Atlas / MCP servers / mathhire / Shortlist

ShortlistSAFE

mcp/mathhire/shortlist

MCP server for Shortlist — search, queue, and auto-apply to jobs from Claude Code

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
32 12r · 13w · 7d
Transport
—
License
MIT
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE) [](https://discord.gg/hmHujPetXH)

Apply to hundreds of jobs from Claude in minutes.

Shortlist connects to Claude Code, Claude Desktop, or Cursor and lets you search for jobs, fill out applications with AI, and submit them automatically — without leaving your terminal.

How it works

1. Connect

Add the MCP server and log in — takes 30 seconds.

claude mcp add shortlist --transport http https://shortlist.jobs/mcp

Restart Claude Code, then type /mcp and select shortlist. A browser window opens — sign in with your Shortlist account and you're connected.

Claude Desktop setup (macOS)

Add this to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
"mcpServers": {
"shortlist": {
"transport": "http",
"url": "https://shortlist.jobs/mcp"
}
}
}

Restart Claude Desktop. You'll be prompted to authenticate on first use.

Claude Desktop setup (Windows)

Add this to %APPDATA%\Claude\claude_desktop_config.json:

{
"mcpServers": {
"shortlist": {
"transport": "http",
"url": "https://shortlist.jobs/mcp"
}
}
}

Restart Claude Desktop. You'll be prompted to authenticate on first use.

2. Search and queue jobs

Find jobs by role, location, or company. Or paste URLs directly from any supported job board.

You: Find me remote senior frontend engineer jobs
You: Add these to my queue:
https://jobs.ashbyhq.com/stripe/senior-frontend
https://jo
Read from source at commit 992361e82e42OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add shortlistjobs-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "shortlistjobs-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (32)

12 read · 13 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_educationwriteAdd an education entry to your profile. Set type to
add_languageswriteAdd one or more languages to your profile.
add_skillswriteAdd one or more skills to your profile. Provide an array of skill objects with name and optional years of experience.
add_to_queuewriteAdd jobs to your application queue by URL. Just paste the job posting URLs — title, company, and ATS are auto-detected. Supported: Ashby, Lever, SmartRecruiters, Workable, Greenhouse, Workday.
add_work_experiencewriteAdd a work experience or project to your profile. Set type to
approve_allreadApprove all pending jobs in the queue for application submission.
approve_jobreadApprove a single job for application submission. Optionally provide form answers as JSON.
clear_queuedestructiveClear all jobs from your application queue.
delete_educationdestructiveDelete an education entry by ID. Get the ID from get_profile.
delete_resumedestructiveDelete a resume by ID. Get the ID from list_resumes.
delete_work_experiencedestructiveDelete a work experience or project by ID. Get the ID from get_profile.
get_application_progressreadCheck how your current application batch is progressing — see how many jobs are done, in progress, and remaining.
get_application_summaryreadGet a summary of recent job applications with your profile data for match analysis. Returns success/failure counts, per-job details with descriptions, and your full profile (skills, experience, education). Best used after the bot finishes applying.
get_applied_jobsreadView your application history — jobs you
get_applied_jobs_countreadGet the total number of jobs you
get_job_detailsreadGet full details about a job in your queue — description, AI-filled answers, prefill status, and scraped form data.
get_profilereadView your Shortlist profile summary including personal details, skills, work experience, and completion status.
get_queuereadView jobs in your application queue. Optionally filter by status (pending, approved, in_progress, failed).
list_resumesreadList all your uploaded resumes (max 5). Shows which one is the default.
prefill_jobreadScrape a job
remove_from_queuedestructiveRemove a specific job from your application queue by its ID.
remove_languagesdestructiveRemove one or more languages from your profile by name.
remove_skillsdestructiveRemove one or more skills from your profile by name.
search_jobsreadSearch for jobs by title, location, and filters. Returns up to 20 results per page.
set_default_resumewriteSet a resume as your default for job applications. Get the resume ID from list_resumes.
start_applyingwriteStart the bot to submit all approved job applications. The bot fills out forms and submits them automatically.
stop_applyingwriteStop the bot from submitting more applications.
update_application_questionswriteUpdate application questions — salary, years of experience, sponsorship, relocation, work authorization, notice period, and profile links.
update_educationwriteUpdate an existing education entry (degree, certification, or clearance) by ID. Get the ID from get_profile.
update_personal_detailswriteUpdate your personal details — name, email, phone, address. Only provide fields you want to change.
update_work_experiencewriteUpdate an existing work experience or project by ID. Get the ID from get_profile. Only provide fields you want to change.
upload_resumewriteUpload a resume file (PDF, DOC, or DOCX). Provide the full file as a base64-encoded string and the file name. Files up to 16MB are supported — do not split or chunk the file, just send it all at once.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_queue, delete_education, delete_resume, delete_work_experience, remove_from_queue, remove_languages, remove_skills
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, typescript, @types/node
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 992361e82e42full audit observations/trust-audit/mcp-server/mathhire__shortlist.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08992361e82e42SAFEB89first audit
06

Questions

What is the Shortlist MCP server?

MCP server for Shortlist — search, queue, and auto-apply to jobs from Claude Code

What tools does Shortlist expose?

32 in total: 12 read-only, 13 that write, and 7 that can delete or overwrite (clear_queue, delete_education, delete_resume, delete_work_experience, remove_from_queue). Every one is listed on this page with its risk.

Is Shortlist safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Shortlist need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (992361e82e42), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement