# io.github.drjerryrelth/ghl-command (npm · @elitedcs/ghl-mcp)

GoHighLevel MCP for Claude: 233 tools, 49 modules, incl. the only programmatic GHL workflow builder

- Trust score: 51/100 (low)
- Change this week: +24
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

> **Malware flagged**: A supply-chain scanner flagged a high-severity malware risk in this package. Treat it as unsafe to install until the finding is cleared.

## Components

- npm · `@elitedcs/ghl-mcp`: 51/100 (this document), [markdown](https://verifymcp.io/servers/drjerryrelth-ghl-command/elitedcs-ghl-mcp.md), [page](https://verifymcp.io/servers/drjerryrelth-ghl-command/elitedcs-ghl-mcp)

## Channel facts

- Registry: `npm`
- Package: `@elitedcs/ghl-mcp`
- Version: `3.57.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 42/100
  - Malware check failed: a supply-chain vendor flagged a high-severity malware risk.
  - Only part of the dependency tree could be resolved (97 of 101), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (97 of 101), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 32/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - License check failed: the license (SEE LICENSE IN LICENSE) isn't a recognized OSI-approved license.
  - Actively maintained (last published 3 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 70/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 661 tokens (~165/item across 4 items; 4 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 23/100
  - Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add drjerryrelth-ghl-command -- npx -y @elitedcs/ghl-mcp
```

### Codex

```bash
codex mcp add drjerryrelth-ghl-command -- npx -y @elitedcs/ghl-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "drjerryrelth-ghl-command": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@elitedcs/ghl-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add drjerryrelth-ghl-command --command npx --arg -y --arg @elitedcs/ghl-mcp
```

### Hermes

```yaml
mcp_servers:
  drjerryrelth-ghl-command:
    command: "npx"
    args: ["-y", "@elitedcs/ghl-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "drjerryrelth-ghl-command": {
      "command": "npx",
      "args": [
        "-y",
        "@elitedcs/ghl-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 51, +30)

- [security regression] Provenance: unverified → fail
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Install scripts: unverified → pass
- [functional regression] License: unverified → fail
- [functional regression] Security disclosure: fail → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Stability: unverified → 0.20
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Schema quality: unverified → excellent
- [functional] Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional] Licence: SEE LICENSE IN LICENSE

### 2026-08-01 (score 21, −6)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-31 (score 27, +2)

- [security regression] Known CVEs: partial → unverified
- [security regression] Provenance: fail → unverified
- [security regression] Install scripts: pass → unverified
- [functional regression] License: fail → unverified
- [functional regression] Dependency health: partial → unverified
- [functional regression] Maintenance: pass → unverified
- [functional improvement] Tool coverage: unverified → 100
- [functional] Licence: SEE LICENSE IN LICENSE
- [functional] Package version: 3.56.0 → 3.57.0

### 2026-07-30 (score 25, 0)

- [functional] Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess.
- [functional] Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess.
- [functional] Package version: 3.52.2 → 3.56.0

### 2026-07-29 (score 25, +19)

- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [functional regression] License: unverified → fail
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional] Licence: SEE LICENSE IN LICENSE
- [functional] Package version: 3.53.0 → 3.56.0
- [functional] Package version: 3.52.2 → 3.55.0

### 2026-07-28 (score 6, −21)

- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified
- [functional] Package version: 3.52.2 → 3.53.0

### 2026-07-27 (score 27)

First indexed and scored.

## MCP tools (4)

### `get_mcp_version` (~66 tokens)

Check the installed version of GHL Command (the GoHighLevel MCP server) against the latest version published to npm. Use this to confirm an upgrade landed after restarting Claude. Returns installed version, latest version, whether up-to-date, and the one-line restart instruction if not.

### `setup_ghl_mcp` (~302 tokens)

First-run setup for GHL Command MCP. Validates your license and GHL credentials, then writes them to a per-user credentials file. Restart Claude after this completes to load all 233 tools (179 if you skip the optional Firebase fields; add Firebase later with enable_workflow_builder).

Input parameters:

- `email` (string, required): Email used at purchase.
- `firebase_paste` (string): (Workflow Builder, one-paste path) Paste the JSON output from auto_capture_firebase_script here. Replaces the three separate Firebase fields below.
- `ghl_api_key` (string, required): GHL Private Integration key (starts with 'pit-'). Created INSIDE the sub-account at Settings > Integrations > Private Integrations.
- `ghl_company_id` (string): (Agency only) Company ID for multi-location access.
- `ghl_firebase_api_key` (string): (Workflow Builder, manual path) Firebase API Key starting with 'AIza'. Prefer firebase_paste instead.
- `ghl_firebase_refresh_token` (string): (Workflow Builder, manual path) Firebase refresh token. Prefer firebase_paste instead.
- `ghl_location_id` (string, required): GHL Location ID (sub-account ID). Found in your GHL URL: /location/THIS_PART/dashboard.
- `ghl_user_id` (string): (Workflow Builder, manual path) Firebase User ID. Prefer firebase_paste instead.
- `license_key` (string, required): License key from your purchase email.

### `request_license` (~156 tokens)

Get a GHL Command license. Use this if you installed from npm but don't have a license yet (or setup_ghl_mcp says your license is missing/invalid). GHL Command is $97/mo — every sub-account you manage, 3-machine activation, includes the only programmatic GHL workflow builder. There's also a FREE read-only tier (account audits + all reads on your own account) — instant key at https://ghlcommand.com/free. Leave your email and we'll send the purchase link + setup help; the tool also returns where to buy right now.

Input parameters:

- `email` (string, required): Your email — where to send the purchase link and setup help.
- `name` (string): Your name (optional).

### `auto_capture_firebase_script` (~137 tokens)

Get the browser-console script that auto-extracts the 3 Firebase fields needed to enable the Workflow Builder. PREFER `capture_firebase_interactive` when Chrome/Edge is installed (one-click, zero pasting); this script is the fallback for locked-down machines and the path for capturing a CLIENT account's Firebase (multi-tenant). Run this, copy the script, paste it into Chrome DevTools Console on a tab logged into GHL, press Enter, and the result lands in your clipboard. Then paste the JSON into setup_ghl_mcp's firebase_paste field (or enable_workflow_builder's).

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/drjerryrelth-ghl-command/elitedcs-ghl-mcp#diagnostics

## Score history

- 2026-08-03: 51
- 2026-08-02: 51
- 2026-08-01: 21
- 2026-07-31: 27
- 2026-07-30: 25
- 2026-07-29: 25
- 2026-07-28: 6
- 2026-07-27: 27

## Links

- npm package: https://www.npmjs.com/package/@elitedcs/ghl-mcp
- Socket report: https://socket.dev/npm/package/@elitedcs/ghl-mcp
- Repository: https://github.com/drjerryrelth/ghl-command-feedback
- Changelog RSS feed: https://verifymcp.io/servers/drjerryrelth-ghl-command/elitedcs-ghl-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/drjerryrelth-ghl-command/elitedcs-ghl-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/drjerryrelth-ghl-command/elitedcs-ghl-mcp
