PodcliCAUTION
Open-source AI podcast clipper. Generate vertical clips with face tracking and burned-in captions. CLI, MCP server, web app.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Open-source AI podcast clipper. Turn a long episode into short clips with face tracking and burned-in captions. Drive it from the CLI, a web studio, or your coding agent.
podcli.com · Docs · Install · MCP
▶ Watch with sound on X
podcli process episode.mp4
That one command transcribes the episode, picks the moments worth clipping, crops to whoever is speaking, and burns the captions in. Transcription and rendering run on your machine. The only network calls are the optional Claude or Codex requests when you use AI clip scoring.
Install
No prerequisites. The installer fetches a self-contained binary, and the first run provisions Python, Node, FFmpeg, whisper.cpp, and the models it needs into a managed folder.
macOS and Linux
curl -fsSL https://podcli.com/install.sh | sh
Windows (PowerShell)
irm https://podcli.com/install.ps1 | iex
Runs on macOS (Apple Silicon), Linux (x64 and arm64), and Windows (x64). Intel Mac support is in progress.
Quick start
podcli
0c50880c4ea2OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add podcli-remotion-bundle --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env ASSEMBLYAI_API_KEY=${ASSEMBLYAI_API_KEY} --env HF_TOKEN=${HF_TOKEN} -- npx -y podcli-remotion-bundle{
"mcpServers": {
"podcli-remotion-bundle": {
"command": "npx",
"args": [
"-y",
"podcli-remotion-bundle"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"API_KEY": "${API_KEY}",
"ASSEMBLYAI_API_KEY": "${ASSEMBLYAI_API_KEY}",
"HF_TOKEN": "${HF_TOKEN}"
}
}
}
}Exposed tools (30)
16 read · 12 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
ai_cli_status | read | Show whether Claude Code / Codex CLIs are available for AI-powered clip suggestion and content generation.\n\n |
analyze_energy | read | Analyze audio energy levels for a video or specific segments. Useful for finding high-energy moments. Defaults to the current UI video and suggestions if not specified. |
batch_create_clips | write | STEP 3 — Export multiple clips at once as finished vertical shorts.\n\n |
clip_history | read | View previously created clips to avoid duplicates. Check before creating new clips. |
compare_transcription_engines | read | Transcribe the same sample window of a file with two engines and report where their output |
create_clip | write | STEP 3 — Export a single clip as a finished vertical short (1080x1920, 9:16).\n\n |
export_to_davinci_resolve | read | Export podcli shorts as a DaVinci Resolve FCPXML project.\n\n |
get_ui_state | read | Read the current podcli session state and get guidance on what to do next. |
import_transcript | write | Import an external transcript (e.g. from a transcription service) into the UI. Skips Whisper entirely. The transcript must include word-level timestamps. |
job_status | read | Poll the status of any background job (transcription, clip render, batch export). |
knowledge_base | read | Read or manage the podcli knowledge base. These are .md files that provide context about the podcast (hosts, style, audience, etc). Always read the knowledge base before suggesting or creating clips. |
list_outputs | read | List all rendered clip files in the output directory with file sizes and dates. |
manage_assets | read | Register and manage reusable assets (logos, outros, intros, music, images). Reference them by name in create_clip/manage_reel instead of full paths. One logo/outro/intro/music can be the default, applied automatically when none is passed. |
manage_config | read | Manage portable config profiles and legacy path migration.\n\n |
manage_env | write | List, set, or unset global podcli settings stored in .env.\n\n |
manage_integrations | write | List, enable, or disable podcli integrations (editor exporters, platform uploads, productivity tools, AI helpers).\n\n |
manage_multicam | write | Edit a full multicam podcast episode: map every camera and mic file to a person, sync them by audio (with clock-drift correction), |
manage_presets | destructive | Save, load, list, or delete rendering presets. Presets store caption_style, crop_strategy, logo_path, and outro_path for quick reuse. |
manage_reel | write | Create and iterate on a highlights reel. Detection runs once with action |
manage_thumbnail_config | destructive | Show, export, import, or reset the thumbnail template (colors, fonts, frame, box, layout) podcli uses to generate thumbnails. |
mine_channel | read | Mine a YouTube channel |
modify_clip | write | Adjust a suggested clip before exporting. Change timing, title, caption style, or opening hook. |
parse_transcript | read | Parse a raw speaker-labeled plain text transcript into word-level timestamps. Input format: |
record_decisions | read | |
set_video | write | Set the working video file without transcribing. Use this when you |
suggest_clips | write | STEP 2 — Submit your clip suggestions after analyzing the transcript.\n\n |
toggle_clip | read | Select or deselect a suggested clip by clip_number. Selected clips are exported with export_selected. |
transcribe_podcast | read | STEP 1 — Transcribe a podcast video/audio file. This is typically the first tool you call.\n\n |
transcribe_start | write | Start transcription as a background job and return a job_id immediately. |
update_settings | write | Update rendering settings (caption style, crop strategy, logo, outro) in the Web UI. |
Trust audit
CAUTIONgrade C · trust 71/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
face_detection_yunet_2023mar.onnx
const logoSrc = logo ? `http://127.0.0.1:${server.address().port}/logo.png` : undefined;const videoSrc = `http://127.0.0.1:${assetPort}/clip.mp4`;const logoSrc = opts.logo ? `http://127.0.0.1:${assetPort}/logo.png` : undefined;expect(matchSecretPatterns("key = AKIAABCDEFGHIJKLMNOP")).toContain("AWS access key");expect(matchSecretPatterns("-----BEGIN RSA PRIVATE KEY-----\nabc\n-----END RSA PRIVATE KEY-----")).toContain(manage_presets, manage_thumbnail_config
id=hashlib.sha1(f"{os.path.basename(path)}:{os.path.getsize(path)}".encode()).hexdigest()[:10],return hashlib.sha1(f"{s.file_size}:{s.file_mtime_ns}".encode()).hexdigest()[:8]id=hashlib.sha1(f"{whole.id}:{crop}".encode()).hexdigest()[:10], path=whole.path, kind="video",id=hashlib.sha1(f"split:{seated}".encode()).hexdigest()[:10], path="", kind="video",src.id = hashlib.sha1(f"{src.id}:{n}".encode()).hexdigest()[:10]src="$here/../../../backend"
src="$here/../../../.claude/commands"
{"escape via dotdot", "/tmp/dest/link", "../../etc/passwd", false},{"deep escape", "/tmp/dest/a/b/link", "../../../outside", false},if err := tw.WriteHeader(&tar.Header{Name: "evil", Typeflag: tar.TypeSymlink, Linkname: "../../../../etc", Mode: 0o777}); err != nil {const res = await fetch(`http://127.0.0.1:${PORT}/api/ui-state`);const res = await fetch(`http://127.0.0.1:${PORT}/api/outputs`);openai-whisper, opencv-python-headless, numpy, onnxruntime, sherpa-onnx, Pillow, questionary, python-dotenv
@fontsource/dm-sans, @modelcontextprotocol/sdk, @remotion/bundler, @remotion/cli, @remotion/renderer, dotenv, express, lucide-react
> You are a senior content analyst. Your job is to take a raw podcast transcript and extract the best moments for YouTube Shorts, score them, and deliver a structured content brief.
curl -fsSL https://podcli.com/install.sh | sh
curl -fsSL https://podcli.com/install.sh | sh
curl -fsSL .../install.sh | sh # Windows: irm .../install.ps1 | iex
Gates applied: no_behavioural_pass.
0c50880c4ea2full audit observations/trust-audit/mcp-server/nmbrthirteen__podcli.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 0c50880c4ea2 | CAUTION | C | 71 | first audit |
Questions
What is the Podcli MCP server?
Open-source AI podcast clipper. Generate vertical clips with face tracking and burned-in captions. CLI, MCP server, web app.
What tools does Podcli expose?
30 in total: 16 read-only, 12 that write, and 2 that can delete or overwrite (manage_presets, manage_thumbnail_config). Every one is listed on this page with its risk.
Is Podcli safe to connect to an agent?
With care. The audit graded it C (71/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Podcli need?
It reads ANTHROPIC_API_KEY, API_KEY, ASSEMBLYAI_API_KEY, HF_TOKEN, PODCLI_OMNILINGUAL_TOKENS, PODCLI_TOKEN and PODCLI_TRANSITION_AUTOFIX_PASSES from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Podcli run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as podcli-remotion-bundle.
How current is this page?
The grade is for one exact copy of the source (0c50880c4ea2), read on 2026-10-08. The repository is watched and re-audited when it changes.