Atlas / MCP servers / tonhowtf / OmniGet

OmniGetBLOCK

mcp/tonhowtf/omniget

Udemy & Hotmart course downloader, YouTube downloader (yt-dlp GUI, 1,800+ sites) + desktop app for AI agents: Claude Code, Codex, Gemini CLI, Ollama. Permissions, undo, jobs, loops until tests pass, MCP server, 156 tools, course player. Free and open source for Windows, macOS and Linux. No terminal.

Verdict
BLOCK
Grade
D
Trust score
60 /100
Exposed tools
43 38r · 4w · 1d
Transport
stdio · streamable-http
License
GPL-3.0
Stars
13,958
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Read from source at commit 0764ecd2d794OBSERVED · 2026-09-20
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add omniget --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GENERATE_I18N_KEYS_STRICT=${GENERATE_I18N_KEYS_STRICT} --env GOOGLE_API_KEY=${GOOGLE_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "omniget": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "GENERATE_I18N_KEYS_STRICT": "${GENERATE_I18N_KEYS_STRICT}",
        "GOOGLE_API_KEY": "${GOOGLE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (43)

38 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ConvertreadFFmpeg conversions with GPU acceleration.
CoursesreadDownload from Hotmart, Udemy, Kiwify and Rocketseat.
StudyreadReader, player, notes, flashcards and focus tools.
TelegramreadBrowse and batch-download from Telegram chats.
UtilitiesreadScreen recording studio, file clips and media library.
areadd
addwriteAdd two numbers.
bread
bad-skillreadd
bigreadReturn kb kilobytes of text, to exercise long lines.
dupreadold
echoreadReturn the text it was given.
envreadReturn one environment variable of the server process.
failreadAnswer with isError: true and no structured content.
fetchreadFetch a url
greadd
good-skillreadd
greetreadSay hello.
headersreadReturn the headers of the last HTTP request the server saw.
install-ori-harnesswriteInstall Ori and run the user
left-overreadd
list_directoryreadList the files and folders of a directory.
okreadd
openrouter-agent-migrationreadMigration guide from @openrouter/sdk to @openrouter/agent for callModel, tool(), stop conditions, and agent features. This skill should be used when code imports callModel, tool(), or stop conditions from @openrouter/sdk and needs to migrate to @openrouter/agent.
openrouter-analyticsreadAnswer natural-language questions about a user
openrouter-analytics-querywriteConstruct and execute analytics queries against the OpenRouter API — full parameter reference for metrics, dimensions, filters, time ranges, ordering, and pagination. Use when building or debugging an analytics query, understanding the request/response shape, or handling query errors.
openrouter-analytics-schemareadDiscover the OpenRouter analytics schema — available metrics, dimensions, filter operators, and granularities. Use when you need to know what analytics data is queryable, what dimensions you can break down by, or how to map a user
openrouter-benchmarksreadQuery OpenRouter
openrouter-generationsreadRetrieve detailed metadata and stored content for individual OpenRouter generations. Use when the user wants to inspect a specific request — its cost, latency, token usage, provider routing, or the actual prompt/completion text — or is debugging a failed or unexpected generation.
openrouter-imageswriteGenerate images from text prompts and edit existing images using OpenRouter
openrouter-modelsreadQueries OpenRouter for models, pricing, context length, capabilities, throughput and provider performance.
openrouter-oauthreadImplement \
openrouter-sttreadTranscribe speech to text using OpenRouter
openrouter-ttsreadGenerate speech audio from text using OpenRouter
openrouter-typescript-sdkreadComplete reference for integrating with 300+ AI models through the OpenRouter TypeScript SDK and Agent packages using the callModel pattern
openrouter-videoreadGenerate videos from text prompts (and optional reference or frame images) using OpenRouter
plainreadd
read_filereadRead the complete contents of a file.
release-notesreadWrites the release notes of a version from the commits since the last tag.
slowreadAnswer after a delay, to exercise timeouts and cancellation.
write_filedestructiveCreate a new file or overwrite an existing one.
xreadd
zreadd
04

Trust audit

BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (13 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src-tauri/src/commands/auth_webview.rs:482
tracing::error!("[auth_webview] eval() error: {}", e);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
claude-plugin/omniget/skills/omniget-fetch/SKILL.md:62
**Automatic login retry.** When a fetch is blocked by a login wall or rate-limit, the scripts retry once on their own using the browser you're logged into (auto-detected: Chrome/Brave/Edge/Firefox/Saf
Why it matters. asks the agent to read credentials
MEDIUMInventory / provenance · inv.binary · CWE-1104
src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/lib/omni/pet-state.ts
pet-state.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/lib/world/render/text.ts
text.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
browser-extension/chrome/src/media-sniffer.js:14
/\/beacon(\/|\?|$)/i,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
browser-extension/firefox/src/media-sniffer.js:14
/\/beacon(\/|\?|$)/i,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src-tauri/omniget-core/src/core/tools/ai_keys.rs:847
pub callback_url: String,
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
browser-extension/chrome/pages/options.js:238
const FALLBACK_ENDPOINT = "http://127.0.0.1:47720";
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
browser-extension/chrome/src/bridge-client.js:24
const DEFAULT_ENDPOINT = "http://127.0.0.1:47720";
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
browser-extension/chrome/src/deep-search-toggle.js:41
"http://127.0.0.1/__omniget_deep_search_probe__/*",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
write_file
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
browser-extension/chrome/tests/capture-rules.test.mjs
capture-rules.test.mjs
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
src/lib/omni/pet-state.test.ts
pet-state.test.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.weblate
.weblate
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/lib/omni/tool-ask-queue.test.ts:32
input: { path: '/Users/tonho/.ssh/id_ed25519' },
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/lib/omni/tool-ask-queue.test.ts:36
expect(JSON.stringify(clean)).not.toContain('id_ed25519');
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
browser-extension/chrome/tests/deep-search.test.mjs:287
["../manifest.json", "../../firefox/manifest.json"].map(async (rel) =>
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
browser-extension/chrome/tests/manifest.test.mjs:133
await readFile(new URL("../../firefox/manifest.json", import.meta.url), "utf8")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src-tauri/omniget-core/src/core/embed/minilm.rs:573
const FIXTURES: &str = include_str!("../../../tests/embed_fixtures/minilm_vectors.json");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src-tauri/omniget-core/src/core/embed/tokenizer.rs:289
const VOCAB: &str = include_str!("../../../tests/embed_fixtures/vocab.txt");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src-tauri/omniget-core/src/core/skills/inject.rs:365
open_in(&root, "../../etc").unwrap_err().code(),
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
browser-extension/chrome/tests/blocked-hosts.test.mjs:22
const out = normalizeBlocklist(["  Ads.EXAMPLE.com  ", "*.tracker.io", ".beacon.net"]);
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
browser-extension/chrome/tests/blocked-hosts.test.mjs:24
assert.deepEqual(out, ["ads.example.com", "tracker.io", "beacon.net"]);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
browser-extension/chrome/pages/options.html:62
placeholder="http://127.0.0.1:47720"

Gates applied: no_behavioural_pass.

Audited 2026-09-20 · audit v0.4.1 · source sha 0764ecd2d794full audit observations/trust-audit/mcp-server/tonhowtf__omniget.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-200764ecd2d794BLOCKD60first audit
06

Questions

What is the OmniGet MCP server?

Udemy & Hotmart course downloader, YouTube downloader (yt-dlp GUI, 1,800+ sites) + desktop app for AI agents: Claude Code, Codex, Gemini CLI, Ollama. Permissions, undo, jobs, loops until tests pass, MCP server, 156 tools, course player. Free and open source for Windows, macOS and Linux. No terminal.

What tools does OmniGet expose?

43 in total: 38 read-only, 4 that write, and 1 that can delete or overwrite (write_file). Every one is listed on this page with its risk.

Is OmniGet safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (60/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OmniGet need?

It reads GEMINI_API_KEY, GENERATE_I18N_KEYS_STRICT and GOOGLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OmniGet run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as omniget at 0.10.0.

How current is this page?

The grade is for one exact copy of the source (0764ecd2d794), read on 2026-09-20. The repository is watched and re-audited when it changes.

Advertisement