TwitterBLOCK
MCP server for X (Twitter) that enables AI assistants to post tweets, upload images, and search Twitter using natural language via the Twitter API.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/genaiwithms-twitter-mcp)
<img src="https://capsule-render.vercel.app/api?type=waving&color=0:0F1419,50:1D9BF0,100:7856FF&height=230§ion=header&text=Twitter%20MCP%20Server&fontSize=52&fontColor=ffffff&fontAlignY=38&animation=fadeIn&desc=Connect%20AI%20assistants%20to%20X%20(Twitter)%20using%20the%20Model%20Context%20Protocol&descSize=17&descAlignY=60" alt="Twitter MCP Server — Connect AI assistants to X (Twitter) using the Model Context Protocol" width="100%" />
<img src="https://readme-typing-svg.demolab.com?font=Fira+Code&weight=600&size=20&duration=2500&pause=700&color=1D9BF0¢er=true&vCenter=true&width=520&lines=Post+tweets;Upload+images;Search+tweets;Reply+to+conversations;Look+up+user+profiles;Fetch+conversation+threads;Monitor+mentions;Publish+smart+threads;Quote+tweets;Extract+media;Like%2C+retweet+%26+bookmark" alt="Post tweets • Upload images • Search tweets • Reply to conversations • Look up user profiles • Fetch conversation threads • Monitor mentions • Publish smart threads • Quote tweets • Extract media • Like, retweet & bookmark" />
Post tweets · Upload images · Search tweets · Reply to conversations · Look up user profiles · Fetch conversation threads Monitor mentions · Publish smart threads · Quote tweets · Extract media · Like, retweet & bookmark
2ef63ce3e162OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add twitter-mcp --env ACCESS_TOKEN=${ACCESS_TOKEN} --env ACCESS_TOKEN_SECRET=${ACCESS_TOKEN_SECRET} --env API_KEY=${API_KEY} --env API_SECRET_KEY=${API_SECRET_KEY} -- npx -y @muhammadsiddiq/[email protected]{
"mcpServers": {
"twitter-mcp": {
"command": "npx",
"args": [
"-y",
"@muhammadsiddiq/[email protected]"
],
"env": {
"ACCESS_TOKEN": "${ACCESS_TOKEN}",
"ACCESS_TOKEN_SECRET": "${ACCESS_TOKEN_SECRET}",
"API_KEY": "${API_KEY}",
"API_SECRET_KEY": "${API_SECRET_KEY}"
}
}
}
}Exposed tools (10)
7 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
draft_quote_tweet | read | |
engage_with_tweet | read | |
fetch_thread_history | read | |
get_user_profile_context | read | |
media_extraction_helper | read | |
post_tweet | write | |
post_tweet_with_image | write | |
publish_smart_thread | write | |
search_recent_mentions | read | |
search_tweets | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
yamlData = yaml.load(fileContent) as any;
@modelcontextprotocol/sdk, dotenv, fs-extra, inquirer, js-yaml, mcp-evals, smol-toml, twitter-api-v2
<img src="https://readme-typing-svg.demolab.com?font=Fira+Code&weight=600&size=20&duration=2500&pause=700&color=1D9BF0¢er=true&vCenter=true&width=520&lines=Post+tweets;Upload+images;Search+tweets;
2. Open [Account > API Keys](https://dashboard.xquik.com/en/account?tab=api-keys).
Gates applied: no_behavioural_pass.
2ef63ce3e162full audit observations/trust-audit/mcp-server/genaiwithms__twitter-8.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 2ef63ce3e162 | BLOCK | D | 69 | first audit |
Questions
What is the Twitter MCP server?
MCP server for X (Twitter) that enables AI assistants to post tweets, upload images, and search Twitter using natural language via the Twitter API.
What tools does Twitter expose?
10 in total: 7 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Twitter safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Twitter need?
It reads ACCESS_TOKEN, ACCESS_TOKEN_SECRET, API_KEY, API_SECRET_KEY, GETXAPI_API_KEY, HERMES_TWEET_API_KEY and XQUIK_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Twitter run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @muhammadsiddiq/twitter-mcp at 0.3.11.
How current is this page?
The grade is for one exact copy of the source (2ef63ce3e162), read on 2026-10-09. The repository is watched and re-audited when it changes.