Atlas / MCP servers / genaiwithms / Twitter

TwitterBLOCK

mcp/genaiwithms/twitter-8

MCP server for X (Twitter) that enables AI assistants to post tweets, upload images, and search Twitter using natural language via the Twitter API.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
10 7r · 3w · 0d
Transport
stdio
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/genaiwithms-twitter-mcp)

<img src="https://capsule-render.vercel.app/api?type=waving&color=0:0F1419,50:1D9BF0,100:7856FF&height=230&section=header&text=Twitter%20MCP%20Server&fontSize=52&fontColor=ffffff&fontAlignY=38&animation=fadeIn&desc=Connect%20AI%20assistants%20to%20X%20(Twitter)%20using%20the%20Model%20Context%20Protocol&descSize=17&descAlignY=60" alt="Twitter MCP Server — Connect AI assistants to X (Twitter) using the Model Context Protocol" width="100%" />

<img src="https://readme-typing-svg.demolab.com?font=Fira+Code&weight=600&size=20&duration=2500&pause=700&color=1D9BF0&center=true&vCenter=true&width=520&lines=Post+tweets;Upload+images;Search+tweets;Reply+to+conversations;Look+up+user+profiles;Fetch+conversation+threads;Monitor+mentions;Publish+smart+threads;Quote+tweets;Extract+media;Like%2C+retweet+%26+bookmark" alt="Post tweets • Upload images • Search tweets • Reply to conversations • Look up user profiles • Fetch conversation threads • Monitor mentions • Publish smart threads • Quote tweets • Extract media • Like, retweet & bookmark" />

Post tweets · Upload images · Search tweets · Reply to conversations · Look up user profiles · Fetch conversation threads Monitor mentions · Publish smart threads · Quote tweets · Extract media · Like, retweet & bookmark

Read from source at commit 2ef63ce3e162OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add twitter-mcp --env ACCESS_TOKEN=${ACCESS_TOKEN} --env ACCESS_TOKEN_SECRET=${ACCESS_TOKEN_SECRET} --env API_KEY=${API_KEY} --env API_SECRET_KEY=${API_SECRET_KEY} -- npx -y @muhammadsiddiq/[email protected]
claude-desktop
{
  "mcpServers": {
    "twitter-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@muhammadsiddiq/[email protected]"
      ],
      "env": {
        "ACCESS_TOKEN": "${ACCESS_TOKEN}",
        "ACCESS_TOKEN_SECRET": "${ACCESS_TOKEN_SECRET}",
        "API_KEY": "${API_KEY}",
        "API_SECRET_KEY": "${API_SECRET_KEY}"
      }
    }
  }
}
03

Exposed tools (10)

7 read · 3 write · 0 destructive.

ToolRiskDescription
draft_quote_tweetread
engage_with_tweetread
fetch_thread_historyread
get_user_profile_contextread
media_extraction_helperread
post_tweetwrite
post_tweet_with_imagewrite
publish_smart_threadwrite
search_recent_mentionsread
search_tweetsread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/universal-installer.ts:165
yamlData = yaml.load(fileContent) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, fs-extra, inquirer, js-yaml, mcp-evals, smol-toml, twitter-api-v2
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:12
<img src="https://readme-typing-svg.demolab.com?font=Fira+Code&weight=600&size=20&duration=2500&pause=700&color=1D9BF0&center=true&vCenter=true&width=520&lines=Post+tweets;Upload+images;Search+tweets;
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:264
2. Open [Account > API Keys](https://dashboard.xquik.com/en/account?tab=api-keys).
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 2ef63ce3e162full audit observations/trust-audit/mcp-server/genaiwithms__twitter-8.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-092ef63ce3e162BLOCKD69first audit
06

Questions

What is the Twitter MCP server?

MCP server for X (Twitter) that enables AI assistants to post tweets, upload images, and search Twitter using natural language via the Twitter API.

What tools does Twitter expose?

10 in total: 7 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Twitter safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Twitter need?

It reads ACCESS_TOKEN, ACCESS_TOKEN_SECRET, API_KEY, API_SECRET_KEY, GETXAPI_API_KEY, HERMES_TWEET_API_KEY and XQUIK_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Twitter run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @muhammadsiddiq/twitter-mcp at 0.3.11.

How current is this page?

The grade is for one exact copy of the source (2ef63ce3e162), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement