# com.mambabuilt/mcp-b2b-prospect-engine (npm · @mambalabsdev/mcp-b2b-prospect-engine)

Enrich companies, discover hiring signals and find verified contacts in one actor.

- Trust score: 78/100 (medium)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- npm · `@mambalabsdev/mcp-b2b-prospect-engine`: 78/100 (this document), [markdown](https://verifymcp.io/servers/com-mambabuilt-mcp-b2b-prospect-engine/mambalabsdev-mcp-b2b-prospect-engine.md), [page](https://verifymcp.io/servers/com-mambabuilt-mcp-b2b-prospect-engine/mambalabsdev-mcp-b2b-prospect-engine)

## Channel facts

- Registry: `npm`
- Package: `@mambalabsdev/mcp-b2b-prospect-engine`
- Version: `1.0.2`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 98/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 31 of 96 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 48/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 37 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 55/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1410 tokens (~1410/item across 1 items; 1 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 80/100
  - Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 1 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 1 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the com.mambabuilt/mcp-b2b-prospect-engine server?

com.mambabuilt/mcp-b2b-prospect-engine runs locally as an npm package, launched with npx -y @mambalabsdev/mcp-b2b-prospect-engine. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add com-mambabuilt-mcp-b2b-prospect-engine -- npx -y @mambalabsdev/mcp-b2b-prospect-engine
```

### Cursor

```json
{
  "mcpServers": {
    "com-mambabuilt-mcp-b2b-prospect-engine": {
      "command": "npx",
      "args": [
        "-y",
        "@mambalabsdev/mcp-b2b-prospect-engine"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-mambabuilt-mcp-b2b-prospect-engine": {
      "command": "npx",
      "args": [
        "-y",
        "@mambalabsdev/mcp-b2b-prospect-engine"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add com-mambabuilt-mcp-b2b-prospect-engine -- npx -y @mambalabsdev/mcp-b2b-prospect-engine
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-mambabuilt-mcp-b2b-prospect-engine": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@mambalabsdev/mcp-b2b-prospect-engine"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-mambabuilt-mcp-b2b-prospect-engine --command npx --arg -y --arg @mambalabsdev/mcp-b2b-prospect-engine
```

### Hermes

```yaml
mcp_servers:
  com-mambabuilt-mcp-b2b-prospect-engine:
    command: "npx"
    args: ["-y", "@mambalabsdev/mcp-b2b-prospect-engine"]
```

### Netclaw

```json
{
  "McpServers": {
    "com-mambabuilt-mcp-b2b-prospect-engine": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@mambalabsdev/mcp-b2b-prospect-engine"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-mambabuilt-mcp-b2b-prospect-engine -t stdio -c npx -a -y @mambalabsdev/mcp-b2b-prospect-engine
```

### Other

```json
{
  "mcpServers": {
    "com-mambabuilt-mcp-b2b-prospect-engine": {
      "command": "npx",
      "args": [
        "-y",
        "@mambalabsdev/mcp-b2b-prospect-engine"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-20 (score 78, −3)

- [functional] Stability: pass → 0.80

### 2026-09-19 (score 81, +1)

- [security] Stability: 0.97 → pass

### 2026-09-16 (score 80, +1)

No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 79, +1)

No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-13 (score 78, −3)

- [functional] Stability: pass → 0.80

### 2026-09-12 (score 81, +1)

- [security] Stability: 0.97 → pass

### 2026-09-10 (score 80, −1)

- [functional] Stability: pass → 0.93

### 2026-09-09 (score 81, +1)

- [security] Stability: 0.97 → pass

## MCP tools (1)

### `run_prospect_engine` (~1410 tokens)

Run Prospect Engine

A composed prospecting actor with four modes. enrich_companies resolves identity, firmographics, LinkedIn and social for each domain or company name you supply, and needs no vendor key at all. discover_jobs finds who is hiring for your keywords and resolves the real employer behind each posting, including postings a job board placed on an employer's behalf. find_contacts finds people at the companies you name, with optional email discovery and verification. full runs discovery, enrichment, ICP scoring and then contact discovery, passing only the companies at or above min_icp_score through to the contact stage. Every row comes back flat and Clay ready with per field provenance. Vendor keys are yours: you supply them, those vendors bill you directly, and the per event price covers the actor only. discover_jobs and full require a SerpApi key, which is a different vendor from the Serper key that powers people search. Note that this actor is a pass through wrapper over the live actor, so any classification behavior you see is the actor's own. Requires an APIFY_TOKEN and consumes Apify credits. Read only: it enriches and discovers, it writes nothing.

Input parameters:

- `bounceban_api_key` (string): Your BounceBan key. Second verifier, used for the catch-all case.
- `company_names` (array): One name per line. Used when you have a name but no domain.
- `company_size_max` (string): Drop companies above this headcount. Same condition as the minimum.
- `company_size_min` (string): Drop companies below this headcount. Only takes effect once headcount is known, so it applies in full mode and to any discovery row that carried an employee count. Discovery alone does not enrich.
- `country` (string): Two letter country code for job search, for example us or gb. Default: "us".
- `departments` (array): marketing, sales, engineering, product, finance, hr, operations, legal.
- `domains` (array): One domain per line. Used by enrich_companies and find_contacts.
- `exclude_marketplaces` (string): true to drop Upwork, Fiverr, Freelancer and similar gig listings. Default: "true".
- `exclude_staffing` (string): true to drop postings from staffing and recruitment agencies. Default: "true".
- `extra_exclude_names` (array): Any company whose name contains one of these is excluded.
- `extra_marketplaces` (array): Additional marketplace names to filter out.
- `fetch_posting_page` (string): true to open the job posting when the description alone does not identify the employer. Slower, and it is what catches a job board posting on an employer's behalf. Default: "true".
- `findymail_api_key` (string): Your Findymail key. First provider in the email waterfall.
- `icp_preset` (string): Which scoring model to apply. "editorial_services" scores for a seller of managed copy editing and proofreading. "generic_b2b" scores on hiring intent, employer resolvability and headcount with no se…
- `icypeas_api_key` (string): Your Icypeas key. Runs on Findymail misses.
- `include_email` (string): true to run the email waterfall. Needs an Icypeas or Prospeo key, which you supply and are billed for directly. Default: "false".
- `include_social` (string): true to resolve Facebook, Instagram, X and YouTube alongside LinkedIn. Default: "true".
- `job_titles` (array): Titles to search for when finding contacts.
- `keywords` (array): Roles to search for. Used by discover_jobs and full. Example: copy editor, proofreader, content editor. Default: ["copy editor", "proofreader", "content editor"].
- `location` (string): Optional location filter for job search, for example New York.
- `lookback_days` (string): Drop postings older than this many days. Sent as a string because Clay sends every field as a string. Default: "30".
- `max_pages` (string): 1 to 5. Each page is one SerpAPI call, so this is the main cost dial on discovery. Default: "1".
- `max_results` (string): Cap on postings returned per run. Keeps a broad keyword set from running away. Default: "25".
- `min_icp_score` (string): In full mode, only companies scoring at or above this go on to contact discovery. Default 45: at 25 the filter passed every keyword-discovered editorial posting, because 25 is the floor such a postin…
- `mode` (string): What to run. enrich_companies resolves identity, firmographics, LinkedIn and social for each company. discover_jobs finds who is hiring for your keywords and resolves the real employer from the job d…
- `new_postings_only` (string): true to return only postings not seen in a previous run. Default: "false".
- `previous_run_date` (string): YYYY-MM-DD watermark for delta detection when the cross-run cache is unavailable.
- `prospeo_api_key` (string): Your Prospeo key. Runs on the residual after Findymail and Icypeas.
- `remote_only` (string): true to keep only postings flagged remote by the board. Default: "false".
- `reoon_api_key` (string): Your Reoon key. First email verification provider.
- `score_icp` (string): true to score every row against the ICP rules and tier it A to D. Default: "true".
- `seniority` (array): c_level, vp, director, manager, senior.
- `serpapi_key` (string): Your SerpApi key. Required by discover_jobs and full. Distinct from a Serper key: different vendor.
- `serper_api_key` (string): Your Serper.dev key. Powers people search in find_contacts, which is the highest-coverage layer. Without it the free fallback is measurably poor.
- `signal_taxonomy` (array): Override the default signal types. Each entry is an object with type, strength, title_keywords, and optional also_keywords and description_keywords.
- `skip_cache` (string): true to ignore the 7 day cross-run cache and recompute everything. Default: "false".
- `source_timeout_secs` (string): 5 to 120. A source that exceeds this is marked degraded and the run continues. Default: "30".
- `target_contacts` (string): 1 to 25. Default: "3".
- `verify_email` (string): true to verify each address. Needs a Reoon or BounceBan key. Default: "true".

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/com-mambabuilt-mcp-b2b-prospect-engine/mambalabsdev-mcp-b2b-prospect-engine#diagnostics

## Score history

- 2026-09-20: 78
- 2026-09-19: 81
- 2026-09-18: 80
- 2026-09-17: 80
- 2026-09-16: 80
- 2026-09-15: 79
- 2026-09-14: 79
- 2026-09-13: 78
- 2026-09-12: 81
- 2026-09-11: 80
- 2026-09-10: 80
- 2026-09-09: 81
- 2026-09-08: 80
- 2026-09-07: 80
- 2026-09-06: 80
- 2026-09-05: 79
- 2026-09-04: 79
- 2026-09-03: 78
- 2026-09-02: 78
- 2026-09-01: 77
- 2026-08-31: 77
- 2026-08-30: 76
- 2026-08-29: 76
- 2026-08-28: 75
- 2026-08-27: 75
- 2026-08-26: 74
- 2026-08-25: 73
- 2026-08-24: 72
- 2026-08-23: 71
- 2026-08-22: 71

## Common questions

### What is the com.mambabuilt/mcp-b2b-prospect-engine server?

com.mambabuilt/mcp-b2b-prospect-engine is listed in the public MCP registry as com.mambabuilt/mcp-b2b-prospect-engine. Enrich companies, discover hiring signals and find verified contacts in one actor. This page covers its npm package (@mambalabsdev/mcp-b2b-prospect-engine).

### Is the com.mambabuilt/mcp-b2b-prospect-engine server safe to use?

com.mambabuilt/mcp-b2b-prospect-engine scores 78 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the com.mambabuilt/mcp-b2b-prospect-engine server expose?

com.mambabuilt/mcp-b2b-prospect-engine exposes 1 tool: run_prospect_engine. Their descriptions and schemas cost roughly 1,410 tokens of context every time the server is loaded.

### Is the com.mambabuilt/mcp-b2b-prospect-engine server still maintained?

com.mambabuilt/mcp-b2b-prospect-engine is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the com.mambabuilt/mcp-b2b-prospect-engine server under?

com.mambabuilt/mcp-b2b-prospect-engine declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/@mambalabsdev/mcp-b2b-prospect-engine
- Socket report: https://socket.dev/npm/package/@mambalabsdev/mcp-b2b-prospect-engine
- Repository: https://github.com/mambalabsdev/mcp-b2b-prospect-engine
- Changelog RSS feed: https://verifymcp.io/servers/com-mambabuilt-mcp-b2b-prospect-engine/mambalabsdev-mcp-b2b-prospect-engine.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-mambabuilt-mcp-b2b-prospect-engine/mambalabsdev-mcp-b2b-prospect-engine.json
- HTML version of this page: https://verifymcp.io/servers/com-mambabuilt-mcp-b2b-prospect-engine/mambalabsdev-mcp-b2b-prospect-engine
