Skip to content

MCP servers › io.github.LeadFox-Shay › leadfoxconnect

MCP server · registry snapshot 2026-10-04 · last tested 2026-10-09

io.github.LeadFox-Shay/leadfoxconnect

Marketo MCP server for AI. 130 tools to operate Marketo from Claude, Cursor, or ChatGPT. — the publisher's description

Topic: commerce-and-marketing · AI-classifiedPricing: freemium · AI-classifiedversion 0.1.0streamable HTTP

Summary

io.github.LeadFox-Shay/leadfoxconnect is a remote MCP server listed in the official MCP registry at version 0.1.0. On 2026-10-09 no session could be opened with it. None of the 18 checks that apply to it could be exercised. Results of the checks are published only after we have verified them and told the publisher.

No session

No session could be opened when we tried, so no check could run. No security score is given; a check we did not run is never counted as passed.

Key facts

Runs
remote (hosted by the publisher)
Transport
streamable HTTP
Repository
public
Topic
commerce-and-marketingAI-classified
Pricing
freemiumAI-classified
Last tested
2026-10-09
The 18 checks at a glanceour test · 2026-10-09
  1. Inventory: not run · no session
  2. Hidden instructions: not run · no session
  3. Real execution: not run · no session
  4. Secret leak: not run · no session
  5. Internal addresses: not run · no session
  6. Unconfirmed changes: not run · no session
  7. Bad input: not run · no session
  8. Model requests: not run · no session
  9. Sensitive questions: not run · no session
  10. Folder boundary: not run · no session
  11. Log leaks: not run · no session
  12. Hidden content: not run · no session
  13. Fake assistant turns: not run · no session
  14. Token passthrough: not run · no session
  15. Token audience: not run · no session
  16. Sign-in redirect: not run · no session
  17. Consent handling: not run · no session
  18. Sign-in metadata: not run · no session

0 exercised18 not run (reason given)0 not applicable

How fresh this is

Live-tested
attempted, see below
Last tested
2026-10-09
Registry data
snapshot 2026-10-04
Package and repository
checked 2026-10-06
Engine
mcp-runtime-engine@0.1.0 · sdk@1.32.0

Security testing

What did we test, and what did we leave out?

18 checks · features #1, #2

Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). None of the 18 checks that apply to it could be exercised. Results of the checks are published only after we have verified them and told the publisher.

Not run, with the reason · 18
  • 1Inventory
    tool-list
    Reads the declared tools, resources and prompts.No session could be opened with the server, so no check could run.not run · no session
  • 2Hidden instructions
    description-poisoning
    Looks for hidden instructions in tool descriptions.No session could be opened with the server, so no check could run.not run · no session
  • 3Real execution
    real-execution
    Calls a tool and checks what really happens.No session could be opened with the server, so no check could run.not run · no session
  • 4Secret leak
    canary-leak
    Plants a fake secret and checks whether it leaks.No session could be opened with the server, so no check could run.not run · no session
  • 5Internal addresses
    ssrf
    Checks whether a tool can be steered to internal addresses.No session could be opened with the server, so no check could run.not run · no session
  • 6Unconfirmed changes
    write-without-confirmation
    Checks whether tools that change data act without asking.No session could be opened with the server, so no check could run.not run · no session
  • 7Bad input
    error-handling
    Sends bad input and watches how the server answers.No session could be opened with the server, so no check could run.not run · no session
  • 8Model requests
    sampling
    Checks whether the server asks the client's model to act for it.No session could be opened with the server, so no check could run.not run · no session
  • 9Sensitive questions
    elicitation-sensitive-data
    Checks whether the server asks users for sensitive data.No session could be opened with the server, so no check could run.not run · no session
  • 10Folder boundary
    root-boundary
    Checks whether the server reaches outside the folders it was given.No session could be opened with the server, so no check could run.not run · no session
  • 11Log leaks
    logging-side-channel
    Checks whether log messages carry data they should not.No session could be opened with the server, so no check could run.not run · no session
  • 12Hidden content
    audience-hiding
    Checks resources that hide content from the user.No session could be opened with the server, so no check could run.not run · no session
  • 13Fake assistant turns
    fake-assistant-turn
    Checks prompts that pose as the assistant's own words.No session could be opened with the server, so no check could run.not run · no session
  • 14Token passthrough
    token-passthrough
    Checks whether the server forwards a user's token to other services.No session could be opened with the server, so no check could run.not run · no session
  • 15Token audience
    token-audience-validation
    Checks whether tokens meant for another service are accepted.No session could be opened with the server, so no check could run.not run · no session
  • 16Sign-in redirect
    open-redirect
    Checks the sign-in redirect for abuse.No session could be opened with the server, so no check could run.not run · no session
  • 17Consent handling
    confused-deputy
    Checks consent handling when one service acts for another.No session could be opened with the server, so no check could run.not run · no session
  • 18Sign-in metadata
    oauth-url-scheme
    Checks the published sign-in metadata for unsafe URLs.No session could be opened with the server, so no check could run.not run · no session

Source: our own test, 2026-10-09, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model.

What happened during the test?

Feature #8

The steps in order, as the test record holds them.

  1. 0 msStarted a session with the server's remote endpoint
  2. No session could be opened.
  3. 139 msFinished: 0 checks exercised.

What it is

Does the registry listing match what we found?

Feature #6

The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.

Registry saysWe foundResultSource · date
Remote endpoint app.leadfoxconnect.com/mcpNo session could be opened when we triedno sessionour test · 2026-10-09
Repository github.com/LeadFox-Shay/leadfoxconnectOpens publiclymatchesapi.github.com · 2026-10-06

Who made it?

Feature #7 · lineage

Facts about the publisher. We do not turn them into a trust score.

Namespace
io.github.LeadFox-Shay
GitHub owner
a personal account (LeadFox-Shay)
Repository
github.com/LeadFox-Shay/leadfoxconnect
Stars
0
Repository age
91–180 days
Last push
91–180 days ago
Archived
no

Source: the registry entry and api.github.com · 2026-10-06.

Choosing

Common questions about io.github.LeadFox-Shay/leadfoxconnect

Answered from the data above

Is io.github.LeadFox-Shay/leadfoxconnect free to use?

Its website (leadfoxconnect.com/) describes a freemium pricing model. This is an AI-classified reading of the page on 2026-10-08, so check the page itself before relying on it.

Has io.github.LeadFox-Shay/leadfoxconnect been security tested?

We tried, but no check could run. None of the 18 checks that apply to it could be exercised. No session could be opened when we tried, so no check could run. No security verdict is published before verification.

Where is the source code of io.github.LeadFox-Shay/leadfoxconnect?

In github.com/LeadFox-Shay/leadfoxconnect, which opens publicly.

Reference

How is it classified?

18 fields

One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.

TopicAI-classified
commerce-and-marketing
AI-classified · 2026-10-08
Pricing modelAI-classified
freemium
read from leadfoxconnect.com/ · 2026-10-08

“Paid plans will be priced per connected Marketo instance, with a free tier for individuals and evaluation.”

Programming language
not stated
GitHub detects no source language in this repository (docs-only or empty)
Hosting type
remote (hosted by the publisher)
registry · 2026-10-04
MCP capability
not checked
not read (no session)
Transport
streamable HTTP
registry · 2026-10-04
Required credentials
none declared
registry · no declaration is not a guarantee
Package registry
does not apply
remote-only server: no package is shipped, so there is no package registry
Freshness
91–180 days
registry updatedAt · 2026-10-04
Lifecycle status
active
registry · 2026-10-04
License class
does not apply
remote-only server: ships no package, so there is nothing to look up in a package registry
Integrity hash
does not apply
remote-only server: ships no package, so there is nothing to look up in a package registry
Signature / provenance
does not apply
remote-only server: ships no package, so there is nothing to look up in a package registry
Dependency advisories
does not apply
ships no package, so there are no dependencies to audit
Popularity
does not apply
remote-only server: ships no package, so there is nothing to look up in a package registry
Publisher signals
owner: a personal account · repository age: 91–180 days · stars: 0–9
api.github.com · 2026-10-06
Maintenance
slowing (no push for a while)
api.github.com · 2026-10-06
Environment
the publisher's infrastructure
where it runs, from the hosting type

“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.

Cite or correct this page

Sources and corrections

Suggested citation

ProtocolProbe. “io.github.LeadFox-Shay/leadfoxconnect: MCP server record.” Data checked 2026-10-09. https://protocolprobe.com/mcp/servers/io.github.LeadFox-Shay/leadfoxconnect

Figures are valid for the date shown. Our facts on this page are CC BY 4.0: reuse them with a link and the check date. Quoted text (the publisher’s descriptions, website quotes, tool names) is not ours to license.

As JSON: this record in the API · API documentation.

Something wrong, or is this yours?

If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.

Write to hello@protocolprobe.com · corrections log · methodology