Mcp Poc — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Poc (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that turns a recruitment database into an AI-queryable pipeline. Instead of clicking through dashboards and writing filters, you ask Claude plain-English questions and it searches contractors, builds shortlists, drafts outreach, and books engagements — all through structured tool calls against a live PostgreSQL database. Built to demonstrate how service businesses can make their methodology accessible through Claude. Built by HelloCrossman.
19 MCP tools that cover the full contractor recruitment lifecycle. Connect Claude to your database and ask:
Claude calls the right tools, chains them together, and handles the workflow end-to-end.
See the /screenshots directory for examples of Claude Desktop interacting with the server.
Claude Desktop / Claude.ai
│
▼
MCP Server (Express.js)
├── Streamable HTTP POST /mcp
└── SSE GET /sse
│
▼
PostgreSQL
├── contractors (50 enriched profiles)
├── jobs (10 open roles)
├── shortlists + shortlist_items
├── engagements
└── outreach_draftsStack: TypeScript · Node.js 20 · @modelcontextprotocol/sdk · Express · PostgreSQL · PDFKit · Google OAuth 2.1 · Vitest
| Tool | What it does | Key parameters |
|---|---|---|
search_contractors | Search by location, skills, certs, rate, clearance, free text | query, location, availability, certifications, skills, sector, max_rate, min_experience, clearance, limit |
get_contractor | Full profile by ID | id |
get_contractor_cv | Complete CV: work history, education, projects, languages | id |
list_jobs | List open roles with filters | status, sector, urgency, location, limit |
get_job | Full job details by ID | id |
find_matching_contractors | Auto-match contractors to a job's requirements | job_id, limit |
update_job_status | Move job through pipeline stages | id, status |
create_shortlist | Create a named shortlist for a role | name, description, role_title, client_name |
add_to_shortlist | Add contractor to shortlist with notes | shortlist_id, contractor_id, notes |
get_shortlist | View shortlist with all candidates | id |
list_shortlists | List all shortlists | status |
update_candidate_status | Track candidate through pipeline | shortlist_id, contractor_id, status |
draft_outreach | Save a personalised outreach email | contractor_id, shortlist_id, subject, body |
list_outreach | View outreach drafts | contractor_id, status |
book_contractor | Book contractor for a role | contractor_id, role_title, client_name, start_date, end_date, agreed_rate |
get_pipeline | Full recruitment pipeline overview | — |
generate_contractor_pdf | PDF report with full contractor CV | contractor_id |
generate_shortlist_pdf | PDF report of a shortlist | shortlist_id |
generate_comparison_pdf | Side-by-side PDF comparing 2–10 contractors | contractor_ids |
# 1. Clone the repo
git clone https://github.com/hellocrossman/mcp-recruitment-pipeline.git
cd mcp-recruitment-pipeline
# 2. Install dependencies
npm install
# 3. Set up PostgreSQL
# Create a database and note the connection string.
# On Replit, this is handled automatically.
# 4. Configure environment variables
cp .env.example .env
# Edit .env with your DATABASE_URL and auth settings
# 5. Run database migrations
npm run migrate
# 6. Seed the database with sample data
npm run seed
# 7. Start the server
npm run devThe server starts on port 5000 with 50 contractor profiles and 10 open roles.
Add to your Claude Desktop MCP config (claude_desktop_config.json):
{
"mcpServers": {
"recruitment": {
"url": "https://your-deployment-url/sse",
"headers": {
"Authorization": "Bearer YOUR_MCP_API_KEY"
}
}
}
}In Claude.ai settings, add a custom MCP connector:
https://your-deployment-url/mcpMCP_API_KEY)This is a proof of concept — the structure is designed to be forked and adapted to any service domain. Key steps:
contractors with your domain entities (candidates, properties, products, inventory). Update the migration files in migrations/ and the schema in src/db.ts.src/seed.ts with realistic records for your domain. The current 50 contractor profiles show the level of enrichment that makes AI interactions useful.src/tools.ts maps to one MCP tool. Rename them, change the query logic, add new tools. The pattern is always: validate input → build parameterised query → return structured result.src/
index.ts Entry point — Express server, 19 MCP tool registrations
types.ts Shared TypeScript interfaces and constants
db.ts Database pool and schema initialization
auth.ts Google OAuth + API key middleware
tools.ts Query builders for all 16 data tools
pdf.ts PDF report generators (contractor CV, shortlist, comparison)
seed.ts 50 contractor profiles + 10 sample jobs
migrations/ Numbered SQL migration files
scripts/ Utility scripts (migrate runner)
__tests__/ 111 tests (unit + integration)| Variable | Required | Description |
|---|---|---|
DATABASE_URL | Yes | PostgreSQL connection string |
PORT | No | Server port (default: 5000) |
GOOGLE_CLIENT_ID | No | Google OAuth client ID for token verification |
MCP_API_KEY | No | API key for direct access without OAuth |
At least one auth method (GOOGLE_CLIENT_ID or MCP_API_KEY) is recommended for production.
npm test # Run all 111 tests
npm run test:coverage # Run with coverage report
npm run test:watch # Watch mode during development
npm run lint # Type-check without emittingCoverage: 100% on tool handlers, 90%+ on auth, 95%+ on database layer. Tests include unit tests with mocked DB, integration tests against real PostgreSQL, and edge cases for invalid inputs and SQL injection attempts.
MIT — see LICENSE.
[HelloCrossman](https://hellocrossman.com) — We turn service businesses into agentic software.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.