
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@chrischall/thumbtack-mcp
Advanced tools
MCP server for Thumbtack — search local service pros and read pro profiles, ratings, reviews and credentials.
Unofficial Thumbtack MCP server — search local service pros, and read their profiles, ratings, reviews and credentials.
Read-only and anonymous. Thumbtack's consumer pages and its GraphQL endpoint answer without a login, so this server needs no account, no API key and no browser extension. It also cannot write: Thumbtack's write paths sit behind a reCAPTCHA-gated login that no server-side client can pass.
Thumbtack has no public consumer API. This server reads its server-rendered pages and anonymous GraphQL endpoint, and may break or violate their ToS. Developed and maintained by AI (Claude). Use at your own discretion.
// .mcp.json
{ "mcpServers": { "thumbtack": { "command": "npx", "args": ["-y", "@chrischall/thumbtack-mcp"] } } }
No configuration — there are no environment variables.
| Tool | What it does |
|---|---|
thumbtack_search_pros | Search pros by trade + US ZIP. Returns up to 10 with rating, review count, lifetime hires, mean response time, profile URL. |
thumbtack_resolve_service | Canonicalise a loose service name (plumbing → plumbers) by asking Thumbtack. |
thumbtack_get_pro | A pro's profile: name, description, location, aggregate rating, credentials, section inventory. |
thumbtack_get_pro_reviews | Reviews on a pro's profile — stars, author, date, text. |
thumbtack_graphql | Escape hatch for arbitrary read-only GraphQL. Mutations refused. |
thumbtack_healthcheck | Probes the page and GraphQL surfaces separately and reports the response shape still matches. |
thumbtack_search_pros returns the full upstream records by default; pass
compact: true for slim summaries. The full records are large and mostly
tracking metadata, so compact: true is usually what you want when an agent
is browsing or ranking.
skills/thumbtack/ is a self-contained skill covering the same surface with
plain curl + jq — no server process. Use it for one-shot lookups and
scripts.
Three verified surfaces, all pinned in docs/THUMBTACK-API.md:
__NEXT_DATA__.window.__APOLLO_STATE__ (a bare JS assignment, so it
needs balanced-brace extraction) plus schema.org JSON-LD.app.thumbtack.com/graphql) — accepts ad-hoc anonymous
queries; introspection is disabled.Two things that bite anyone reading these pages:
@type is the trade-specific subtype, not LocalBusiness — a
plumber's node is "@type":"Plumber". Match by shape, not by type name.errors[] body. Status alone is never
sufficient.developers.thumbtack.com) — real and
documented, but gated behind partner credentials ("Request Access"). It is a
seller surface, not a consumer one.npm install
npm run build
npm test # unit + server-boot smoke tests
npm run test:coverage
Coverage is enforced at 100%.
MIT
FAQs
MCP server for Thumbtack — search local service pros and read pro profiles, ratings, reviews and credentials.
We found that @chrischall/thumbtack-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.