an autoresponder

list_tiers

List all support tiers

create_tier

Create a new support tier

delete_tier

Delete a support tier

list_customer_groups

List all customer groups

create_customer_group

Create a new customer group

add_customer_to_groups

Add a customer to one or more groups

remove_customer_from_groups

Remove a customer from one or more groups

list_thread_field_schemas

List all custom thread field schemas

upsert_thread_field

Set a custom field value on a thread

delete_note

Delete an internal note from a thread

list_threads

List support threads with optional filters. Note: statusDetail (CREATED, NEW_REPLY, etc.) is not available in list results - use get_thread for that.

get_thread

Get detailed thread information including conversation timeline

search_customers

Search for customers by email

get_queue_stats

Get a quick overview of the support queue with counts by status

reply_to_thread

Reply to a support thread. The reply will be sent to the customer via the original channel (email, chat, etc.)

mark_thread_done

Mark a support thread as done/resolved

mark_thread_todo

Mark a support thread as todo (re-open it)

change_thread_status_to_todo

Change thread status to Todo with optional status detail. Use this instead of mark_thread_todo when you need to set a specific status detail.

snooze_thread

Snooze a support thread. Use WAITING_FOR_CUSTOMER (no duration) to snooze until customer replies, or WAITING_FOR_DURATION with duration_seconds for time-based snooze.

create_note

Create an internal note on a thread (not visible to customer)

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.23.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.23.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.23.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretPLAIN_API_KEY"": "your-api-key"
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

78/78 tools missing one or more hints — list_help_centers (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_help_center (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); create_help_center (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +75 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

70/78 tool handlers declare input schemas (90%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 0/78 tool handlers wrap calls in try/catch (0%)

Wrap each tool handler body in try/catch and return a structured error response.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.23.0 (high), @modelcontextprotocol/sdk@1.23.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 7 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/tellahq/plain-mcp?variant=verified)](https://m8ven.ai/mcp/tellahq/plain-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: f5129713883c7415ac64254dbe4d38ea6b9dc5ba
code hash: 1c02e09db4853e0a9e013c8cd12016f920988e5d3d14fb32c3d95426da22b7bf
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client