LeadFunnel MCP (UcemaRepo/mcpfunnel) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 14 tools. No publisher has claimed this listing.

D
Caution
56/100

LeadFunnel MCP

Ephemeral MCP server that loads Salesforce leads into RAM for natural-language querying via Claude, with PII masking and session purging.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

UcemaRepo

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
3 flows detected: MCP_TOKEN, SF_CLIENT_SECRET. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 2 credentials: MCP_TOKEN, SF_CLIENT_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes14 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

estado_sesion

Indica si hay datos de Salesforce cargados en memoria, cuántos leads y admitidos hay, y cuándo se cargaron. Usar SIEMPRE primero si no se sabe si hay datos disponibles.

cohortes

Lista las cohortes (año + semestre) presentes en los datos cargados, con sus volúmenes. Usar para saber qué períodos se pueden consultar antes de filtrar por uno.

admitidos

Cantidad de admitidos y suma de cápitas, filtrable por cohorte. La cápita es fraccionaria: refleja el arancel neto tras la beca (0,70 = beca del 30%). Usar para preguntas de volumen de admisiones.

admitidos_lista

Devuelve los admitidos individuales de una cohorte, con nombre, estado, cápita y beca. Usar para casos concretos, no para totales — para eso está 'admitidos'.

admitidos_salesforce

Consulta admitidos directamente contra Salesforce, sin usar la sesión en memoria. Más lento, pero refleja el estado actual. Usar cuando importa que el dato esté al minuto o cuando no hay sesión cargada.

embudo

Embudo completo de una cohorte: leads, contactados, convertidos y admitidos, con tasas de conversión entre etapas. Usar para preguntas sobre rendimiento del proceso, no sobre volúmenes sueltos.

resumen

Panorama agregado de los datos cargados. Usar como punto de partida cuando la pregunta es amplia y todavía no se sabe qué cortar.

buscar_leads

Leads filtrados por cohorte, programa o estado. Usar para casos concretos; para volúmenes usar 'embudo'.

agregados

Devuelve conteos de leads agrupados por una o dos dimensiones, calculados en el servidor. USAR ESTA en lugar de 'buscar_leads' para cualquier panel, grafico o pregunta de volumen: devuelve unos pocos KB en vez de traerse decenas de miles de registros individuales. 'buscar_leads' es solo para inspecc

buscar_persona

Busca a una persona en TODOS sus registros de Salesforce en vivo, sin los filtros de la sesion en memoria: incluye posgrado (maestrias, especializaciones, doctorados) y formularios sin semestre, que no forman parte del dataset de las demas herramientas. Devuelve sus formularios y solicitudes clasifi

enviar_panel

Publica un panel en el dashboard embebido en Salesforce Lightning. Si ya existe un panel con esa clave lo REEMPLAZA; si no, lo crea. ANTES de usar esta herramienta llamar a 'listar_paneles': muestra las claves ya existentes, incluidas las que solo estan guardadas en el navegador del usuario. Si el p

listar_paneles

Devuelve las claves, titulos y fechas de TODOS los paneles conocidos, sin el HTML: los que estan en el servidor y tambien los que solo quedaron guardados en el navegador del usuario de una sesion anterior (origen: 'addon'). USAR SIEMPRE antes de enviar un panel: es la unica forma de saber que claves

ver_panel

Devuelve el HTML completo de un panel publicado. Usar antes de modificarlo o fusionarlo, para partir de lo que ya tiene en vez de rehacerlo de cero. Si el servidor se reinicio, el HTML puede no estar disponible aunque el panel siga visible en el navegador del usuario.

borrar_panel

Elimina un panel del dashboard, tanto del servidor como de la copia guardada en el navegador del usuario. El borrado local se aplica cuando la extension sincroniza (al abrir el panel o tocar Actualizar). SOLO usar cuando el usuario lo pide de forma explicita e inequivoca.

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configENMASCARAR_PIItrue (poné false solo si necesitás el dato completo)
🔐 secretMCP_TOKENopenssl rand -hex 32
configORIGENES_PERMITIDOS
configSF_CLIENT_IDconsumer key de la Connected App
🔐 secretSF_CLIENT_SECRETconsumer secret
configSF_DOMAINucema2.my.salesforce.com
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

14/14 tools missing one or more hints — estado_sesion (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); cohortes (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); admitidos (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +11 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

License file

No license file

Add a LICENSE file (MIT, Apache-2.0, etc.).

Tests exist

No test files found

Add tests that exercise each declared tool.

Secrets stay with their owner

3 secrets sent to a request target we could not resolve (MCP_TOKEN → dynamic, SF_CLIENT_SECRET → dynamic) — often a configured endpoint, not necessarily third-party

Audit where credentials are sent. A NOTION_TOKEN should only reach api.notion.com — never a third-party host.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/ucemarepo/mcpfunnel?variant=verified)](https://m8ven.ai/mcp/ucemarepo/mcpfunnel)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: aec035b99e14a6a3c2556c1cbfedb8e41de85b1b
code hash: 38d69b5e3c5efb55bb69cec8c8ca4040f33757cd5537938f1b367b2815804533
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client