# io.github.philly88r/localtry-mcp

Operate and customize one tenant-isolated LocalTry CRM. ChatGPT plugin coming soon.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.1
- **Author:** io.github.philly88r
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.localtry.com/mcp
- **Source:** https://github.com/philly88r/localtry-mcp
- **Endpoint health:** reachable (last checked 2026-10-03T06:28:48.970Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 34 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-01T10:03:00.734Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

12 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `get_workspace_overview` — Inspect the authenticated business's complete LocalTry feature catalog: every registered page, action, agent, integration, workflow, tenant addition, and custom
- `search_localtry_features` — Search the authenticated business's live LocalTry capability registry before choosing an action. Returns exact pages, actions, agents, integrations, additions, 
- `search_crm` — Search the authenticated business's CRM. The server chooses safe tenant-scoped queries; raw SQL and tenant identifiers are not accepted.
- `create_or_update_crm_record` — Create or update one CRM record for the authenticated business using LocalTry domain rules and validation.
- `create_workflow_agent` — Create a reusable AI agent for the authenticated business. Describe the agent's duties; LocalTry writes and saves its tenant-scoped instruction, then makes the 
- `request_workspace_customization` — Submit a plain-language request to the authenticated business's Customize Workspace builder. This is the same action as entering the request in LocalTry and pre
- `get_workspace_customization_status` — Read the authenticated business's latest Customize Workspace request, conversation, progress, questions, errors, and completed result.
- `list_workspace_versions` — List versioned customization history for the authenticated tenant.
- `restore_workspace_version` — Restore an earlier workspace version for the authenticated tenant after explicit approval.
- `run_workflow` — Run one saved workflow belonging to the authenticated tenant. Publishing and communication steps still enforce their own approvals.
- `run_localtry_command` — Use any AI-ready LocalTry feature through the authenticated business's live capability registry. LocalTry chooses and executes its own tenant-scoped domain acti
- `get_recent_activity` — Show recent CRM actions, workflow runs, and workspace changes for the authenticated tenant.

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"localtry-mcp\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.localtry.com/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs commands; runs on someone else's infrastructure.
- Floor 40, ceiling 68 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.philly88r%2Flocaltry-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.philly88r%2Flocaltry-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.philly88r%2Flocaltry-mcp
- HTML page: https://forgeregistry.com/registry/io.github.philly88r%2Flocaltry-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
