TwitterSAFE
Manage your twitter account using mcp
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Welcome to the Twitter MCP (Multi-Channel Platform) Server! This application helps you manage your Twitter account programmatically with a variety of powerful features.
Features
- Get Timeline: Retrieve your Twitter home timeline.
- Get Any User's Tweets: Fetch tweets from any public Twitter user.
- Hashtag Search: Search for tweets containing any hashtag (e.g.,
#AI). - Get Replies & Summaries: Retrieve replies to tweets and get summarized insights.
- User Direct Messages: Send and receive Twitter DMs.
- Create Post: Programmatically create new tweets.
- Delete Post: Delete your tweets through the API.
- And much more...
[](https://smithery.ai/server/@LuniaKunal/mcp-twitter)
Getting Started
Prerequisites
- Python 3.11+
- uvicorn (for running the server)
- Twitter API credentials (set in
.envfile)
Installation
- Clone this repository.
- Install dependencies:
pip install -r requirements.txt
- Set up your
.envfile with your Twitter API credentials (see.env.example).
Running the Application
To start the server, run:
uv run --with twikit --with mcp Path\\src\\tweet_service.py
{
"mcpServers": {
"twitter-mcp": {
"command": "uv",
"args": [
"--directory",
"Path\\src\\",
"run",
"--with",
"twikit",
"--with",
"mcp",
"tweet_service.py"
],
"env": {
"COOKIES_PATH": "Path\\cookies.json",
"ENV_FILE": ".env"
}
}
}
}Feel free to contribute or suggest new features!
6faf8671f4bcOBSERVED · 2026-10-07Exposed tools (7)
5 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
delete_tweet | destructive | Delete a tweet by its ID. |
get_latest_timeline | read | Get tweets from your home timeline (Following). |
get_replies_for_tweet | read | |
get_timeline | read | Get tweets from your home timeline (For You). |
get_tweets | read | Search twitter with a query. Sort by |
get_user_tweets | read | Get tweets from a specific user |
post_tweet | write | Post a tweet with optional media, reply, and tags. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
delete_tweet
mcp, twikit, mcp, python-dotenv
Gates applied: no_behavioural_pass, no_license.
6faf8671f4bcfull audit observations/trust-audit/mcp-server/luniakunal__twitter-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6faf8671f4bc | SAFE | B | 89 | first audit |
Questions
What is the Twitter MCP server?
Manage your twitter account using mcp
What tools does Twitter expose?
7 in total: 5 read-only, 1 that write, and 1 that can delete or overwrite (delete_tweet). Every one is listed on this page with its risk.
Is Twitter safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Twitter need?
It reads TWITTER_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (6faf8671f4bc), read on 2026-10-07. The repository is watched and re-audited when it changes.