OmniGetBLOCK
Udemy & Hotmart course downloader, YouTube downloader (yt-dlp GUI, 1,800+ sites) + desktop app for AI agents: Claude Code, Codex, Gemini CLI, Ollama. Permissions, undo, jobs, loops until tests pass, MCP server, 156 tools, course player. Free and open source for Windows, macOS and Linux. No terminal.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
0764ecd2d794OBSERVED · 2026-09-20Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add omniget --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GENERATE_I18N_KEYS_STRICT=${GENERATE_I18N_KEYS_STRICT} --env GOOGLE_API_KEY=${GOOGLE_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"omniget": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"GENERATE_I18N_KEYS_STRICT": "${GENERATE_I18N_KEYS_STRICT}",
"GOOGLE_API_KEY": "${GOOGLE_API_KEY}"
}
}
}
}Exposed tools (43)
38 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Convert | read | FFmpeg conversions with GPU acceleration. |
Courses | read | Download from Hotmart, Udemy, Kiwify and Rocketseat. |
Study | read | Reader, player, notes, flashcards and focus tools. |
Telegram | read | Browse and batch-download from Telegram chats. |
Utilities | read | Screen recording studio, file clips and media library. |
a | read | d |
add | write | Add two numbers. |
b | read | |
bad-skill | read | d |
big | read | Return kb kilobytes of text, to exercise long lines. |
dup | read | old |
echo | read | Return the text it was given. |
env | read | Return one environment variable of the server process. |
fail | read | Answer with isError: true and no structured content. |
fetch | read | Fetch a url |
g | read | d |
good-skill | read | d |
greet | read | Say hello. |
headers | read | Return the headers of the last HTTP request the server saw. |
install-ori-harness | write | Install Ori and run the user |
left-over | read | d |
list_directory | read | List the files and folders of a directory. |
ok | read | d |
openrouter-agent-migration | read | Migration guide from @openrouter/sdk to @openrouter/agent for callModel, tool(), stop conditions, and agent features. This skill should be used when code imports callModel, tool(), or stop conditions from @openrouter/sdk and needs to migrate to @openrouter/agent. |
openrouter-analytics | read | Answer natural-language questions about a user |
openrouter-analytics-query | write | Construct and execute analytics queries against the OpenRouter API — full parameter reference for metrics, dimensions, filters, time ranges, ordering, and pagination. Use when building or debugging an analytics query, understanding the request/response shape, or handling query errors. |
openrouter-analytics-schema | read | Discover the OpenRouter analytics schema — available metrics, dimensions, filter operators, and granularities. Use when you need to know what analytics data is queryable, what dimensions you can break down by, or how to map a user |
openrouter-benchmarks | read | Query OpenRouter |
openrouter-generations | read | Retrieve detailed metadata and stored content for individual OpenRouter generations. Use when the user wants to inspect a specific request — its cost, latency, token usage, provider routing, or the actual prompt/completion text — or is debugging a failed or unexpected generation. |
openrouter-images | write | Generate images from text prompts and edit existing images using OpenRouter |
openrouter-models | read | Queries OpenRouter for models, pricing, context length, capabilities, throughput and provider performance. |
openrouter-oauth | read | Implement \ |
openrouter-stt | read | Transcribe speech to text using OpenRouter |
openrouter-tts | read | Generate speech audio from text using OpenRouter |
openrouter-typescript-sdk | read | Complete reference for integrating with 300+ AI models through the OpenRouter TypeScript SDK and Agent packages using the callModel pattern |
openrouter-video | read | Generate videos from text prompts (and optional reference or frame images) using OpenRouter |
plain | read | d |
read_file | read | Read the complete contents of a file. |
release-notes | read | Writes the release notes of a version from the commits since the last tag. |
slow | read | Answer after a delay, to exercise timeouts and cancellation. |
write_file | destructive | Create a new file or overwrite an existing one. |
x | read | d |
z | read | d |
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (13 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
tracing::error!("[auth_webview] eval() error: {}", e);**Automatic login retry.** When a fetch is blocked by a login wall or rate-limit, the scripts retry once on their own using the browser you're logged into (auto-detected: Chrome/Brave/Edge/Firefox/Saf
icon.icns
pet-state.ts
text.ts
/\/beacon(\/|\?|$)/i,
/\/beacon(\/|\?|$)/i,
pub callback_url: String,
const FALLBACK_ENDPOINT = "http://127.0.0.1:47720";
const DEFAULT_ENDPOINT = "http://127.0.0.1:47720";
"http://127.0.0.1/__omniget_deep_search_probe__/*",
write_file
capture-rules.test.mjs
pet-state.test.ts
.weblate
input: { path: '/Users/tonho/.ssh/id_ed25519' },expect(JSON.stringify(clean)).not.toContain('id_ed25519');["../manifest.json", "../../firefox/manifest.json"].map(async (rel) =>
await readFile(new URL("../../firefox/manifest.json", import.meta.url), "utf8")const FIXTURES: &str = include_str!("../../../tests/embed_fixtures/minilm_vectors.json");const VOCAB: &str = include_str!("../../../tests/embed_fixtures/vocab.txt");open_in(&root, "../../etc").unwrap_err().code(),
const out = normalizeBlocklist([" Ads.EXAMPLE.com ", "*.tracker.io", ".beacon.net"]);
assert.deepEqual(out, ["ads.example.com", "tracker.io", "beacon.net"]);
placeholder="http://127.0.0.1:47720"
Gates applied: no_behavioural_pass.
0764ecd2d794full audit observations/trust-audit/mcp-server/tonhowtf__omniget.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-20 | 0764ecd2d794 | BLOCK | D | 60 | first audit |
Questions
What is the OmniGet MCP server?
Udemy & Hotmart course downloader, YouTube downloader (yt-dlp GUI, 1,800+ sites) + desktop app for AI agents: Claude Code, Codex, Gemini CLI, Ollama. Permissions, undo, jobs, loops until tests pass, MCP server, 156 tools, course player. Free and open source for Windows, macOS and Linux. No terminal.
What tools does OmniGet expose?
43 in total: 38 read-only, 4 that write, and 1 that can delete or overwrite (write_file). Every one is listed on this page with its risk.
Is OmniGet safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does OmniGet need?
It reads GEMINI_API_KEY, GENERATE_I18N_KEYS_STRICT and GOOGLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does OmniGet run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as omniget at 0.10.0.
How current is this page?
The grade is for one exact copy of the source (0764ecd2d794), read on 2026-09-20. The repository is watched and re-audited when it changes.