Atlas / MCP servers / instantstudioai / instantclips-mcp

instantclips-mcpSAFE

mcp/instantstudioai/instantclips-mcp

Turn an e-commerce product into short-form vertical video with Claude, Codex, Cursor, or any MCP client.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English · Español · 简体中文

[](https://m8ven.ai/mcp/instantclips-mcp-1k56q7)

InstantClips turns an e-commerce product into short-form vertical video for TikTok, Instagram Reels and Stories. It runs a hosted MCP server, so Claude Code, Codex, Cursor, VS Code, the Claude app, ChatGPT or any other MCP client can do what the web app does: import a product, draft the plan, and generate the video.

This is not a text-to-video generator. InstantClips reads the product page — photos, price, details — and builds the ad from what is actually there. The plan is written first and shown to you; the video follows the plan. That is why it is cheap enough to run across a catalogue, and why the result is the product you sell rather than a guess at it.

Free to start: the welcome credits cover the first video, and there is no card to enter. After that, one-time credit packs, or an Agency membership for anyone running several brands. See pricing.

  • Where it fits. Beside a scheduler (Postiz, Buffer) that posts what comes back. Beside an

attribution tool that tells you which hook worked. Instead of an editor when you have a product page and no footage.

  • Not for. Cinematic hero films. A presenter reading your script. Horizontal 4K. Products with

no page and no photos.

  • Built for. Shopify sellers, dropshippers, brands and agencies running social for several

stores at once.

The product server stays hosted. This repository contains its connection guide, registry metadata, example HTTP client and a small open-source stdio adapter for clients that cannot connect to a remote server directly. The adapter answers initialization, ping and tool discovery from a generated snapshot, then sends authenticated tool calls to the hosted endpoint. The hosted server r

Read from source at commit 08dff1cf26bcOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add instantclips-mcp --env INSTANTCLIPS_TOKEN=${INSTANTCLIPS_TOKEN} -- npx -y [email protected]
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
generate_videoreadRender an approved video direction.
list_brandsreadList the account
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/shim.test.js:103
url: `http://127.0.0.1:${address.port}/mcp`,
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:127
gives full access to your account, so keep it out of anything you commit.

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 08dff1cf26bcfull audit observations/trust-audit/mcp-server/instantstudioai__instantclips-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0908dff1cf26bcSAFEB89first audit
06

Questions

What is the instantclips-mcp MCP server?

Turn an e-commerce product into short-form vertical video with Claude, Codex, Cursor, or any MCP client.

What tools does instantclips-mcp expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is instantclips-mcp safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does instantclips-mcp need?

It reads INSTANTCLIPS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does instantclips-mcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as instantclips-mcp at 1.7.2.

How current is this page?

The grade is for one exact copy of the source (08dff1cf26bc), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement