TwilioCAUTION
Monorepo providing 1) OpenAPI to MCP Tool generator 2) Exposing all of Twilio's API as MCP Tools
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Twilio MCP Monorepo
This is a monorepo for the Model Context Protocol server that exposes all of Twilio APIs.
What is MCP?
The Model Context Protocol (MCP) is a protocol for exchanging model context information between AI tools and services. This implementation allows you to expose Twilio's APIs to AI assistants and other tools that support the MCP protocol.
Packages
This monorepo contains two main packages:
- mcp - MCP Server for all of Twilio's Public API
- openapi-mcp-server - An MCP server that serves the given OpenAPI spec
Each package has its own comprehensive README with detailed documentation:
- MCP Package Documentation
- OpenAPI MCP Server Documentation
Quick Start
The easiest way to get started is by using npx:
{
"mcpServers": {
"twilio": {
"command": "npx",
"args": [
"-y",
"@twilio-alpha/mcp",
"YOUR_ACCOUNT_SID/YOUR_API_KEY:YOUR_API_SECRET"
]
}
}
}Visit Twilio API Keys docs for information on how to find/create your API Key and Secret.
Security Recommendations
To guard against injection attacks that may allow untrusted systems access to your Twilio data, the ETI team advises users of Twilio MCP servers to avoid installing or running any community MCP servers alongside our official ones. Doing so helps ensure that only trusted MCP servers have access to tools interacting with your Twilio account, reducin
2fdc95cc1809OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add openapi-mcp-server -- npx -y @twilio-alpha/[email protected]
{
"mcpServers": {
"openapi-mcp-server": {
"command": "npx",
"args": [
"-y",
"@twilio-alpha/[email protected]"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
TestTool | read | A test tool |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (10)
apiKey: 'SK00000000000000000000000000000000',
apiKey: 'SK11111111111111111111111111111111',
import loadAdditionalTools from '../../src/tools/additionalTools';
import { uploadFunctionDefinition } from '../../src/tools/uploadFunction';import { uploadAssetDefinition } from '../../src/tools/uploadAsset';} from '../../src/tools/uploadAsset';
} from '../../src/tools/uploadFunction';
@changesets/cli, eslint-plugin-prettier, husky, lint-staged, npm-run-all
@apidevtools/swagger-parser, @modelcontextprotocol/sdk, form-data, inquirer, minimist, openapi-types, @types/form-data, @types/minimist
@apidevtools/swagger-parser, @modelcontextprotocol/sdk, form-data, minimist, node-fetch, openapi-types, pino, pino-pretty
Gates applied: no_behavioural_pass.
2fdc95cc1809full audit observations/trust-audit/mcp-server/twilio-labs__twilio-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 2fdc95cc1809 | CAUTION | B | 87 | first audit |
Questions
What is the Twilio MCP server?
Monorepo providing 1) OpenAPI to MCP Tool generator 2) Exposing all of Twilio's API as MCP Tools
What tools does Twilio expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Twilio safe to connect to an agent?
With care. The audit graded it B (87/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Twilio need?
No credential environment variables were found in its source, so it appears to need none.
How does Twilio run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @twilio-alpha/openapi-mcp-server at 0.7.0.
How current is this page?
The grade is for one exact copy of the source (2fdc95cc1809), read on 2026-10-07. The repository is watched and re-audited when it changes.