Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Official MCP server for Leadpipe intent and data APIs.
Use this server to give agents direct access to:
Leadpipe MCP wraps the public Leadpipe intent and data APIs in a local MCP server that agents can use over stdio.
This server is API-key authenticated by default so the full audience workflow, visitor data access, and pixel management workflows are available to agents.
Most users do not need to clone this repo or build from source. The published package is:
npx -y @leadpipe/mcpYou will need:
export LEADPIPE_API_KEY=sk_...Optional advanced override:
export LEADPIPE_BASE_URL=https://api.aws53.cloudLEADPIPE_BASE_URL only needs to change if you are pointing at a non-default environment.
Add this to your Claude Desktop MCP config:
{
"mcpServers": {
"leadpipe": {
"command": "npx",
"args": ["-y", "@leadpipe/mcp"],
"env": {
"LEADPIPE_API_KEY": "sk_..."
}
}
}
}Add this to ~/.cursor/mcp.json:
{
"mcpServers": {
"leadpipe": {
"command": "npx",
"args": ["-y", "@leadpipe/mcp"],
"env": {
"LEADPIPE_API_KEY": "sk_..."
}
}
}
}Add the server with the Codex CLI:
codex mcp add leadpipe --env LEADPIPE_API_KEY=sk_... -- npx -y @leadpipe/mcpThen confirm it is configured:
codex mcp listIf you just want to verify the package runs:
npx -y @leadpipe/mcpFor local development or repo hacking:
npm install
npm run build
node dist/index.jsFor iterative local development:
npm run devLocal source build MCP config:
{
"mcpServers": {
"leadpipe": {
"command": "node",
"args": ["/absolute/path/to/mcp/dist/index.js"],
"env": {
"LEADPIPE_API_KEY": "sk_..."
}
}
}
}list_topicsget_topic_facetssearch_topicsget_topic_trendcompare_topicsget_topic_moversanalyze_website_topicsget_audience_filterspreview_audiencequery_audiencelist_audiencesget_audiencecreate_audienceupdate_audiencedelete_audienceget_audience_statusget_audience_resultslist_audience_runsget_audience_statsexport_audiencequery_visitor_datalist_pixelscreate_pixelupdate_pixelget_account_statusdiscover-audience-topicsoperate-saved-audienceinvestigate-visitor-dataSee examples/prompt-examples.md for copy-paste prompts that work well with this MCP server.
Good starting prompts:
<audience-id>. If it is ready, export it and give me the download URL."example.com over the last 30 days and tell me whether our tracking setup looks healthy."For more structured operational flows, see:
leadpipe://docs/authleadpipe://docs/workflowsleadpipe://docs/data-apiget_account_statusquery_visitor_datalist_pixels / create_pixelupdate_pixelnpm run typecheck
npm run buildMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.