Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

com.mambabuilt/mcp-gtm-job-discovery

NPM · @MAMBALABSDEV/MCP-GTM-JOB-DISCOVERY · SCANNED AUG 17

Find companies hiring for your role keywords, with firmographics and LinkedIn per posting.

+4 this week 70 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 30 of 96 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency48
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 4 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability63
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 670 tokens (~670/item across 1 items; 1 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
  • Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @mambalabsdev/mcp-gtm-job-discovery

# add to Claude Code
claude mcp add com-mambabuilt-mcp-gtm-job-discovery -- npx -y @mambalabsdev/mcp-gtm-job-discovery
# add to Codex CLI
codex mcp add com-mambabuilt-mcp-gtm-job-discovery -- npx -y @mambalabsdev/mcp-gtm-job-discovery
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-mambabuilt-mcp-gtm-job-discovery": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@mambalabsdev/mcp-gtm-job-discovery"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-mambabuilt-mcp-gtm-job-discovery --command npx --arg -y --arg @mambalabsdev/mcp-gtm-job-discovery
# ~/.hermes/config.yaml
mcp_servers:
  com-mambabuilt-mcp-gtm-job-discovery:
    command: "npx"
    args: ["-y", "@mambalabsdev/mcp-gtm-job-discovery"]
// mcp.json
{
  "mcpServers": {
    "com-mambabuilt-mcp-gtm-job-discovery": {
      "command": "npx",
      "args": [
        "-y",
        "@mambalabsdev/mcp-gtm-job-discovery"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 16 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

  • 13 Aug 26 +1
    • Stability: unverified → 0.10 functional
    • Package version: 1.0.0 → 1.2.1 functional
  • 11 Aug 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 10 Aug 26 66

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 17 Aug 2026 · Analysed npm/@mambalabsdev/mcp-gtm-job-discovery@1.2.1

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm
Dependencies 96 packages
Packages resolved 96
Stale 30
Tree resolution Complete
MCP tools · 1 exposed · ~670 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
monitor_job_postings ~670

Find companies that are hiring for a set of role keywords across public job boards, and return one flat row per posting enriched with company firmographics and the company LinkedIn URL. Discovery runs through Google Jobs, and passing your own SerpAPI key runs that search on your own quota. Postings are filtered by age, by country, and optionally by employee count, and staffing agencies and freelance marketplaces are dropped by default because they are noise for direct outreach. A cross run delta cache means a repeat run returns only postings it has not emitted before, and previous_run_date lets you set that watermark yourself. max_results caps how many raw postings are pulled before filtering and max_companies caps how many unique companies get enriched, so the two together are the cost dial. Requires an APIFY_TOKEN and consumes Apify credits. Read only: this discovers and enriches, it writes nothing.

NameTypeReqDescription
company_size_maxintegerOptional. Drop companies larger than this (only applied when company size is known).
company_size_minintegerOptional. Drop companies with fewer employees than this (only applied when company size is known).
countrystringGeographic filter, e.g. United States, United Kingdom, Canada. Default: "United States".
exclude_freelance_marketplacesbooleanFilter out postings where the company is a freelance marketplace (Upwork, Fiverr, etc.), which are noise for direct outreach. Default: true.
exclude_staffing_agenciesbooleanFilter out staffing and recruitment agency postings using name and job-description heuristics. Default: true.
freelance_marketplacesarrayCompany names treated as freelance marketplaces and excluded when the toggle above is on. Defaults shown; override or extend as needed. Default: ["Upwork", "Fiverr", "Freelancer", "Toptal", "PeoplePe…
keywordsarrayyesEditorial / content role titles to search for across job boards.
lookback_daysintegerOnly return postings newer than this many days. Default: 30.
max_companiesintegerCap on unique companies enriched per run (firmographics + LinkedIn). Bounds sub-actor cost. Default: 40.
max_resultsintegerUpper bound on raw postings pulled from the discovery source before filtering. Higher values cost more. Default: 100.
previous_run_datestringOptional ISO date (e.g. 2026-06-01) of your last run. Only postings newer than this are emitted, on top of the built-in cross-run delta cache.
remote_onlybooleanOnly return remote / work-from-home postings. Default: false.
serpapi_keystringSerpAPI key used for Google Jobs discovery (get a free key at serpapi.com, 250 searches/month, no card). Required to produce results unless a SERPAPI_KEY environment variable is set on the actor.
use_gio21booleanBest-effort fallback to the gio21 Google Jobs sub-actor when no SerpAPI key is available. Only works on Apify plans that permit running third-party public actors. Default: false.

No output schema declared.

No examples provided.