Atlas / MCP servers / shinzo-labs / HubSpot

HubSpotSAFE

mcp/shinzo-labs/hubspot-4

MCP Implementation for HubSpot

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
112 45r · 51w · 16d
Transport
stdio · streamable-http
License
MIT
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

HubSpot MCP Server

A Model Context Protocol (MCP) server implementation for the HubSpot API, providing a standardized interface for accessing and managing CRM data.

Features

  • Complete coverage of the HubSpot CRM API
  • Support for all standard CRM objects (companies, contacts, deals, etc.)
  • Advanced association management with CRM Associations v4
  • Company-specific endpoints with property validation
  • Batch operations for efficient data management
  • Advanced search and filtering capabilities
  • Type-safe parameter validation with Zod

Prerequisites

If you don't have an API key, follow the steps here to obtain an access token. OAuth support is planned as a future enhancement.

Client Configuration

There are several options to configure your MCP client wi

Read from source at commit 7405cc49a3b7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add hubspot-mcp --env HUBSPOT_ACCESS_TOKEN=${HUBSPOT_ACCESS_TOKEN} -- npx -y @shinzolabs/[email protected]
claude-desktop
{
  "mcpServers": {
    "hubspot-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@shinzolabs/[email protected]"
      ],
      "env": {
        "HUBSPOT_ACCESS_TOKEN": "${HUBSPOT_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (112)

45 read · 51 write · 16 destructive. Blast radius: 16 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
calls_archivedestructiveArchive (delete) a call record
calls_batch_archivedestructiveArchive (delete) multiple call records in a single request
calls_batch_createwriteCreate multiple call records in a single request
calls_batch_readreadRead multiple call records in a single request
calls_batch_updatewriteUpdate multiple call records in a single request
calls_createwriteCreate a new call record
calls_getreadGet details of a specific call
calls_listreadList all calls with optional filtering
calls_searchreadSearch calls with specific filters
calls_updatewriteUpdate an existing call record
communications_get_preferencesreadGet communication preferences for a contact
communications_get_subscription_definitionsreadGet all subscription definitions for the portal
communications_get_subscription_statusreadGet subscription status for multiple contacts
communications_subscribe_contactreadSubscribe a contact to all email communications
communications_unsubscribe_contactreadUnsubscribe a contact from all email communications
communications_update_preferenceswriteUpdate communication preferences for a contact
communications_update_subscription_statuswriteUpdate subscription status for multiple contacts
crm_archive_associationdestructiveArchive (delete) an association between two objects
crm_archive_objectdestructiveArchive (delete) a CRM object
crm_batch_archive_associationsdestructiveArchive (delete) multiple associations in a single request
crm_batch_archive_objectsdestructiveArchive (delete) multiple CRM objects in a single request
crm_batch_create_associationswriteCreate multiple associations in a single request
crm_batch_create_companieswriteCreate multiple companies in a single request
crm_batch_create_contactswriteCreate multiple contacts in a single request
crm_batch_create_leadswriteCreate multiple leads in a single request
crm_batch_create_objectswriteCreate multiple CRM objects in a single request
crm_batch_read_objectswriteCreate multiple CRM objects in a single request
crm_batch_update_companieswriteUpdate multiple companies in a single request
crm_batch_update_contactswriteUpdate multiple contacts in a single request
crm_batch_update_leadswriteUpdate multiple leads in a single request
crm_batch_update_objectswriteUpdate multiple CRM objects in a single request
crm_create_associationwriteCreate an association between two objects
crm_create_companywriteCreate a new company with validated properties
crm_create_company_propertywriteCreate a new company property
crm_create_contactwriteCreate a new contact with validated properties
crm_create_contact_propertywriteCreate a new contact property
crm_create_leadwriteCreate a new lead with validated properties
crm_create_lead_propertywriteCreate a new lead property
crm_create_objectwriteCreate a new CRM object
crm_get_associationsreadGet all associations of a specific type between objects
crm_get_companyreadGet a single company by ID with specific properties and associations
crm_get_company_propertiesreadGet all properties for companies
crm_get_contactreadGet a single contact by ID with specific properties and associations
crm_get_contact_propertiesreadGet all properties for contacts
crm_get_leadreadGet a single lead by ID with specific properties and associations
crm_get_lead_propertiesreadGet all properties for leads
crm_get_objectreadGet a single CRM object by ID
crm_list_association_typesreadList all available association types for a given object type pair
crm_list_objectsreadList CRM objects of a specific type with optional filtering and pagination
crm_search_companiesreadSearch companies with company-specific filters
crm_search_contactsreadSearch contacts with contact-specific filters
crm_search_leadsreadSearch leads with lead-specific filters
crm_search_objectsreadSearch CRM objects using filters
crm_update_companywriteUpdate an existing company with validated properties
crm_update_contactwriteUpdate an existing contact with validated properties
crm_update_leadwriteUpdate an existing lead with validated properties
crm_update_objectwriteUpdate an existing CRM object
emails_archivedestructiveArchive (delete) an email record
emails_batch_archivedestructiveArchive (delete) multiple email records in a single request
emails_batch_createwriteCreate multiple email records in a single request
emails_batch_readreadRead multiple email records in a single request
emails_batch_updatewriteUpdate multiple email records in a single request
emails_createwriteCreate a new email record
emails_getreadGet details of a specific email
emails_listreadList all emails with optional filtering
emails_searchreadSearch emails with specific filters
emails_updatewriteUpdate an existing email record
engagement_details_archivedestructiveArchive (delete) an engagement
engagement_details_createwriteCreate a new engagement with details
engagement_details_getreadGet details of a specific engagement
engagement_details_get_associatedreadGet all engagements associated with an object
engagement_details_listreadList all engagements with optional filtering
engagement_details_updatewriteUpdate an existing engagement
meetings_archivedestructiveArchive (delete) a meeting
meetings_batch_archivedestructiveArchive (delete) multiple meetings in a single request
meetings_batch_createwriteCreate multiple meetings in a single request
meetings_batch_updatewriteUpdate multiple meetings in a single request
meetings_createwriteCreate a new meeting
meetings_getreadGet details of a specific meeting
meetings_listreadList all meetings with optional filtering
meetings_searchreadSearch meetings with specific filters
meetings_updatewriteUpdate an existing meeting
notes_archivedestructiveArchive (delete) a note
notes_batch_archivedestructiveArchive (delete) multiple notes in a single request
notes_batch_createwriteCreate multiple notes in a single request
notes_batch_readreadRead multiple notes in a single request
notes_batch_updatewriteUpdate multiple notes in a single request
notes_createwriteCreate a new note
notes_getreadGet details of a specific note
notes_listreadList all notes with optional filtering
notes_searchreadSearch notes with specific filters
notes_updatewriteUpdate an existing note
products_archivewriteMove an Object identified by ID to the recycling bin.
products_batch_archivedestructiveArchive (delete) a batch of products by ID
products_batch_createwriteCreate a batch of products
products_batch_readreadRead a batch of products by internal ID, or unique property values. Retrieve records by the
products_batch_updatewriteUpdate a batch of products by internal ID, or unique values specified by the
products_createwriteCreate a product with the given properties and return a copy of the object, including the ID.
products_listreadRead a page of products. Control what is returned via the
products_readreadRead an Object identified by ID
products_searchreadSearch products
products_updatewritePerform a partial update of an Object identified by ID. Read-only and non-existent properties will result in an error. Properties values can be cleared by passing an empty string.
tasks_archivedestructiveArchive (delete) a task
tasks_batch_archivedestructiveArchive (delete) multiple tasks in a single request
tasks_batch_createwriteCreate multiple tasks in a single request
tasks_batch_readreadRead multiple tasks in a single request
tasks_batch_updatewriteUpdate multiple tasks in a single request
tasks_createwriteCreate a new task
tasks_getreadGet details of a specific task
tasks_listreadList all tasks with optional filtering
tasks_searchreadSearch tasks with specific filters
tasks_updatewriteUpdate an existing task
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
calls_archive, calls_batch_archive, crm_archive_association, crm_archive_object, crm_batch_archive_associations, crm_batch_archive_objects, emails_archive, emails_batch_archive, engagement_details_arc
Why it matters. 16 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@shinzolabs/instrumentation-mcp, @babel/core, @babel/preset-env, @babel/preset-typescript, @changesets/cli, @types/jest, @types/node, babel-jest
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7405cc49a3b7full audit observations/trust-audit/mcp-server/shinzo-labs__hubspot-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087405cc49a3b7SAFEB89first audit
06

Questions

What is the HubSpot MCP server?

MCP Implementation for HubSpot

What tools does HubSpot expose?

112 in total: 45 read-only, 51 that write, and 16 that can delete or overwrite (calls_archive, calls_batch_archive, crm_archive_association, crm_archive_object, crm_batch_archive_associations). Every one is listed on this page with its risk.

Is HubSpot safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 16 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does HubSpot need?

It reads HUBSPOT_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does HubSpot run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @shinzolabs/hubspot-mcp at 2.0.5.

How current is this page?

The grade is for one exact copy of the source (7405cc49a3b7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement