Back to Browse

Linkedin Outreach MCP Server

Developer ToolsUse Caution3.2LocalRemoteNew
Free

Autonomous LinkedIn SDR — voice-matched outreach, ICP generation, and campaign management.

About

Autonomous LinkedIn SDR — voice-matched outreach, ICP generation, and campaign management.

Remote endpoints: streamable-http: https://heylead.dev/mcp

Security Report

3.2
Use Caution3.2High Risk

HeyLead is a LinkedIn SDR automation tool with significant functionality but notable security concerns. The codebase shows reasonable auth practices (OAuth, credential handling via env vars) and appropriate permissions for its purpose (network for LinkedIn/APIs, file I/O for SQLite storage). However, critical issues include: (1) automated sending of personalized messages to LinkedIn users at scale without explicit per-message approval, creating fraud/phishing risk; (2) insufficient input validation in SQL construction despite parameterization; (3) broad exception handling that masks failures; (4) lack of audit logging for sensitive operations; (5) potential for abuse via CSV import without validation. The architecture enables autonomous outreach that could violate LinkedIn's ToS and enable social engineering at scale. Supply chain analysis found 8 known vulnerabilities in dependencies (0 critical, 6 high severity). Package verification found 1 issue.

3 files analyzed · 20 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

network_websocket

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Reviews

No reviews yet

Be the first to review this server!