
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
ictcontact-mcp
Advanced tools
Model Context Protocol server for ICTContact and ICTDialer. Lets AI assistants monitor outbound call-center campaigns and, with writes enabled, start and stop them.
A Model Context Protocol server for ICTContact and its hosted edition ICTDialer.com — the same contact-center engine from ICT Innovations.
It lets an AI assistant monitor outbound campaigns — list them, check status, read summaries and per-call results — and, only when you turn writes on, start and stop them.
npx -y ictcontact-mcp # no install
npm install -g ictcontact-mcp
Requires Node.js 18 or newer.
| Variable | Required | Default | |
|---|---|---|---|
ICTCONTACT_BASE_URL | yes | Server base URL, without the /rest suffix, e.g. https://your-ictcontact | |
ICTCONTACT_USERNAME | yes | API account username | |
ICTCONTACT_PASSWORD | yes | Password for that account | |
ICTCONTACT_MCP_ALLOW_WRITE | no | false | Unlock start/stop campaign (see Safety) |
ICTCONTACT_TIMEOUT_MS | no | 30000 | Per-request timeout |
ICTCONTACT_TLS_INSECURE | no | false | Skip TLS verification — self-signed test servers only |
{
"mcpServers": {
"ictcontact": {
"command": "npx",
"args": ["-y", "ictcontact-mcp"],
"env": {
"ICTCONTACT_BASE_URL": "https://your-ictcontact",
"ICTCONTACT_USERNAME": "admin",
"ICTCONTACT_PASSWORD": "your-password"
}
}
}
}
Read tools are always available:
| Tool | What it does |
|---|---|
ictcontact_list_campaigns | List campaigns (id and name) |
ictcontact_campaign_status | Live status of a campaign (running, stopped) |
ictcontact_campaign_summary | Totals: answered, failed, human vs machine |
ictcontact_campaign_result | Per-call results (contact, response, AMD, DNC) |
Write tools appear only when ICTCONTACT_MCP_ALLOW_WRITE=true:
| Tool | What it does |
|---|---|
ictcontact_start_campaign | Launch a campaign — begins live outbound calling |
ictcontact_stop_campaign | Stop a running campaign |
The server is read-only by default. Starting a campaign begins live outbound
calling and can cost real money, so ictcontact_start_campaign and
ictcontact_stop_campaign are not registered at all unless you set
ICTCONTACT_MCP_ALLOW_WRITE=true.
ICTContact and ICTDialer expose a form-encoded RPC API at {base}/rest/<Method>.
Each call carries the account username and password; the server sends those for
you. There is no separate token to provision.
Built by Tahir Almas at ICT Innovations — the team behind ICTContact, ICTDialer, ICTBroadcast, ICTFax and ICTPBX. Learn more at ictcontact.com and ictdialer.com.
MIT licensed. Issues and PRs welcome at github.com/ictinnovations/ictcontact-mcp.
FAQs
Model Context Protocol server for ICTContact and ICTDialer. Lets AI assistants monitor outbound call-center campaigns and, with writes enabled, start and stop them.
We found that ictcontact-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.