Lead Stampede Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Lead Stampede Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The live backend that powers Lead Stampede Agent Cards. Exposes SMB business data as tools that AI agents can call over HTTP.
An Express server that implements four MCP tools:
| Tool | What it returns |
|---|---|
get_business_profile | Name, description, industry, service area, contact info |
get_services | List of services + pricing summary |
get_availability | Hours + booking URL (or phone/email fallback) |
get_reviews | Review count, average rating, summary |
Each request is authenticated via an X-Agency-API-Key header that maps to a row in the agencies table in Supabase. Clients are scoped to their agency, so one agency can never read another's data.
npm installcp .env.example .envThen edit .env and fill in:
SUPABASE_URL — your project URL (e.g. https://xlhxnlhxeprtzwbyepza.supabase.co)SUPABASE_SERVICE_ROLE_KEY — from Supabase → Project Settings → API → service_role secretPORT — defaults to 3000Never commit `.env` to git. It's already in .gitignore.
npm run devYou should see:
Lead Stampede MCP server listening on port 3000curl http://localhost:3000/health
# → {"status":"ok","timestamp":"..."}curl -H "X-Agency-API-Key: YOUR_AGENCY_API_KEY" \
http://localhost:3000/mcp/toolscurl -X POST \
-H "X-Agency-API-Key: YOUR_AGENCY_API_KEY" \
-H "Content-Type: application/json" \
-d '{"arguments":{"client_slug":"grandinetti-molinar-law"}}' \
http://localhost:3000/mcp/tools/get_business_profileExpected response:
{
"tool": "get_business_profile",
"result": {
"business_name": "Grandinetti & Molinar Law",
"description": "Austin-based law firm founded in 2002...",
"industry": "legal",
...
},
"response_ms": 42
}SUPABASE_URLSUPABASE_SERVICE_ROLE_KEYnpm start.mcp-production.up.railway.app.mcp.leadstampede.io) at it via Railway → Settings → Domains.AI agent → POST /mcp/tools/:name → auth.js → tools.js → supabase.js
↓
analytics.js (fire-and-forget)
↓
mcp_tool_calls tableagentcards.leadstampede.io/{slug}.clients rows in Supabase.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.