TwitterBLOCK
Model Context Protocol Server for Accessing twitter
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A comprehensive Model Context Protocol server implementation for X (Twitter) API integration with professional workflow automation, enhanced error handling, and real-time documentation.
🚀 Features
- 53 Total Tools - 33 Twitter API + 20 enhanced SocialData.tools research capabilities
- Advanced Analytics - Thread analysis, network mapping, sentiment analysis, viral tracking
- Bypasses API Restrictions - Enhanced research tools work without Pro tier requirements
- Professional Error Handling - Clear upgrade guidance and graceful API key handling
- 5 Workflow Prompts - Pre-built automation templates
- 6 Dynamic Resources - Real-time API documentation and status
- Full MCP Compliance - Tools, prompts, and resources support
📋 Quick Start
Prerequisites
- Node.js 18+
- npm or yarn
- X (Twitter) API credentials (Basic tier minimum - $200/month)
Local Installation
- Clone and Install
git clone cd twitter-server npm install
- Environment Setup
cp .env.example .env # Edit .env with your credentials
Required Environment Variables:
# Twitter API credentials (Required) X_API_KEY=your_api_key_here X_API_SECRET=your_api_secret_here X_ACCESS_TOKEN=your_access_token_here X_ACCESS_TOKEN_SECRET=your_access_token_secret_here # SocialData.tools API key (Optional - enables enhanced research tools) SOCIALDATA_API_KEY=your_socialdata_api_key_here SOCIALDATA_BASE_URL=https://api.socialdata.tools # Optional, uses default if not set
- Build and Run
npm run build npm start
- Test the Server
# Test with JSON-RPC calls
source .env && echo '{"jsonrpc": "2.0", "id": 1, "method": "tools/list"}' | node dist/index.js
# aa0fbb58c8c7OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-twitter-server --env BEARER_TOKEN=${BEARER_TOKEN} --env CONSUMER_SECRET=${CONSUMER_SECRET} --env CONSUMER_TOKEN=${CONSUMER_TOKEN} --env DOTENV_CONFIG_DOTENV_KEY=${DOTENV_CONFIG_DOTENV_KEY} -- npx -y [email protected]{
"mcpServers": {
"mcp-twitter-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"BEARER_TOKEN": "${BEARER_TOKEN}",
"CONSUMER_SECRET": "${CONSUMER_SECRET}",
"CONSUMER_TOKEN": "${CONSUMER_TOKEN}",
"DOTENV_CONFIG_DOTENV_KEY": "${DOTENV_CONFIG_DOTENV_KEY}"
}
}
}
}Exposed tools (16)
16 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analytics-report | read | Generate comprehensive Twitter analytics and engagement reports |
audience | read | Target audience for the tweet |
business_type | read | Type of business or personal brand |
campaign_type | read | Type of campaign or content |
community-management | read | Best practices for managing Twitter community interactions and responses |
compose-tweet | read | Guide for composing effective tweets with hashtags, mentions, and engagement strategies |
content-strategy | read | Develop a Twitter content strategy with scheduling and engagement recommendations |
goals | read | Primary goals (growth, engagement, sales, awareness) |
hashtag-research | read | Research and recommend relevant hashtags for better tweet discoverability |
industry | read | Industry or niche for hashtag research |
period | read | Time period for analysis (recent, week, month) |
scenario | read | Type of interaction (customer service, crisis management, general engagement) |
tone | read | The desired tone (professional, casual, humorous, informative) |
topic | read | The main topic or subject of the tweet |
twitter-help | read | Get help with Twitter MCP server tools and usage |
username | read | Twitter username to analyze |
Trust audit
BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
var deprecatedfn = new Function('fn', 'log', 'deprecate', 'message', 'site','return function (' + args + ') {' +exec(string: string): RegExpExecArray | null;
request ~ requests
node_modules/.bin/tsc
node_modules/.bin/tsserver
* console.log(myURL.password);
"chars": "€پ‚ƒ„...†‡ˆ‰ٹ‹Œچژڈگ‘’“”•–—کTMڑ›œں ،¢£¤¥¦§ ̈©ھ«¬® ̄°±23 ́μ¶· ̧1؛»1⁄41⁄23⁄4؟ہءآأؤإئابةتثجحخدذرزسشصض×طظعغـفقكàلâمنهوçèéêëىيîïًٌٍَôُِ÷ّùْûüے"
"chars": "«»...“”�•‘’� กขฃคฅฆงจฉชซฌญฎฏฐฑฒณดตถทธนบปผฝพฟภมยรฤลฦวศษสหฬอฮฯะัาําิีึืฺุู–—฿เแโใไๅๆ็่้๊๋์ํTM๏๐๑๒๓๔๕๖๗๘๙®©����"
PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----\nKh9NV...\n-----END RSA PRIVATE KEY-----\n"
PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----\nKh9NV...\n-----END RSA PRIVATE KEY-----\n"
.roomodes
.taskmasterconfig
.windsurfrules
.package-lock.json
dotenv.config({ path: __dirname + '/../../.env' });import type { ClientRequestMaker } from '../../client-mixins/request-maker.mixin';dotenv.config({ path: __dirname + '/../../.env' });import type { ClientRequestMaker } from '../../client-mixins/request-maker.mixin';import { getSocialDataClient } from '../../socialDataClient.js';function atob(data: string): string;
atob(data: string): string;
declare function atob(data: string): string;
Gates applied: no_behavioural_pass.
aa0fbb58c8c7full audit observations/trust-audit/mcp-server/crazyrabbitltc__twitter.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | aa0fbb58c8c7 | BLOCK | F | 44 | first audit |
Questions
What is the Twitter MCP server?
Model Context Protocol Server for Accessing twitter
What tools does Twitter expose?
16 in total: 16 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Twitter safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (44/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Twitter need?
It reads BEARER_TOKEN, CONSUMER_SECRET, CONSUMER_TOKEN, DOTENV_CONFIG_DOTENV_KEY, DOTENV_KEY, OAUTH_SECRET, OAUTH_TOKEN, SOCIALDATA_API_KEY, X_ACCESS_TOKEN, X_ACCESS_TOKEN_SECRET, X_API_KEY and X_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Twitter run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as mcp-twitter-server at 0.4.0.
How current is this page?
The grade is for one exact copy of the source (aa0fbb58c8c7), read on 2026-10-09. The repository is watched and re-audited when it changes.