# io.github.Autostackup/hr (npm · @autostackup/hr)

Candidate screening, offer letters, onboarding, interview kits & performance reviews for Claude.

- Trust score: 68/100 (medium)
- Change this week: +25
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-05

## Components

- npm · `@autostackup/hr`: 68/100 (this document), [markdown](https://verifymcp.io/servers/autostackup-hr/autostackup-hr.md), [page](https://verifymcp.io/servers/autostackup-hr/autostackup-hr)

## Channel facts

- Registry: `npm`
- Package: `@autostackup/hr`
- Version: `0.1.1`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-05.

- **Supply Chain Security**: 87/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (96 of 100), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (96 of 100), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 57 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 64/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1130 tokens (~226/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 33/100
  - Stability observed for 10 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 99/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 98% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add autostackup-hr -- npx -y @autostackup/hr
```

### Codex

```bash
codex mcp add autostackup-hr -- npx -y @autostackup/hr
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "autostackup-hr": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@autostackup/hr"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add autostackup-hr --command npx --arg -y --arg @autostackup/hr
```

### Hermes

```yaml
mcp_servers:
  autostackup-hr:
    command: "npx"
    args: ["-y", "@autostackup/hr"]
```

### Other

```json
{
  "mcpServers": {
    "autostackup-hr": {
      "command": "npx",
      "args": [
        "-y",
        "@autostackup/hr"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-05 (score 68, +2)

- [security improvement] CVE-2026-69207 no longer affects this package
- [security improvement] Known CVEs: fail → partial

### 2026-08-04 (score 66, −1)

- [security regression] CVE-2026-69207 affects this package: medium
- [security regression] Known CVEs: partial → fail

### 2026-08-03 (score 67, +4)

- [functional improvement] Stability: unverified → 0.27

### 2026-08-02 (score 63, +45)

- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] License: unverified → pass
- [functional improvement] Schema quality: unverified → excellent
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional] Licence: MIT

### 2026-07-31 (score 18, +12)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 6, −37)

- [security regression] Malware scan: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-07-27 (score 43)

First indexed and scored.

## MCP tools (5)

### `screen_candidate` (~221 tokens)

Score a candidate against a job's required skills, experience, and must-haves. Returns a tier (A/B/C/D), skill gap analysis, salary fit, and exact recommended next step. Built on structured competency scoring used by top People teams.

Input parameters:

- `background` (string, required): Brief background — education, companies, notable achievements
- `budgetCeiling` (number): Maximum budget for the role in USD
- `candidateName` (string, required): Full name of the candidate
- `mustHaves` (array): Non-negotiable requirements — instant disqualify if missing
- `niceToHaveSkills` (array): Skills that are a bonus
- `redFlags` (array): Any concerns noted (gaps, short tenures, etc.)
- `requiredSkills` (array, required): Skills required for the role
- `role` (string, required): Job title being hired for
- `salaryExpectation` (number): Candidate's salary expectation in USD
- `skills` (array, required): Skills the candidate has
- `yearsExperience` (number, required): Years of relevant experience

### `draft_offer_letter` (~282 tokens)

Generate a professional, ready-to-send offer letter with compensation summary, equity and bonus clauses, expiry date, negotiation notes, and a follow-up call script. Supports formal, warm, and startup tones.

Input parameters:

- `benefits` (array): Key benefits to highlight (e.g. health, dental, 401k, remote)
- `bonus` (string): Bonus structure if any (e.g. 15% annual performance bonus)
- `candidateName` (string, required): Full name of the candidate
- `companyName` (string, required): Your company name
- `companySignatory` (string, required): Name and title of person signing the offer
- `currency` (string): Currency code
- `department` (string, required): Department or team
- `equity` (string): Equity offer if any (e.g. 0.5% vested over 4 years)
- `offerExpiryDays` (number): Days until offer expires
- `probationPeriod` (string): Probation period if applicable (e.g. 90 days)
- `reportingTo` (string, required): Manager's name and title
- `role` (string, required): Job title being offered
- `salary` (number, required): Annual base salary in USD
- `startDate` (string, required): Proposed start date (e.g. July 1, 2025)
- `tone` (string): Tone of the offer letter

### `create_onboarding_plan` (~226 tokens)

Build a complete 30/60/90-day onboarding plan for a new hire. Includes Day 1 checklist, weekly themes, milestone goals, manager action list, red flag warnings, and a success definition. Adapts for IC, manager, and executive roles.

Input parameters:

- `companyValues` (array): Company values to embed in the plan
- `department` (string, required): Department or team
- `employeeName` (string, required): New hire's full name
- `keyStakeholders` (array): Key people they should meet (names or titles)
- `keyTools` (array): Key software/tools they'll use (e.g. Salesforce, Notion, Figma)
- `manager` (string, required): Manager's name
- `remote` (boolean): Is this a remote role?
- `role` (string, required): Job title
- `roleType` (string)
- `startDate` (string, required): Start date (e.g. July 1, 2025)
- `topPriorities` (array): Top 3 things they should achieve in their first 90 days

### `build_interview_kit` (~168 tokens)

Generate a complete interview kit for any role — structured questions by competency, STAR follow-up probes, 'what good looks like' benchmarks, red flags, a scorecard template, legal reminders, and a debrief guide. Covers screening, technical, behavioural, case, panel, and final interviews.

Input parameters:

- `companyStage` (string): Company stage — shapes the culture-fit questions
- `coreCompetencies` (array): Key competencies to assess (e.g. leadership, technical depth, customer empathy)
- `department` (string, required): Department
- `interviewType` (string): Type of interview
- `level` (string, required): Seniority level
- `mustAssess` (array): Specific skills or situations that must be probed
- `role` (string, required): Job title being interviewed for

### `write_performance_review` (~233 tokens)

Write a structured performance review with achievements narrative, development sections, next-period goals, compensation recommendation, and a manager meeting guide. Adapts to exceeds/meets/partially meets/does not meet ratings and supports coaching, direct, and formal tones.

Input parameters:

- `compensationAction` (string): Recommended compensation or status action
- `developmentAreas` (array, required): Areas that need improvement
- `employeeName` (string, required): Employee's full name
- `goalsAchieved` (array, required): Goals or projects the employee completed this period
- `goalsNotMet` (array): Goals that were missed or partially met
- `keyStrengths` (array, required): Top strengths demonstrated this period
- `manager` (string, required): Manager's name
- `nextPeriodGoals` (array): Goals for the next review period
- `overallRating` (string, required): Overall performance rating
- `reviewPeriod` (string, required): Review period (e.g. H1 2025, Q3 2025, Annual 2024)
- `role` (string, required): Employee's job title
- `tone` (string): Tone of the review

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/autostackup-hr/autostackup-hr#diagnostics

## Score history

- 2026-08-05: 68
- 2026-08-04: 66
- 2026-08-03: 67
- 2026-08-02: 63
- 2026-08-01: 18
- 2026-07-31: 18
- 2026-07-30: 6
- 2026-07-28: 43
- 2026-07-27: 43

## Links

- npm package: https://www.npmjs.com/package/@autostackup/hr
- Socket report: https://socket.dev/npm/package/@autostackup/hr
- Repository: https://github.com/Autostackup/autostackup
- Changelog RSS feed: https://verifymcp.io/servers/autostackup-hr/autostackup-hr/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/autostackup-hr/autostackup-hr/changelog.json
- HTML version of this page: https://verifymcp.io/servers/autostackup-hr/autostackup-hr
