Atlas / MCP servers / twilio-labs / Twilio

TwilioCAUTION

mcp/twilio-labs/twilio-1

Monorepo providing 1) OpenAPI to MCP Tool generator 2) Exposing all of Twilio's API as MCP Tools

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
112
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Twilio MCP Monorepo

This is a monorepo for the Model Context Protocol server that exposes all of Twilio APIs.

What is MCP?

The Model Context Protocol (MCP) is a protocol for exchanging model context information between AI tools and services. This implementation allows you to expose Twilio's APIs to AI assistants and other tools that support the MCP protocol.

Packages

This monorepo contains two main packages:

  • mcp - MCP Server for all of Twilio's Public API
  • openapi-mcp-server - An MCP server that serves the given OpenAPI spec

Each package has its own comprehensive README with detailed documentation:

  • MCP Package Documentation
  • OpenAPI MCP Server Documentation

Quick Start

The easiest way to get started is by using npx:

{
"mcpServers": {
"twilio": {
"command": "npx",
"args": [
"-y",
"@twilio-alpha/mcp",
"YOUR_ACCOUNT_SID/YOUR_API_KEY:YOUR_API_SECRET"
]
}
}
}

Visit Twilio API Keys docs for information on how to find/create your API Key and Secret.

Security Recommendations

To guard against injection attacks that may allow untrusted systems access to your Twilio data, the ETI team advises users of Twilio MCP servers to avoid installing or running any community MCP servers alongside our official ones. Doing so helps ensure that only trusted MCP servers have access to tools interacting with your Twilio account, reducin

Read from source at commit 2fdc95cc1809OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add openapi-mcp-server -- npx -y @twilio-alpha/[email protected]
claude-desktop
{
  "mcpServers": {
    "openapi-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@twilio-alpha/[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
TestToolreadA test tool
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (10)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp/tests/server.spec.ts:57
apiKey: 'SK00000000000000000000000000000000',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/mcp/tests/utils/args.spec.ts:150
apiKey: 'SK11111111111111111111111111111111',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp/tests/tools/additionalTools.spec.ts:2
import loadAdditionalTools from '../../src/tools/additionalTools';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp/tests/tools/additionalTools.spec.ts:3
import { uploadFunctionDefinition } from '../../src/tools/uploadFunction';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp/tests/tools/additionalTools.spec.ts:4
import { uploadAssetDefinition } from '../../src/tools/uploadAsset';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp/tests/tools/uploadAsset.spec.ts:9
} from '../../src/tools/uploadAsset';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp/tests/tools/uploadFunction.spec.ts:9
} from '../../src/tools/uploadFunction';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@changesets/cli, eslint-plugin-prettier, husky, lint-staged, npm-run-all
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp/package.json
@apidevtools/swagger-parser, @modelcontextprotocol/sdk, form-data, inquirer, minimist, openapi-types, @types/form-data, @types/minimist
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/openapi-mcp-server/package.json
@apidevtools/swagger-parser, @modelcontextprotocol/sdk, form-data, minimist, node-fetch, openapi-types, pino, pino-pretty
Why it matters. 26 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 2fdc95cc1809full audit observations/trust-audit/mcp-server/twilio-labs__twilio-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-072fdc95cc1809CAUTIONB87first audit
06

Questions

What is the Twilio MCP server?

Monorepo providing 1) OpenAPI to MCP Tool generator 2) Exposing all of Twilio's API as MCP Tools

What tools does Twilio expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Twilio safe to connect to an agent?

With care. The audit graded it B (87/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Twilio need?

No credential environment variables were found in its source, so it appears to need none.

How does Twilio run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @twilio-alpha/openapi-mcp-server at 0.7.0.

How current is this page?

The grade is for one exact copy of the source (2fdc95cc1809), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement