Atlas / MCP servers / xquik-dev / X-Twitter Scraper

X-Twitter ScraperBLOCK

mcp/xquik-dev/x-twitter-scraper

X (Twitter) scraper API & X API alternative with REST, MCP, SDKs & webhooks. Not affiliated with X Corp.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
3 2r · 1w · 0d
Transport
streamable-http
License
MIT
Stars
209
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.bestpractices.dev/projects/13731)

English · Español · Türkçe · 简体中文 · 日本語 · 한국어 · Deutsch · Français · Italiano

Search Tweets, profiles, followers & replies. Use REST, MCP, SDKs, CLI, webhooks & Apify.

Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.

Framer demo

Watch Connect Framer to Claude Code, Codex, Cursor, and more at 6:07 for the Xquik MCP connection.

You need an XQUIK_API_KEY for the request below. Public reads need no official X developer account or connected X account.

Private reads and X account actions require a connected X account. Never send an X password, cookie, session export, or 2FA code to Xquik or an agent.

Run one request

Create an API key in the Xquik dashboard. Then run:

export XQUIK_API_KEY='xq_replace_me'

curl --get 'https://xquik.com/api/v1/x/tweets/search' \
--header "x-api-key: ${XQUIK_API_KEY}" \
--data-urlencode 'q=machine learning' \
--data-urlencode 'language=en' \
--data-urlencode 'minLikes=100' \
--data-urlencode 'replies=exclude' \
--data-urlencode 'retweets=exclude' \
--data-urlencode
Read from source at commit 8bf0166595f9OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add x-developer -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "x-developer": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (3)

2 read · 1 write · 0 destructive.

ToolRiskDescription
docsreadSearch Xquik scraper and API documentation. The stub returns setup guidance.
executewriteSend confirmed Xquik API requests. The stub returns setup guidance.
searchreadSearch the credential-scoped OpenAPI catalog. The stub makes no API request.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (8)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
skills/x-twitter-scraper/SKILL.md:75
- Send credentials only to `https://xquik.com/api/v1` or `/mcp` on that host.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/x-twitter-scraper/SKILL.md:67
`x-api-key` header, read from the `XQUIK_API_KEY` environment variable or the
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/x-twitter-scraper/SKILL.md:173
- Never collect X passwords, 2FA codes, cookies, or session tokens. Users
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/xquik-social-research/SKILL.md:13
distinction only for setup, access, credentials, or API comparison questions.
Why it matters. asks the agent to read credentials
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
INFOPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
skills/xquik-social-research/SKILL.md:31
When the user says not to follow a cursor, send one request only.
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/x-twitter-scraper/references/writes.md:106
same secrets, so this Skill never calls it. Never collect or send X passwords,
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/xquik-mcp/references/mcp-setup.md:244
Load `XQUIK_API_KEY` from a password manager or operating-system secret store.
Why it matters. asks the agent to read credentials

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-06 · audit v0.4.1 · source sha 8bf0166595f9full audit observations/trust-audit/mcp-server/xquik-dev__x-twitter-scraper.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-068bf0166595f9BLOCKD69first audit
06

Questions

What is the X-Twitter Scraper MCP server?

X (Twitter) scraper API & X API alternative with REST, MCP, SDKs & webhooks. Not affiliated with X Corp.

What tools does X-Twitter Scraper expose?

3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is X-Twitter Scraper safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does X-Twitter Scraper need?

No credential environment variables were found in its source, so it appears to need none.

How does X-Twitter Scraper run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as x-developer at 2.6.7.

How current is this page?

The grade is for one exact copy of the source (8bf0166595f9), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement