YouTube TranscriptBLOCK
Zero-setup YouTube transcript extraction for Claude. Works on mobile, desktop, and web - no local installation required.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The first remote Model Context Protocol (MCP) server that enables Claude AI to extract transcripts from YouTube videos. This server offers zero-setup access for users on any platform including mobile devices.
[](https://deploy.workers.cloudflare.com/?url=https://github.com/ergut/youtube-transcript-mcp)
🌟 Features
- Zero Local Setup: No installation required - works directly from the cloud
- Universal Access: Works on desktop, mobile, and web versions of Claude
- Smart Caching: Efficient caching system using Cloudflare KV for fast responses
- Multi-language Support: Extract transcripts in different languages
- Error Handling: Robust error handling with user-friendly messages
- Analytics: Built-in request tracking and usage analytics
- URL Flexibility: Handles all YouTube URL formats (youtube.com, youtu.be, m.youtube.com, etc.)
🚀 Quick Start
Option 1: Use Our Hosted Server (Recommended)
The easiest way to get started - just add our public server to your Claude Desktop:
For Claude Desktop Users
- Open Claude Desktop Settings
- Click on "Claude" in the menu bar → "Settings"
- Navigate to "Developer" tab
- Click "Edit Config"
- Add the MCP Server Configuration
Add this to your claude_desktop_config.json:
{
"mcpServers": {
"youtube-transcript": {
"command": "npx",
"args": [
"mcp-remote",
"https://youtube-transcript-mcp.ergut.workers.dev/sse"
]
}
}
}- Restart Claude Desktop
After saving the config file, restart Claude Desktop to load the server.
- Verify Installation
Look for the tools icon (🔧) in the chat interface. You should see the `get_tr
85eec69e2a7bOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add remote-mcp-github-oauth -- npx -y [email protected]
{
"mcpServers": {
"remote-mcp-github-oauth": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_transcript | read | Extract transcript from YouTube video URL |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
exec(query: string): Promise<D1ExecResult>;
.dev.vars.example
const oauthReqInfo = JSON.parse(atob(c.req.query("state") as string)) as AuthRequest;const jsonString = atob(encoded);
const payload = atob(base64Payload); // Assuming payload is base64 encoded JSON string
atob(data: string): string;
declare function atob(data: string): string;
@cloudflare/workers-oauth-provider, @modelcontextprotocol/sdk, agents, hono, just-pick, octokit, url-parse, workers-mcp
assets/logo.png
Gates applied: no_behavioural_pass.
85eec69e2a7bfull audit observations/trust-audit/mcp-server/ergut__youtube-transcript-8.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 85eec69e2a7b | BLOCK | D | 69 | first audit |
Questions
What is the YouTube Transcript MCP server?
Zero-setup YouTube transcript extraction for Claude. Works on mobile, desktop, and web - no local installation required.
What tools does YouTube Transcript expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is YouTube Transcript safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does YouTube Transcript need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (85eec69e2a7b), read on 2026-10-09. The repository is watched and re-audited when it changes.