RetailCRM plugin for Codex and Claude Code
RetailCRM plugin
The RetailCRM plugin: a remote GraphQL MCP server plus a skill that safely searches the schema and confirms mutations with the user
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Mutations can change orders, customers, deliveries, payments and conversations in the live RetailCRM account
- The skill requires confirmation before a mutation, but reads are available to the agent without limits
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add plugins/retailcrm-pluginDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run one by one in the Claude Code chat
/plugin marketplace add ilyavlasoff/retailcrm-plugin
/plugin install retailcrm@retailcrm-pluginIn Claude Code, run claude plugin marketplace add ilyavlasoff/RetailCRM-Plugin, then claude plugin install retailcrm@retailcrm-plugin, and start a new session for the plugin to become available.
Other ways from the author
claude plugin marketplace add ilyavlasoff/RetailCRM-Plugin
claude plugin install retailcrm@retailcrm-pluginInstalling the plugin in Claude Code, from the README.
This is third-party code. Review the repository files before installing.
What it does
The plugin combines two parts. First, a remote MCP server retailcrm_mcp at mcp.rcrm-tech.ru that provides tools to search RetailCRM GraphQL API operations, fetch their contracts, resolve types, and execute queries and mutations. Second, a use-retailcrm skill with a step-by-step protocol for the agent: find a suitable operation, fetch only the needed part of the schema, build a minimal GraphQL document, validate it fully, and only then execute it, with a mutation requiring separate explicit user confirmation before running. One repository installs both as an OpenAI Codex marketplace plugin and in Claude Code.
Who it is for. For RetailCRM teams who want to give an agent access to orders, customers and other CRM entities through a safe confirmation protocol.
Good fit when
- You need agent access to arbitrary RetailCRM entities via GraphQL without hand-writing queries
- You need mutations to run only after separate user confirmation
- You need one repository that installs into both OpenAI Codex and Claude Code
Not a fit when
- You need confirmed vendor official status: the plugin is hosted on the developer's personal GitHub account, not the RetailCRM organization
- You need a local server with no calls to the external host mcp.rcrm-tech.ru
- You want to work with the RetailCRM REST API directly rather than through GraphQL
Example request
Find all RetailCRM orders for this customer by email and show their statuses without changing anythingLimitations
The README calls the plugin official for RetailCRM and lists the plugin.json author as RetailCRM Team, but the repository itself belongs to the developer's personal account ilyavlasoff, not a RetailCRM organization on GitHub, so official status cannot be confirmed from GitHub alone. The MCP server is remote and hosted on the third-party host mcp.rcrm-tech.ru; the server's own source code is not published in this repository, only the client side (plugin and skill).
How to disable. Remove the plugin with claude plugin uninstall retailcrm in Claude Code, or by removing the marketplace in OpenAI Codex.
Security check
- Mutations can change orders, customers, deliveries, payments and conversations in the live RetailCRM account
- The skill requires confirmation before a mutation, but reads are available to the agent without limits
README in short
The Russian README describes the plugin as combining the RetailCRM MCP server and the use-retailcrm skill, giving step-by-step install instructions for OpenAI Codex via a marketplace and for Claude Code via claude plugin marketplace add and claude plugin install. It separately stresses that the skill safely locates operations and schema types before running a request and never lets a mutation through without user confirmation.
SKILL.md
--- name: use-retailcrm description: Use retailcrm_mcp to work with the official RetailCRM GraphQL API: search and inspect the schema, then build, validate, and execute arbitrary GraphQL queries and mutations. Apply when reading or changing data in a connected RetailCRM account, including orders, customers, deliveries, payments, products, inventory, users, chats, conversations, messages, quick replies, bots, channels, templates, and other CRM entities. --- # Use RetailCRM Communicate with the user in the language of their request. Work with RetailCRM only through retailcrm_mcp. Do not bypass retailcrm_mcp with direct HTTP requests or use guessed API methods. Do not request, expose, or store access tokens. If retailcrm_mcp is unavailable or returns 401/403, explain that its connection or authentication must be configured outside this skill, then stop.
FAQ
Does installing the plugin require an OAuth login?
No, the README states plainly that installing the plugin needs no OAuth login.
Can the agent run a mutation right away?
No, the skill requires separate explicit user confirmation before executing any mutation.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail