Atlas / MCP servers / claude-world / Trend Pulse

Trend PulseCAUTION

mcp/claude-world/trend-pulse

Free trending topics aggregator — 20 sources, zero auth. CLI + Python library + MCP Server.

Verdict
CAUTION
Grade
B
Trust score
88 /100
Exposed tools
29 26r · 3w · 0d
Transport
—
License
MIT
Stars
62
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/claude-world/trend-pulse/actions/workflows/ci.yml) [](https://pypi.org/project/trend-pulse/) [](https://pypi.org/project/trend-pulse/) [](LICENSE)

Agentic Trend Intelligence Platform — 37 sources, plugin system, vector search, lifecycle prediction, 6-agent content factory, web dashboard, and 29-tool MCP server.

Use as a Python library, CLI tool, MCP server for Claude Code / AI agents, or a standalone web dashboard.

One-line MCP setup (zero install):

{ "mcpServers": { "trend-pulse": { "command": "uvx", "args": ["--from", "trend-pulse[mcp]", "trend-pulse-server"], "type": "stdio" } } }
Paste into .mcp.json and you're done. Requires uv (brew install uv or curl -LsSf https://astral.sh/uv/install.sh | sh).

Sources

Built-in Sources (20)

All built-in sources are free and require zero authentication:

Read from source at commit 8a8e30950dc1OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add trend-pulse --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CF_API_TOKEN=${CF_API_TOKEN} --env LINE_NOTIFY_TOKEN=${LINE_NOTIFY_TOKEN} --env SMTP_PASS=${SMTP_PASS} -- uvx trend-pulse
claude-desktop
{
  "mcpServers": {
    "trend-pulse": {
      "command": "uvx",
      "args": [
        "trend-pulse"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "CF_API_TOKEN": "${CF_API_TOKEN}",
        "LINE_NOTIFY_TOKEN": "${LINE_NOTIFY_TOKEN}",
        "SMTP_PASS": "${SMTP_PASS}"
      }
    }
  }
}
03

Exposed tools (29)

26 read · 3 write · 0 destructive.

ToolRiskDescription
adapt_contentreadAdapt content from one platform format to another.
analyze_viral_factorsreadDeep analysis of what makes (or doesn
batch_score_contentreadScore multiple posts at once using the Hybrid Scoring 2.0 engine.
compare_trendsreadCompare two trend keywords side-by-side.
export_datareadExport trend data in JSON or CSV format.
generate_hashtagsreadGenerate optimized hashtags for a topic and platform.
get_ab_variantsreadGenerate A/B content variants for testing different approaches.
get_campaign_calendarreadGenerate a content calendar for multiple topics over N days.
get_content_briefreadGet a structured writing brief for creating viral content.
get_lifecycle_predictionreadPredict the lifecycle stage of a trend keyword.
get_platform_specsreadGet platform specifications for content adaptation.
get_reel_guidereadGet a structured guide for creating Reels/Short video scripts.
get_review_checklistreadGet a structured review checklist for evaluating content quality.
get_scoring_guidereadGet the 5-dimension scoring framework for evaluating posts.
get_source_statusreadCheck health status of all registered trend sources.
get_trend_clustersreadCluster trends from multiple sources into semantic topic groups.
get_trend_historyreadQuery historical trend data for a keyword.
get_trend_reportreadGenerate an automated trend intelligence report.
get_trend_velocityreadGet real-time velocity and momentum for a trend keyword.
get_trendingreadGet trending topics from free sources.
list_sourcesreadList all available trend sources and their properties.
list_sources_extendedreadList all available trend sources with extended plugin metadata.
render_pagereadRender a JS-heavy page using Cloudflare Browser Rendering.
run_content_workflowwriteRun the full 6-agent content workflow to auto-generate viral posts.
score_content_hybridreadScore content using the Hybrid Scoring 2.0 engine.
search_semanticreadSemantic similarity search across trend sources.
search_trendsreadSearch for a keyword across trend sources.
send_notificationwriteSend a trend alert notification to a configured channel.
take_snapshotwriteTake a trend snapshot: fetch from all sources and save to history DB.
04

Trust audit

CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (9)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/trend_pulse/plugins/registry.py:49
module = importlib.import_module(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/trend_pulse/plugins/registry.py:92
module = importlib.import_module(module_name)
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_plugins.py:176
module = importlib.import_module(f"trend_pulse.plugins.sources.{module_info.name}")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_server.py:155
("http://192.168.1.1/", "Blocked: private/loopback"),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_server.py:156
("http://127.0.0.1:8080/", "Blocked: private/loopback"),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_server.py:157
("http://10.0.0.1/secret", "Blocked: private/loopback"),
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:18
> Paste into `.mcp.json` and you're done. Requires [uv](https://docs.astral.sh/uv/) (`brew install uv` or `curl -LsSf https://astral.sh/uv/install.sh | sh`).
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:87
> `uvx` is the Python equivalent of `npx`. It comes with [uv](https://docs.astral.sh/uv/) — install uv with `curl -LsSf https://astral.sh/uv/install.sh | sh`
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:221
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 8a8e30950dc1full audit observations/trust-audit/mcp-server/claude-world__trend-pulse.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088a8e30950dc1CAUTIONB88first audit
06

Questions

What is the Trend Pulse MCP server?

Free trending topics aggregator — 20 sources, zero auth. CLI + Python library + MCP Server.

What tools does Trend Pulse expose?

29 in total: 26 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Trend Pulse safe to connect to an agent?

With care. The audit graded it B (88/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Trend Pulse need?

It reads ANTHROPIC_API_KEY, CF_API_TOKEN, LINE_NOTIFY_TOKEN, SMTP_PASS, TELEGRAM_BOT_TOKEN, X_BEARER_TOKEN and YOUTUBE_INNERTUBE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (8a8e30950dc1), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement