x-readerBLOCK
Universal content reader MCP Server for 10+ platforms
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.python.org/downloads/) [](LICENSE)
Give your agent a URL. Make it prove what it actually read.
x-reader is a source-first Agent Skill + CLI for X/Twitter, articles, video, podcasts, WeChat, Xiaohongshu, Telegram, RSS, and the open web.
It does one thing differently: a search snippet is not the source, a tweet caption is not the attached video, and a video description is not a transcript. If a material source layer was not actually retrieved, x-reader says so.
简体中文: README.zh-CN.md
Install the Agent Skill
npx skills add runesleo/x-reader --skill x-reader
Then give your agent a URL and ask it to read the original source. For example:
Read the original source. If it contains attached video/audio that matters to the answer, consume that too. Tell me what you actually read and what is still missing.
The canonical skill uses an explicit evidence contract:
PASS original source + all material media needed for the answer were read PARTIAL some material layer is still missing FAIL the original source could not be fetched reliably UNKNOWN retrieved material is too ambiguous to verify
v0.3.1: verified before / after
The source-fetch hardening has a live, reproducible delta against public v0.3.0:
https://example.com: v0.3.0 hit Jina HTTP 401 and failed; v0.3.1 safely falls back todirect_html_pinnedand returnsREAD.- Mixed-media X: v0.3.0 returned the post text without structured media coverage; v0.3.1 returns
media_status=present, so post text can beREADwhile unconsumed attached media staysPARTIAL.
[Watch the 12-second MP4 proof](https://github.com/runesleo/x-reader/releases/download/v0
be8b761e820eOBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add x-reader --env GROQ_API_KEY=${GROQ_API_KEY} -- uvx x-reader{
"mcpServers": {
"x-reader": {
"command": "uvx",
"args": [
"x-reader"
],
"env": {
"GROQ_API_KEY": "${GROQ_API_KEY}"
}
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
detect_platform | read | |
list_inbox | read | |
read_batch | read | |
read_url | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
"metadata.google.internal",
"169.254.169.254",
self.id = hashlib.md5(self.url.encode()).hexdigest()[:12]
url=url or f"manual://{hashlib.md5(title.encode()).hexdigest()[:8]}",assert safe_validate("http://127.0.0.1/secret") is None"Location": "http://127.0.0.1/internal",
["https://example.com", "http://127.0.0.1/internal"],
Gates applied: no_behavioural_pass.
be8b761e820efull audit observations/trust-audit/mcp-server/runesleo__x-reader.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | be8b761e820e | BLOCK | D | 69 | first audit |
Questions
What is the x-reader MCP server?
Universal content reader MCP Server for 10+ platforms
What tools does x-reader expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is x-reader safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does x-reader need?
It reads GROQ_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (be8b761e820e), read on 2026-09-29. The repository is watched and re-audited when it changes.