Atlas / MCP servers / crazyrabbitltc / Twitter

TwitterBLOCK

mcp/crazyrabbitltc/twitter

Model Context Protocol Server for Accessing twitter

Verdict
BLOCK
Grade
F
Trust score
44 /100
Exposed tools
16 16r · 0w · 0d
Transport
sse · stdio
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A comprehensive Model Context Protocol server implementation for X (Twitter) API integration with professional workflow automation, enhanced error handling, and real-time documentation.

🚀 Features

  • 53 Total Tools - 33 Twitter API + 20 enhanced SocialData.tools research capabilities
  • Advanced Analytics - Thread analysis, network mapping, sentiment analysis, viral tracking
  • Bypasses API Restrictions - Enhanced research tools work without Pro tier requirements
  • Professional Error Handling - Clear upgrade guidance and graceful API key handling
  • 5 Workflow Prompts - Pre-built automation templates
  • 6 Dynamic Resources - Real-time API documentation and status
  • Full MCP Compliance - Tools, prompts, and resources support

📋 Quick Start

Prerequisites

  • Node.js 18+
  • npm or yarn
  • X (Twitter) API credentials (Basic tier minimum - $200/month)

Local Installation

  1. Clone and Install
git clone 
cd twitter-server
npm install
  1. Environment Setup
cp .env.example .env
# Edit .env with your credentials

Required Environment Variables:

# Twitter API credentials (Required)
X_API_KEY=your_api_key_here
X_API_SECRET=your_api_secret_here  
X_ACCESS_TOKEN=your_access_token_here
X_ACCESS_TOKEN_SECRET=your_access_token_secret_here

# SocialData.tools API key (Optional - enables enhanced research tools)
SOCIALDATA_API_KEY=your_socialdata_api_key_here
SOCIALDATA_BASE_URL=https://api.socialdata.tools  # Optional, uses default if not set
  1. Build and Run
npm run build
npm start
  1. Test the Server
# Test with JSON-RPC calls
source .env && echo '{"jsonrpc": "2.0", "id": 1, "method": "tools/list"}' | node dist/index.js

# 
Read from source at commit aa0fbb58c8c7OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-twitter-server --env BEARER_TOKEN=${BEARER_TOKEN} --env CONSUMER_SECRET=${CONSUMER_SECRET} --env CONSUMER_TOKEN=${CONSUMER_TOKEN} --env DOTENV_CONFIG_DOTENV_KEY=${DOTENV_CONFIG_DOTENV_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-twitter-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "BEARER_TOKEN": "${BEARER_TOKEN}",
        "CONSUMER_SECRET": "${CONSUMER_SECRET}",
        "CONSUMER_TOKEN": "${CONSUMER_TOKEN}",
        "DOTENV_CONFIG_DOTENV_KEY": "${DOTENV_CONFIG_DOTENV_KEY}"
      }
    }
  }
}
03

Exposed tools (16)

16 read · 0 write · 0 destructive.

ToolRiskDescription
analytics-reportreadGenerate comprehensive Twitter analytics and engagement reports
audiencereadTarget audience for the tweet
business_typereadType of business or personal brand
campaign_typereadType of campaign or content
community-managementreadBest practices for managing Twitter community interactions and responses
compose-tweetreadGuide for composing effective tweets with hashtags, mentions, and engagement strategies
content-strategyreadDevelop a Twitter content strategy with scheduling and engagement recommendations
goalsreadPrimary goals (growth, engagement, sales, awareness)
hashtag-researchreadResearch and recommend relevant hashtags for better tweet discoverability
industryreadIndustry or niche for hashtag research
periodreadTime period for analysis (recent, week, month)
scenarioreadType of interaction (customer service, crisis management, general engagement)
tonereadThe desired tone (professional, casual, humorous, informative)
topicreadThe main topic or subject of the tweet
twitter-helpreadGet help with Twitter MCP server tools and usage
usernamereadTwitter username to analyze
04

Trust audit

BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (5 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/depd/index.js:425
var deprecatedfn = new Function('fn', 'log', 'deprecate', 'message', 'site',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/depd/index.js:427
'return function (' + args + ') {' +
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/typescript/lib/lib.es5.d.ts:998
exec(string: string): RegExpExecArray | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHSupply chain · supply.typosquat · CWE-829, CWE-1357
node_modules/iconv-lite/package.json
request ~ requests
Why it matters. dependency name one edit from a popular package
Fix. verify the package; likely typosquat
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/tsc
node_modules/.bin/tsc
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/tsserver
node_modules/.bin/tsserver
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
node_modules/@types/node/url.d.ts:543
* console.log(myURL.password);
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
node_modules/iconv-lite/encodings/sbcs-data-generated.js:100
"chars": "€پ‚ƒ„...†‡ˆ‰ٹ‹Œچژڈگ‘’“”•–—کTMڑ›œں ،¢£¤¥¦§ ̈©ھ«¬® ̄°±23 ́μ¶· ̧1؛»1⁄41⁄23⁄4؟ہءآأؤإئابةتثجحخدذرزسشصض×طظعغـفقكàلâمنهوçèéêëىيîïًٌٍَôُِ÷ّùْûüے"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
node_modules/iconv-lite/encodings/sbcs-data-generated.js:373
"chars": "«»...“”�•‘’� กขฃคฅฆงจฉชซฌญฎฏฐฑฒณดตถทธนบปผฝพฟภมยรฤลฦวศษสหฬอฮฯะัาําิีึืฺุู–—฿เแโใไๅๆ็่้๊๋์ํTM๏๐๑๒๓๔๕๖๗๘๙®©����"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
node_modules/dotenv/README-es.md:112
PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
node_modules/dotenv/README-es.md:122
PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----\nKh9NV...\n-----END RSA PRIVATE KEY-----\n"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
node_modules/dotenv/README.md:112
PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
node_modules/dotenv/README.md:122
PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----\nKh9NV...\n-----END RSA PRIVATE KEY-----\n"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.roomodes
.roomodes
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.taskmasterconfig
.taskmasterconfig
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.windsurfrules
.windsurfrules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
node_modules/.package-lock.json
.package-lock.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
node_modules/twitter-api-v2/dist/cjs/test/utils.js:29
dotenv.config({ path: __dirname + '/../../.env' });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
node_modules/twitter-api-v2/dist/cjs/types/plugins/client.plugins.types.d.ts:9
import type { ClientRequestMaker } from '../../client-mixins/request-maker.mixin';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
node_modules/twitter-api-v2/dist/esm/test/utils.js:3
dotenv.config({ path: __dirname + '/../../.env' });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
node_modules/twitter-api-v2/dist/esm/types/plugins/client.plugins.types.d.ts:9
import type { ClientRequestMaker } from '../../client-mixins/request-maker.mixin';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/socialdata/analytics.handlers.ts:5
import { getSocialDataClient } from '../../socialDataClient.js';
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
node_modules/@types/node/buffer.d.ts:1897
function atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
node_modules/typescript/lib/lib.webworker.d.ts:8713
atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
node_modules/typescript/lib/lib.webworker.d.ts:9525
declare function atob(data: string): string;

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha aa0fbb58c8c7full audit observations/trust-audit/mcp-server/crazyrabbitltc__twitter.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09aa0fbb58c8c7BLOCKF44first audit
06

Questions

What is the Twitter MCP server?

Model Context Protocol Server for Accessing twitter

What tools does Twitter expose?

16 in total: 16 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Twitter safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (44/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Twitter need?

It reads BEARER_TOKEN, CONSUMER_SECRET, CONSUMER_TOKEN, DOTENV_CONFIG_DOTENV_KEY, DOTENV_KEY, OAUTH_SECRET, OAUTH_TOKEN, SOCIALDATA_API_KEY, X_ACCESS_TOKEN, X_ACCESS_TOKEN_SECRET, X_API_KEY and X_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Twitter run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as mcp-twitter-server at 0.4.0.

How current is this page?

The grade is for one exact copy of the source (aa0fbb58c8c7), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement