Atlas / MCP servers / zaphod-black / EspoCRM

EspoCRMCAUTION

mcp/zaphod-black/espocrm

Opensource MCP Server for EspoCRM

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
47 27r · 17w · 3d
Transport
stdio
License
—
Stars
51
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A comprehensive Model Context Protocol (MCP) server for seamless integration with EspoCRM. This server enables AI assistants to interact with your EspoCRM instance through a standardized interface, providing complete CRUD operations for Contacts, Accounts, Opportunities, Meetings, Users, Tasks, Leads, and advanced system management capabilities.

NEW: AI Chatbot Integration - Now includes a complete chatbot interface that embeds directly into your EspoCRM, providing natural language access to all 47 MCP tools!

Features

Core Capabilities

  • Complete CRUD Operations - Create, read, update, and delete entities
  • Multi-Entity Support - Contacts, Accounts, Opportunities, Meetings, Users, Tasks, and Leads
  • Advanced Search & Filtering - Flexible search with date ranges, pagination, and complex filters
  • Task Management - Complete task lifecycle with parent relationships and user assignment
  • Lead Management - Full lead pipeline from creation to conversion
  • Meeting Management - Full calendar integration with attendee management
  • User Management - Comprehensive user search and lookup capabilities
  • Real-time Validation - Zod-based schema validation for all operations
  • Comprehensive Logging - Winston-powered logging with multiple levels

Authentication & Security

  • Multiple Auth Methods - API Key and HMAC authentication support
  • Secure Configuration - Environment-based configuration management
  • Rate Limiting - Built-in rate limiting for API protection
  • Error Handling - Robust error handling with detailed logging

Calendar Integration

  • Meeting Operations - Create, search, update, and manage meetings
  • Attendee Management - Link contacts and users to meetings
  • Date/Time Filtering - Advanced date range search capabilities
  • Google Calendar Sync Compatibility - Designed for calendar synchronization workflows

AI Chatbot Integration

  • *Floating Chat Widget
Read from source at commit 840d75bcbf57OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add espocrm-mcp-server --env ESPOCRM_API_KEY=${ESPOCRM_API_KEY} --env ESPOCRM_AUTH_METHOD=${ESPOCRM_AUTH_METHOD} --env ESPOCRM_SECRET_KEY=${ESPOCRM_SECRET_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "espocrm-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ESPOCRM_API_KEY": "${ESPOCRM_API_KEY}",
        "ESPOCRM_AUTH_METHOD": "${ESPOCRM_AUTH_METHOD}",
        "ESPOCRM_SECRET_KEY": "${ESPOCRM_SECRET_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (47)

27 read · 17 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
DevreadDevelopers
add_notewriteAdd a note/comment to any entity
add_user_to_teamwriteAdd a user to a team with optional position
assign_leadreadAssign or reassign a lead to a specific user
assign_role_to_userreadAssign a role to a user
assign_taskreadAssign or reassign a task to a specific user
convert_leadreadConvert a lead to contact, account, and/or opportunity
create_accountwriteCreate a new account/company in EspoCRM
create_callwriteLog a phone call with participants and details
create_casewriteCreate a support case/ticket with details
create_contactwriteCreate a new contact in EspoCRM with validation
create_entitywriteCreate a record for any entity type with validation
create_leadwriteCreate a new lead with full field support
create_meetingwriteCreate a new meeting in EspoCRM
create_opportunitywriteCreate a new sales opportunity in EspoCRM
create_taskwriteCreate a new task. IMPORTANT: Only use the fields listed here — no other fields are accepted. The dateEnd field accepts ONLY a date (YYYY-MM-DD), never include a time component.
delete_entitydestructiveDelete any entity record by ID
get_contactreadGet detailed information about a specific contact by ID
get_entityreadGet a specific entity record by ID
get_entity_relationshipsreadGet all related entities for a specific entity and relationship
get_meetingreadGet detailed information about a specific meeting by ID
get_taskreadGet detailed information about a specific task by ID
get_team_membersreadGet all members of a team
get_user_by_emailreadFind a user by their email address
get_user_permissionsreadGet effective permissions for a user based on roles and teams
get_user_teamsreadGet all teams that a user belongs to
health_checkreadCheck EspoCRM connection and API status
link_entitieswriteCreate relationships between any two entities
remove_user_from_teamdestructiveRemove a user from a team
search_accountsreadSearch for accounts/companies using flexible criteria
search_callsreadSearch for calls using flexible criteria
search_casesreadSearch for support cases using flexible criteria
search_contactsreadSearch for contacts using flexible criteria
search_entityreadSearch any entity type with flexible filters. Returns at most 10 records by default — use specific filters to narrow results.
search_leadsreadSearch for leads using flexible criteria
search_meetingsreadSearch for meetings using flexible criteria
search_notesreadSearch for notes/comments across entities
search_opportunitiesreadSearch for sales opportunities using flexible criteria
search_tasksreadSearch for tasks using flexible criteria
search_teamsreadSearch for teams in the system
search_usersreadSearch for users in the EspoCRM system
unlink_entitiesdestructiveRemove relationships between entities
update_casewriteUpdate an existing support case
update_entitywriteUpdate any entity record by ID
update_leadwriteUpdate an existing lead
update_meetingwriteUpdate an existing meeting in EspoCRM
update_taskwriteUpdate an existing task. IMPORTANT: Only use the fields listed here — no other fields are accepted. The dateEnd field accepts ONLY a date (YYYY-MM-DD), never include a time component.
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
EspoMCP/chatbot-bridge/.env.example:12
ESPOCRM_URL=http://100.117.215.126
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
EspoMCP/chatbot-bridge/.env.example:17
CORS_ORIGINS=http://100.117.215.126,http://localhost:3000
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
EspoMCP/chatbot-bridge/src/server.js:44
"http://100.117.215.126",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
EspoMCP/chatbot-bridge/src/server.js:68
"http://100.117.215.126",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_entity, remove_user_from_team, unlink_entities
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
EspoMCP/chatbot-bridge/src/server.js:81
mcpServerPath: path.join(__dirname, '../../build/index.js'),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
EspoMCP/tests/properties/contact-role.prop.test.ts:13
import { formatContactDetails } from '../../src/utils/formatting';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
EspoMCP/tests/properties/contact-role.prop.test.ts:14
import type { Contact } from '../../src/espocrm/types';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
EspoMCP/tests/properties/datetime.prop.test.ts:9
import { FlexibleDateTimeSchema, normalizeDateTime } from '../../src/utils/validation';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
EspoMCP/tests/properties/hmac.prop.test.ts:10
import { EspoCRMClient } from '../../src/espocrm/client';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
EspoMCP/chatbot-bridge/package.json
express, socket.io, cors, helmet, dotenv, openai, ws, uuid
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
EspoMCP/package.json
axios, winston, zod, @types/jest, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 840d75bcbf57full audit observations/trust-audit/mcp-server/zaphod-black__espocrm.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08840d75bcbf57CAUTIONB83first audit
06

Questions

What is the EspoCRM MCP server?

Opensource MCP Server for EspoCRM

What tools does EspoCRM expose?

47 in total: 27 read-only, 17 that write, and 3 that can delete or overwrite (delete_entity, remove_user_from_team, unlink_entities). Every one is listed on this page with its risk.

Is EspoCRM safe to connect to an agent?

With care. The audit graded it B (83/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does EspoCRM need?

It reads ESPOCRM_API_KEY, ESPOCRM_AUTH_METHOD, ESPOCRM_SECRET_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does EspoCRM run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as espocrm-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (840d75bcbf57), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement