Atlas / MCP servers / rafaljanicki / X Twitter

X TwitterSAFE

mcp/rafaljanicki/x-twitter-1

X/Twitter MCP server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
18 13r · 2w · 3d
Transport
streamable-http
License
MIT
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@rafaljanicki/x-twitter-mcp-server) [](https://badge.fury.io/py/x-twitter-mcp)

A Model Context Protocol (MCP) server for interacting with Twitter (X) via AI tools. This server allows you to fetch tweets, post tweets, search Twitter, manage followers, and more, all through natural language commands in AI Tools.

Features

  • Fetch user profiles, followers, and following lists.
  • Post, delete, and favorite tweets.
  • Search Twitter for tweets and trends.
  • Manage bookmarks and timelines.
  • Built-in rate limit handling for the Twitter API.
  • Uses Twitter API v2 with proper authentication (API keys and tokens), avoiding the username/password hack to minimize the risk of account suspensions.
  • Provides a complete implementation of Twitter API v2 endpoints for user management, tweet management, timelines, and search functionality.

Prerequisites

  • Python 3.10 or higher: Ensure Python is installed on your system.
  • Twitter Developer Account: You need API credentials (API Key, API Secret, Access Token, Access Token Secret, and Bearer Token) from the Twitter Developer Portal.
  • Optional: Claude Desktop: Download and install the Claude Desktop app from the Anthropic website.
  • Optional: Node.js (for MCP integration): Required for running MCP servers in Claude Desktop.
  • A package manager like uv or pip for Python dependencies.

Installation

Option 1: Installing via Smithery (Recommended)

To install X (Twitter) MCP server for Claude Desktop automatically via [Smithe

Read from source at commit 4154be1f3287OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add x-twitter-mcp --env TWITTER_ACCESS_TOKEN=${TWITTER_ACCESS_TOKEN} --env TWITTER_ACCESS_TOKEN_SECRET=${TWITTER_ACCESS_TOKEN_SECRET} --env TWITTER_API_KEY=${TWITTER_API_KEY} --env TWITTER_API_SECRET=${TWITTER_API_SECRET} -- uvx x-twitter-mcp
claude-desktop
{
  "mcpServers": {
    "x-twitter-mcp": {
      "command": "uvx",
      "args": [
        "x-twitter-mcp"
      ],
      "env": {
        "TWITTER_ACCESS_TOKEN": "${TWITTER_ACCESS_TOKEN}",
        "TWITTER_ACCESS_TOKEN_SECRET": "${TWITTER_ACCESS_TOKEN_SECRET}",
        "TWITTER_API_KEY": "${TWITTER_API_KEY}",
        "TWITTER_API_SECRET": "${TWITTER_API_SECRET}"
      }
    }
  }
}
03

Exposed tools (18)

13 read · 2 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
bookmark_tweetreadBookmarks a tweet.
create_poll_tweetwriteCreates a poll tweet.
delete_all_bookmarksdestructivePermanently deletes all of the authenticated user
delete_bookmarkdestructiveRemoves a bookmark.
delete_tweetdestructiveDeletes a tweet.
favorite_tweetreadFavorites a tweet.
get_bookmarksreadFetches the authenticated user
get_trendsreadFetches trending topics (uses Twitter API v1.1 as v2 trends require specific location WOEID).
get_tweet_detailsreadFetches tweet details.
get_user_by_idreadFetches user by ID.
get_user_by_screen_namereadFetches user by screen name.
get_user_followersreadRetrieves a list of followers for a given user.
get_user_followingreadRetrieves a list of users whom the given user is following.
get_user_mentionsreadFetches tweets mentioning a specific user.
get_user_profilereadFetches user profile by user ID.
post_tweetwritePosts a tweet.
search_twitterreadSearches Twitter for recent tweets.
unfavorite_tweetreadUnfavorites a tweet.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_all_bookmarks, delete_bookmark, delete_tweet
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/x_twitter_mcp/middleware.py:28
raw = base64.b64decode(unquote(enc))
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, python-dotenv, tweepy
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:25
- **Twitter Developer Account**: You need API credentials (API Key, API Secret, Access Token, Access Token Secret, and Bearer Token) from the [Twitter Developer Portal](https://developer.twitter.com/)
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4154be1f3287full audit observations/trust-audit/mcp-server/rafaljanicki__x-twitter-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084154be1f3287SAFEB89first audit
06

Questions

What is the X Twitter MCP server?

X/Twitter MCP server

What tools does X Twitter expose?

18 in total: 13 read-only, 2 that write, and 3 that can delete or overwrite (delete_all_bookmarks, delete_bookmark, delete_tweet). Every one is listed on this page with its risk.

Is X Twitter safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does X Twitter need?

It reads TWITTER_ACCESS_TOKEN, TWITTER_ACCESS_TOKEN_SECRET, TWITTER_API_KEY, TWITTER_API_SECRET, TWITTER_BEARER_TOKEN and TWITTER_OAUTH2_USER_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does X Twitter run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as x-twitter-mcp.

How current is this page?

The grade is for one exact copy of the source (4154be1f3287), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement