Atlas / MCP servers / hagaihen / Facebook

FacebookSAFE

mcp/hagaihen/facebook

Facebook MCP server for automating posts, comment moderation, insights, and sentiment filtering.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
40 10r · 26w · 4d
Transport
—
License
MIT
Stars
228
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This project is a MCP server for automating and managing interactions on a Facebook Page using the Facebook Graph API. It exposes tools to create posts, moderate comments, fetch post insights, and filter negative feedback — ready to plug into Claude, or other LLM-based agents.

[](https://archestra.ai/mcp-catalog/hagaihen__facebook-mcp-server)

🤖 What Is This?

This MCP provides a suite of AI-callable tools that connect directly to a Facebook Page, abstracting common API operations as LLM-friendly functions.

✅ Benefits

  • Empowers social media managers to automate moderation and analytics.
  • Seamlessly integrates with Claude Desktop or any Agent client.
  • Enables fine-grained control over Facebook content from natural language.

📦 Features

Read from source at commit f0681ac31a16OBSERVED · 2026-10-06
02

Exposed tools (40)

10 read · 26 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
bulk_delete_commentsdestructiveDelete multiple comments by ID.
bulk_hide_commentsreadHide multiple comments by ID.
bulk_unhide_commentsreadUnhide multiple comments by ID.
delete_commentdestructiveDelete a specific comment from the Page.
delete_comment_from_postdestructiveAlias to delete a comment on a post.
delete_postdestructiveDelete a specific post from the Facebook Page.
filter_negative_commentsreadFilter comments for basic negative sentiment.
get_comment_repliesreadGet all replies to a specific comment.
get_number_of_commentswriteCount the number of comments on a given post.
get_number_of_likeswriteReturn the number of likes on a post.
get_page_fan_countreadGet the Page
get_page_inforeadGet extended information about the Facebook Page.
get_page_postsreadFetch the most recent posts on the Page.
get_post_clickswriteFetch number of post clicks.
get_post_commentswriteRetrieve all comments for a given post.
get_post_engaged_userswriteFetch number of engaged users.
get_post_impressionswriteFetch total impressions of a post.
get_post_impressions_organicwriteFetch organic impressions of a post.
get_post_impressions_paidwriteFetch paid impressions of a post.
get_post_impressions_uniquewriteFetch unique impressions of a post.
get_post_insightswriteFetch all insights metrics (impressions, reactions, clicks, etc).
get_post_permalinkwriteGet the permalink URL of a post.
get_post_reactions_anger_totalwriteFetch number of
get_post_reactions_breakdownwriteGet counts for all reaction types on a post.
get_post_reactions_haha_totalwriteFetch number of
get_post_reactions_like_totalwriteFetch number of
get_post_reactions_love_totalwriteFetch number of
get_post_reactions_sorry_totalwriteFetch number of
get_post_reactions_wow_totalwriteFetch number of
get_post_share_countwriteGet the number of shares for a post.
get_post_top_commenterswriteGet the top commenters on a post.
get_scheduled_postsreadList all scheduled (unpublished) posts on the Page.
hide_commentreadHide a comment from public view.
post_image_to_facebookwritePost an image with a caption to the Facebook page.
post_to_facebookwriteCreate a new Facebook Page post with a text message.
reply_to_commentwriteReply to a specific comment on a Facebook post.
schedule_postwriteSchedule a new post for future publishing.
send_dm_to_userwriteSend a direct message to a user.
unhide_commentreadUnhide a previously hidden comment.
update_postwriteUpdates an existing post
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bulk_delete_comments, delete_comment, delete_comment_from_post, delete_post
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, python-dotenv, requests
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:79
curl -Ls https://astral.sh/uv/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha f0681ac31a16full audit observations/trust-audit/mcp-server/hagaihen__facebook.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06f0681ac31a16SAFEB89first audit
05

Questions

What is the Facebook MCP server?

Facebook MCP server for automating posts, comment moderation, insights, and sentiment filtering.

What tools does Facebook expose?

40 in total: 10 read-only, 26 that write, and 4 that can delete or overwrite (bulk_delete_comments, delete_comment, delete_comment_from_post, delete_post). Every one is listed on this page with its risk.

Is Facebook safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Facebook need?

It reads FACEBOOK_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (f0681ac31a16), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement