Atlas / MCP servers / nmbrthirteen / Podcli

PodcliCAUTION

mcp/nmbrthirteen/podcli

Open-source AI podcast clipper. Generate vertical clips with face tracking and burned-in captions. CLI, MCP server, web app.

Verdict
CAUTION
Grade
C
Trust score
71 /100
Exposed tools
30 16r · 12w · 2d
Transport
stdio
License
AGPL-3.0
Stars
78
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Open-source AI podcast clipper. Turn a long episode into short clips with face tracking and burned-in captions. Drive it from the CLI, a web studio, or your coding agent.

podcli.com · Docs · Install · MCP

▶ Watch with sound on X

podcli process episode.mp4

That one command transcribes the episode, picks the moments worth clipping, crops to whoever is speaking, and burns the captions in. Transcription and rendering run on your machine. The only network calls are the optional Claude or Codex requests when you use AI clip scoring.

Install

No prerequisites. The installer fetches a self-contained binary, and the first run provisions Python, Node, FFmpeg, whisper.cpp, and the models it needs into a managed folder.

macOS and Linux

curl -fsSL https://podcli.com/install.sh | sh

Windows (PowerShell)

irm https://podcli.com/install.ps1 | iex

Runs on macOS (Apple Silicon), Linux (x64 and arm64), and Windows (x64). Intel Mac support is in progress.

Quick start

podcli                       
Read from source at commit 0c50880c4ea2OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add podcli-remotion-bundle --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env ASSEMBLYAI_API_KEY=${ASSEMBLYAI_API_KEY} --env HF_TOKEN=${HF_TOKEN} -- npx -y podcli-remotion-bundle
claude-desktop
{
  "mcpServers": {
    "podcli-remotion-bundle": {
      "command": "npx",
      "args": [
        "-y",
        "podcli-remotion-bundle"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "API_KEY": "${API_KEY}",
        "ASSEMBLYAI_API_KEY": "${ASSEMBLYAI_API_KEY}",
        "HF_TOKEN": "${HF_TOKEN}"
      }
    }
  }
}
03

Exposed tools (30)

16 read · 12 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ai_cli_statusreadShow whether Claude Code / Codex CLIs are available for AI-powered clip suggestion and content generation.\n\n
analyze_energyreadAnalyze audio energy levels for a video or specific segments. Useful for finding high-energy moments. Defaults to the current UI video and suggestions if not specified.
batch_create_clipswriteSTEP 3 — Export multiple clips at once as finished vertical shorts.\n\n
clip_historyreadView previously created clips to avoid duplicates. Check before creating new clips.
compare_transcription_enginesreadTranscribe the same sample window of a file with two engines and report where their output
create_clipwriteSTEP 3 — Export a single clip as a finished vertical short (1080x1920, 9:16).\n\n
export_to_davinci_resolvereadExport podcli shorts as a DaVinci Resolve FCPXML project.\n\n
get_ui_statereadRead the current podcli session state and get guidance on what to do next.
import_transcriptwriteImport an external transcript (e.g. from a transcription service) into the UI. Skips Whisper entirely. The transcript must include word-level timestamps.
job_statusreadPoll the status of any background job (transcription, clip render, batch export).
knowledge_basereadRead or manage the podcli knowledge base. These are .md files that provide context about the podcast (hosts, style, audience, etc). Always read the knowledge base before suggesting or creating clips.
list_outputsreadList all rendered clip files in the output directory with file sizes and dates.
manage_assetsreadRegister and manage reusable assets (logos, outros, intros, music, images). Reference them by name in create_clip/manage_reel instead of full paths. One logo/outro/intro/music can be the default, applied automatically when none is passed.
manage_configreadManage portable config profiles and legacy path migration.\n\n
manage_envwriteList, set, or unset global podcli settings stored in .env.\n\n
manage_integrationswriteList, enable, or disable podcli integrations (editor exporters, platform uploads, productivity tools, AI helpers).\n\n
manage_multicamwriteEdit a full multicam podcast episode: map every camera and mic file to a person, sync them by audio (with clock-drift correction),
manage_presetsdestructiveSave, load, list, or delete rendering presets. Presets store caption_style, crop_strategy, logo_path, and outro_path for quick reuse.
manage_reelwriteCreate and iterate on a highlights reel. Detection runs once with action
manage_thumbnail_configdestructiveShow, export, import, or reset the thumbnail template (colors, fonts, frame, box, layout) podcli uses to generate thumbnails.
mine_channelreadMine a YouTube channel
modify_clipwriteAdjust a suggested clip before exporting. Change timing, title, caption style, or opening hook.
parse_transcriptreadParse a raw speaker-labeled plain text transcript into word-level timestamps. Input format:
record_decisionsread
set_videowriteSet the working video file without transcribing. Use this when you
suggest_clipswriteSTEP 2 — Submit your clip suggestions after analyzing the transcript.\n\n
toggle_clipreadSelect or deselect a suggested clip by clip_number. Selected clips are exported with export_selected.
transcribe_podcastreadSTEP 1 — Transcribe a podcast video/audio file. This is typically the first tool you call.\n\n
transcribe_startwriteStart transcription as a background job and return a job_id immediately.
update_settingswriteUpdate rendering settings (caption style, crop strategy, logo, outro) in the Web UI.
04

Trust audit

CAUTIONgrade C · trust 71/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (11 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
backend/models/face_detection_yunet_2023mar.onnx
face_detection_yunet_2023mar.onnx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
remotion/render-full-episode.mjs:138
const logoSrc = logo ? `http://127.0.0.1:${server.address().port}/logo.png` : undefined;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
remotion/render.mjs:149
const videoSrc = `http://127.0.0.1:${assetPort}/clip.mp4`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
remotion/render.mjs:150
const logoSrc = opts.logo ? `http://127.0.0.1:${assetPort}/logo.png` : undefined;
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
scripts/release-hygiene.test.mjs:70
expect(matchSecretPatterns("key = AKIAABCDEFGHIJKLMNOP")).toContain("AWS access key");
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
scripts/release-hygiene.test.mjs:74
expect(matchSecretPatterns("-----BEGIN RSA PRIVATE KEY-----\nabc\n-----END RSA PRIVATE KEY-----")).toContain(
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
manage_presets, manage_thumbnail_config
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
backend/services/multicam.py:406
id=hashlib.sha1(f"{os.path.basename(path)}:{os.path.getsize(path)}".encode()).hexdigest()[:10],
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
backend/services/multicam.py:432
return hashlib.sha1(f"{s.file_size}:{s.file_mtime_ns}".encode()).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
backend/services/multicam.py:690
id=hashlib.sha1(f"{whole.id}:{crop}".encode()).hexdigest()[:10], path=whole.path, kind="video",
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
backend/services/multicam.py:742
id=hashlib.sha1(f"split:{seated}".encode()).hexdigest()[:10], path="", kind="video",
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
backend/services/multicam.py:908
src.id = hashlib.sha1(f"{src.id}:{n}".encode()).hexdigest()[:10]
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/internal/backend/sync.sh:6
src="$here/../../../backend"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/internal/podstack/sync.sh:7
src="$here/../../../.claude/commands"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/internal/provision/security_test.go:40
{"escape via dotdot", "/tmp/dest/link", "../../etc/passwd", false},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/internal/provision/security_test.go:42
{"deep escape", "/tmp/dest/a/b/link", "../../../outside", false},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/internal/provision/security_test.go:66
if err := tw.WriteHeader(&tar.Header{Name: "evil", Typeflag: tar.TypeSymlink, Linkname: "../../../../etc", Mode: 0o777}); err != nil {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/ui/web-server-outputs.test.ts:36
const res = await fetch(`http://127.0.0.1:${PORT}/api/ui-state`);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/ui/web-server-outputs.test.ts:73
const res = await fetch(`http://127.0.0.1:${PORT}/api/outputs`);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
backend/requirements.txt
openai-whisper, opencv-python-headless, numpy, onnxruntime, sherpa-onnx, Pillow, questionary, python-dotenv
Why it matters. 11 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@fontsource/dm-sans, @modelcontextprotocol/sdk, @remotion/bundler, @remotion/cli, @remotion/renderer, dotenv, express, lucide-react
Why it matters. 27 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.claude/commands/process-transcript.md:15
> You are a senior content analyst. Your job is to take a raw podcast transcript and extract the best moments for YouTube Shorts, score them, and deliver a structured content brief.
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:42
curl -fsSL https://podcli.com/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
RELEASE.md:9
curl -fsSL https://podcli.com/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
RELEASE.md:44
curl -fsSL .../install.sh | sh      # Windows: irm .../install.ps1 | iex

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 0c50880c4ea2full audit observations/trust-audit/mcp-server/nmbrthirteen__podcli.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-080c50880c4ea2CAUTIONC71first audit
06

Questions

What is the Podcli MCP server?

Open-source AI podcast clipper. Generate vertical clips with face tracking and burned-in captions. CLI, MCP server, web app.

What tools does Podcli expose?

30 in total: 16 read-only, 12 that write, and 2 that can delete or overwrite (manage_presets, manage_thumbnail_config). Every one is listed on this page with its risk.

Is Podcli safe to connect to an agent?

With care. The audit graded it C (71/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Podcli need?

It reads ANTHROPIC_API_KEY, API_KEY, ASSEMBLYAI_API_KEY, HF_TOKEN, PODCLI_OMNILINGUAL_TOKENS, PODCLI_TOKEN and PODCLI_TRANSITION_AUTOFIX_PASSES from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Podcli run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as podcli-remotion-bundle.

How current is this page?

The grade is for one exact copy of the source (0c50880c4ea2), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement