YutuSAFE
The AI-powered toolkit that grows your YouTube channel on autopilot.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://gitmoji.dev) [](https://github.com/eat-pray-ai/yutu?tab=Apache-2.0-1-ov-file) [](https://pkg.go.dev/github.com/eat-pray-ai/yutu) [](https://raw.githack.com/wiki/eat-pray-ai/yutu/coverage.html)
[](https://github.com/eat-pray-ai/yutu/stargazers) [](https://github.com/eat-pray-ai/yutu/releases/latest) [](https://github.com/eat-pray-ai/yutu/actions/workflows/publish.yml) [](https://github.com/eat-pray-ai/yutu/actions/workflows/codeql.yml) [](https://github.com/eat-pray-ai/yutu/actions/workflows/test.yml) [](https://linux.do/tag/2234-tag/2234)
[](https://github.com/eat-pray-ai/yutu/releases/latest) [ | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (15)
.bazelignore
.bazelrc
.bazelversion
.goreleaser.yaml
[](https://cursor.com/install-mcp?name=yutu&config=JTdCJTIyY29tbWFuZCUyMiUzQSUyMnl1dHUlMjBtY3AlMjIlMkMlMjJlbnYlMjIlM0ElN0IlMjJZVV
[](https://cursor.com/install-mcp?name=yutu&config=JTdCJTIyY29tbWFuZCUyMiUzQSUyMnl1dHUlMjBtY3AlMjIlMkMlMjJlbnYlMjIlM0ElN0IlMjJZVVRVX0N
❯ curl -sSfL https://raw.githubusercontent.com/eat-pray-ai/yutu/main/scripts/install.sh | bash
❯ curl -sSfL https://raw.githubusercontent.com/eat-pray-ai/yutu/main/scripts/install.sh | bash
❯ curl -sSfL https://raw.githubusercontent.com/eat-pray-ai/yutu/main/scripts/install.sh | bash
❯ curl -sSfL https://raw.githubusercontent.com/eat-pray-ai/yutu/main/scripts/install.sh | bash
curl -sSfL https://raw.githubusercontent.com/eat-pray-ai/yutu/main/scripts/install.sh | bash
assets/mcp-demo.cast
assets/mcp-demo.gif
assets/yutu.drawio
Gates applied: no_behavioural_pass.
1bc9a1f7ea6bfull audit observations/trust-audit/mcp-server/eat-pray-ai__yutu.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 1bc9a1f7ea6b | SAFE | B | 89 | first audit |
Questions
What is the Yutu MCP server?
The AI-powered toolkit that grows your YouTube channel on autopilot.
Is Yutu safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Yutu need?
It reads YUTU_CACHE_TOKEN and YUTU_CREDENTIAL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Yutu run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @eat-pray-ai/yutu at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (1bc9a1f7ea6b), read on 2026-09-29. The repository is watched and re-audited when it changes.