Atlas / MCP servers / guimatheus92 / Video Analyzer

Video AnalyzerCAUTION

mcp/guimatheus92/video-analyzer

MCP server that turns any video — YouTube, Instagram, TikTok, Loom, X, Vimeo, direct URLs, local files — into transcripts, key frames, OCR text, and metadata for AI agents.

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
3 3r · 0w · 0d
Transport
—
License
MIT
Stars
90
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

mcp-video-analyzer

Turn any video — YouTube, Instagram, TikTok, Loom, X, Vimeo, direct links, local files — into transcripts, key frames, OCR text, and metadata for AI agents.

No existing video MCP combines transcripts + visual frames + metadata in one tool. This one does — across Loom, the major yt-dlp platforms (YouTube/Vimeo/TikTok/Instagram/X/Twitch/Dailymotion/Facebook), direct video URLs, and local files.

Want a full pipeline, not just a tool? social-knowledge-base is built on top of this server — it downloads whole Instagram creator accounts (reels, stories, highlights), transcribes them, and turns the result into a searchable, RAG-queryable knowledge base with AI-generated notes. Use this MCP when you
Read from source at commit 650aab286bf9OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-video-analyzer --env OPENAI_API_KEY=${OPENAI_API_KEY} --env TWELVELABS_API_KEY=${TWELVELABS_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-video-analyzer": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "TWELVELABS_API_KEY": "${TWELVELABS_API_KEY}"
      }
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_momentreadDeep-dive analysis of a specific time range in a video. Combines burst frame extraction + transcript filtering + OCR + annotated timeline for a focused segment of the video. Use this when you need to understand exactly what happens between two timestamps: - What
get_frame_atreadExtract a single video frame at a specific timestamp. Useful for inspecting what
get_frame_burstreadExtract multiple frames evenly distributed across a time range. Designed for motion and vibration analysis where scene-change detection fails because the
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
.claude/skills/video-analyzer-dev/SKILL.md:78
- **The blocked-range table only grows.** RFC1918 + loopback + link-local is *not* enough, and shortening it to that is itself the vulnerability: Gitea's GHSA-2r5c-gw76-rh3w is CVSS 9.6 for exactly th
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWInventory / provenance · inv.binary · CWE-1104
test/fixtures/speech.wav
speech.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
test/fixtures/tiny.webm
tiny.webm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/adapters/loom.adapter.test.ts:4
import { FIXTURES_DIR } from '../../test/helpers/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/adapters/ytdlp.adapter.test.ts:4
import { FIXTURES_DIR } from '../../test/helpers/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/processors/audio-transcriber.test.ts:6
import { FIXTURES_DIR } from '../../test/helpers/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/processors/embedded-subtitles.test.ts:7
import { FIXTURES_DIR } from '../../test/helpers/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/processors/frame-dedup.test.ts:6
import { createTestImage } from '../../test/helpers/index.js';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
README.md:335
Cloud instance metadata endpoints (`169.254.169.254`, Azure's `168.63.129.16`, and friends) stay blocked **even with that set** — there is no legitimate video there, and they are what an SSRF is usual
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/processors/browser-frame-extractor.test.ts:92
'http://169.254.169.254/latest/meta-data/',
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/processors/browser-frame-extractor.test.ts:104
extractBrowserFrames('http://169.254.169.254/latest.mp4', '/tmp/out', { timestamps: [1] }),
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/processors/browser-frame-extractor.test.ts:158
['http://169.254.169.254/latest/meta-data/', 'metadata'],
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:328
The check runs on the resolved address, not just the text, so a public hostname that resolves to `10.0.0.5` is refused too — and **every hop of a redirect chain is re-checked**, since a public URL ans
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/processors/browser-frame-extractor.test.ts:89
'http://127.0.0.1:8931/x.mp4',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/processors/browser-frame-extractor.test.ts:91
'http://192.168.1.5/video',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/processors/browser-frame-extractor.test.ts:92
'http://169.254.169.254/latest/meta-data/',
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/processors/browser-frame-extractor.test.ts:104
extractBrowserFrames('http://169.254.169.254/latest.mp4', '/tmp/out', { timestamps: [1] }),
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
cheerio, fastmcp, ffmpeg-static, puppeteer-core, sharp, tesseract.js, zod, @eslint/js
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 650aab286bf9full audit observations/trust-audit/mcp-server/guimatheus92__video-analyzer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08650aab286bf9CAUTIONB87first audit
06

Questions

What is the Video Analyzer MCP server?

MCP server that turns any video — YouTube, Instagram, TikTok, Loom, X, Vimeo, direct URLs, local files — into transcripts, key frames, OCR text, and metadata for AI agents.

What tools does Video Analyzer expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Video Analyzer safe to connect to an agent?

With care. The audit graded it B (87/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Video Analyzer need?

It reads OPENAI_API_KEY and TWELVELABS_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (650aab286bf9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement