64
/ 100
3 days ago
glama

retailcrm-mcp

Production-grade MCP server for RetailCRM e-commerce CRM. Provides 39 tools and 2 prompt skills to manage orders, customers, products, inventory, payments, tasks, references, and analytics via API v5.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: RETAILCRM_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.13.3GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.13.3GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.13.3GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configHOSTPORT / No HTTP server bind (default 3000 / 127.0.0.1, --http mode only)
configPORT/ HOST No HTTP server bind (default 3000 / 127.0.0.1, --http mode only)
🔐 secretRETAILCRM_API_KEYYes API key (sent via the X-API-KEY header)
configRETAILCRM_DNS_PROTECTIONNo off to disable DNS-rebinding protection (HTTP mode)
configRETAILCRM_DOMAINYes Your RetailCRM domain (e.g. yourstore.retailcrm.ru)
configRETAILCRM_HTTP_ALLOWED_HOSTSNo Comma-separated allowed Host values for DNS-rebinding protection
configRETAILCRM_RATE_LIMITNo Client-side requests/second cap (RetailCRM allows ~10/s)
configRETAILCRM_READONLYNo 1 to expose only read tools (hide create/update/merge/delete)
configRETAILCRM_URLis still accepted as a fallback for RETAILCRM_DOMAIN.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/theyahia-retailcrm-mcp-1ee4z6)](https://m8ven.ai/mcp/theyahia-retailcrm-mcp-1ee4z6)
commit: 55a5ebf38a38e9559c5c298b616e4a0d49be167a
code hash: e82b1a829429539807d9141392e6c7ee66e2af92f4b2775497f80c9b6c02745f
verified: 7/28/2026, 9:10:35 AM
view raw JSON →