@socialneuron/mcp-server
npm
v2.0.1
Source verified
Published by socialneuron — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.
Official MCP server, REST API & CLI for Social Neuron — create, schedule, and optimize social content with 20+ AI models across YouTube, TikTok, and more.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 2.1 = 98. What the published surface and source actually contain:
| Points | What was found | Category |
|---|---|---|
| −2.1 | Hardcoded JSON Web Token in server code ×3 MTC-SRC-008 | exfiltration |
2. Client adoption risk — 98 − 6 = 92. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`dist/http.js:1`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ileSync as Ht}from"node:child_process";import{closeSync as hn,constants as Me,existsSync as to,fchmodSync as ro,fstatSyn
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/http.js
In the server's implementation (`dist/index.js:2`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ileSync as Jt}from"node:child_process";import{closeSync as Io,constants as He,existsSync as ur,fchmodSync as fr,fstatSyn
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/index.js
In the server's implementation (`dist/sn.js:2`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ileSync as Wt}from"node:child_process";import{closeSync as jo,constants as Fe,existsSync as ir,fchmodSync as lr,fstatSyn
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/sn.js
Untrusted-input tools ([fetch_trends, list_recent_posts, upload_media, fetch_analytics, refresh_platform_analytics, fetch_youtube_analytics, fetch]) co-exist with external-action tools ([execute_recipe]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [fetch_trends, list_recent_posts, upload_media, fetch_analytics, refresh_platform_analytics, fetch_youtube_analytics, fetch] → sinks [execute_recipe]
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow fetch_trends → execute_recipe
A hardcoded JSON Web Token (a public-by-design (anon/publishable) key — RLS, not secrecy, protects it) appears in `dist/http.js:16`. Verify whether this is a real credential; if so, remove and rotate it.
Evidence: JSON Web Token: eyJh…(redacted)
Fix: Remove the secret, rotate it, and load credentials from the environment or a secret store.
Location: server dist/http.js
A hardcoded JSON Web Token (a public-by-design (anon/publishable) key — RLS, not secrecy, protects it) appears in `dist/index.js:17`. Verify whether this is a real credential; if so, remove and rotate it.
Evidence: JSON Web Token: eyJh…(redacted)
Fix: Remove the secret, rotate it, and load credentials from the environment or a secret store.
Location: server dist/index.js
A hardcoded JSON Web Token (a public-by-design (anon/publishable) key — RLS, not secrecy, protects it) appears in `dist/sn.js:17`. Verify whether this is a real credential; if so, remove and rotate it.
Evidence: JSON Web Token: eyJh…(redacted)
Fix: Remove the secret, rotate it, and load credentials from the environment or a secret store.
Location: server dist/sn.js
Each tool and what it can reach — statically extracted from the published source.
execute_recipenetwork egressfetchingests untrusted inputfetch_analyticsingests untrusted inputfetch_trendsingests untrusted inputfetch_youtube_analyticsingests untrusted inputlist_recent_postsingests untrusted inputrefresh_platform_analyticsingests untrusted inputupload_mediaingests untrusted inputadapt_contentno sensitive capabilityaudit_brand_colorsno sensitive capabilityauto_approve_planno sensitive capabilitycancel_async_jobno sensitive capabilitycancel_scheduled_postno sensitive capabilitycapture_app_pageno sensitive capabilitycapture_screenshotno sensitive capabilitycheck_brand_consistencyno sensitive capabilitycheck_pipeline_readinessno sensitive capabilitycheck_statusno sensitive capabilitycreate_autopilot_configno sensitive capabilitycreate_carouselno sensitive capabilitycreate_plan_approvalsno sensitive capabilitycreate_storyboardno sensitive capabilitydelete_autopilot_configno sensitive capabilitydelete_carouselno sensitive capabilitydelete_commentno sensitive capabilitydelete_content_planno sensitive capabilitydetect_anomaliesno sensitive capabilityexplain_brand_systemno sensitive capabilityexport_design_tokensno sensitive capabilityextract_brandno sensitive capabilityextract_url_contentno sensitive capabilityfind_next_slotsno sensitive capabilityfind_winning_contentno sensitive capabilitygenerate_carouselno sensitive capabilitygenerate_contentno sensitive capabilitygenerate_imageno sensitive capabilitygenerate_performance_digestno sensitive capabilitygenerate_videono sensitive capabilitygenerate_voiceoverno sensitive capabilityget_autopilot_statusno sensitive capabilityget_best_posting_timesno sensitive capabilityget_brand_profileno sensitive capabilityget_brand_runtimeno sensitive capabilityget_budget_statusno sensitive capabilityget_content_planno sensitive capabilityget_credit_balanceno sensitive capabilityget_ideation_contextno sensitive capabilityget_loop_summaryno sensitive capabilityget_mcp_usageno sensitive capabilityget_media_urlno sensitive capabilityget_performance_insightsno sensitive capabilityget_pipeline_statusno sensitive capabilityget_recipe_detailsno sensitive capabilityget_recipe_run_statusno sensitive capabilityget_skillno sensitive capabilitylist_autopilot_configsno sensitive capabilitylist_commentsno sensitive capabilitylist_compositionsno sensitive capabilitylist_connected_accountsno sensitive capabilitylist_hyperframes_blocksno sensitive capabilitylist_plan_approvalsno sensitive capabilitylist_recipesno sensitive capabilitylist_skillsno sensitive capabilitymoderate_commentno sensitive capabilityplan_content_weekno sensitive capabilitypost_commentno sensitive capabilityquality_checkno sensitive capabilityquality_check_planno sensitive capabilityrender_demo_videono sensitive capabilityrender_hyperframesno sensitive capabilityrender_template_videono sensitive capabilityreply_to_commentno sensitive capabilityreschedule_postno sensitive capabilityrespond_plan_approvalno sensitive capabilityrun_content_pipelineno sensitive capabilityrun_skillno sensitive capabilitysave_brand_profileno sensitive capabilitysave_content_planno sensitive capabilityschedule_content_planno sensitive capabilityschedule_postno sensitive capabilitysearchno sensitive capabilitysearch_toolsno sensitive capabilitystart_platform_connectionno sensitive capabilitysubmit_content_plan_for_approvalno sensitive capabilitysuggest_next_contentno sensitive capabilityupdate_autopilot_configno sensitive capabilityupdate_content_planno sensitive capabilityupdate_platform_voiceno sensitive capabilityvisual_gate_constraintsno sensitive capabilityvisual_quality_checkno sensitive capabilitywait_for_connectionno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v2.0.1 latest |
A 92/100 | 7 | 1.13.0 | 2026-09-07 |
v1.9.2 |
A 92/100 | 6 | 1.10.0 | 2026-07-27 |
v1.9.1 |
A 92/100 | 6 | 1.9.0 | 2026-07-24 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @socialneuron/mcp-server --online
Official Abyssfall game info, newsletter double opt-in, and merch reservation tools.
AdCritter ads platform: docs, API reference, app scaffolding, and white-label integration.
Google AdSense MCP Server - Monitor earnings, reports, and account health via Claude/AI
Operational empathy for technical founders + PE/VC operators navigating high-stakes B2B interactions. 28 MCP tools + CLI: ICP scoring, persona simulation, battlecards, deal classification, prospect discovery, investor matching, founder wellness, plus mark
MCP server for Bing Webmaster Tools — SEO site management, URL submission, sitemaps, stats, keywords
MCP (Model Context Protocol) server that helps AI agents use Primer Brand (@primer/react-brand) correctly when building GitHub marketing and landing pages.