YouTubeCAUTION
MCP Server for YouTube API, enabling video management, Shorts creation, and advanced analytics
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/zubeid-youtube-mcp-server) [](https://www.npmjs.com/package/zubeid-youtube-mcp-server) [](https://www.npmjs.com/package/zubeid-youtube-mcp-server)
A Model Context Protocol (MCP) server implementation for YouTube, enabling AI language models to interact with YouTube content through a standardized interface.
Website: zubeidhendricks.github.io/youtube-mcp-server
Available Tools
The server currently exposes 10 MCP tools.
074e10c36291OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add zubeid-youtube-mcp-server --env GOOGLE_TRANSLATE_API_KEY=${GOOGLE_TRANSLATE_API_KEY} --env YOUTUBE_API_KEY=${YOUTUBE_API_KEY} --env YOUTUBE_API_KEY2=${YOUTUBE_API_KEY2} --env YOUTUBE_API_KEY3=${YOUTUBE_API_KEY3} -- npx -y [email protected]{
"mcpServers": {
"zubeid-youtube-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GOOGLE_TRANSLATE_API_KEY": "${GOOGLE_TRANSLATE_API_KEY}",
"YOUTUBE_API_KEY": "${YOUTUBE_API_KEY}",
"YOUTUBE_API_KEY2": "${YOUTUBE_API_KEY2}",
"YOUTUBE_API_KEY3": "${YOUTUBE_API_KEY3}"
}
}
}
}Exposed tools (10)
10 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
channels_findCreators | read | Find creator channels from video mentions with subscriber band and recent activity filters in one call |
channels_getChannel | read | Get information about a YouTube channel |
channels_getChannels | read | Get information about multiple YouTube channels |
channels_listVideos | read | Get videos from a specific channel |
channels_searchChannels | read | Search for YouTube channels by handle, name, or query |
playlists_getPlaylist | read | Get information about a YouTube playlist |
playlists_getPlaylistItems | read | Get videos in a YouTube playlist |
transcripts_getTranscript | read | Get the transcript of a YouTube video |
videos_getVideo | read | Get detailed information about a YouTube video |
videos_searchVideos | read | Search for videos on YouTube |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
zubeid-youtube-mcp-server-1.0.0.tgz
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 CMD node -e "fetch('http://127.0.0.1:' + (process.env.MCP_PORT || 8088) + '/ready').then((r) => process.exit(r.ok ? 0 : 1)).catch.mcp.json.example
@modelcontextprotocol/sdk, dotenv, googleapis, youtube-transcript, @types/node, nodemon, ts-node, typescript
- API key is read from `YOUTUBE_API_KEY` environment variable at initialization time
Gates applied: no_behavioural_pass.
074e10c36291full audit observations/trust-audit/mcp-server/zubeidhendricks__youtube-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 074e10c36291 | CAUTION | B | 89 | first audit |
Questions
What is the YouTube MCP server?
MCP Server for YouTube API, enabling video management, Shorts creation, and advanced analytics
What tools does YouTube expose?
10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is YouTube safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does YouTube need?
It reads GOOGLE_TRANSLATE_API_KEY, YOUTUBE_API_KEY, YOUTUBE_API_KEY2 and YOUTUBE_API_KEY3 from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does YouTube run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as zubeid-youtube-mcp-server at 1.0.2.
How current is this page?
The grade is for one exact copy of the source (074e10c36291), read on 2026-09-29. The repository is watched and re-audited when it changes.