No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by DataWhisker · MCP Server · ★ 75
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is x-mcp-server safe to install? View the security audit →
X MCP Server A Model Context Protocol (MCP) server for X (Twitter) integration. Provides 26 tools for reading timelines, posting, searching, engagement (likes, retweets, bookmarks), user lookup, follower export, mentions, likes, articles, and lists. Designed for use with Claude desktop and other MCP-compatible clients. Features Timeline & Search - Home timeline, search recent posts (7-day window) Post Management - Create, reply, quote, delete posts with optional media Engagement - Like/unlike, retweet/undo, bookmark/unbookmark User Data - Mentions, liked posts, followers, following, blocks, mutes, owned lists, followed lists, and list memberships User Lookup - Get user profiles and their recent posts Media Upload - Images (PNG, JPEG, GIF, WEBP) and videos (MP4, MOV, AVI, WEBM, M4V) via v2 upload API Dual Auth - OAuth 1.0a for post operations, OAuth 2.0 for media upload (v1.1 upload was sunset June 2025) Rate Limiting - Automatic per-endpoint rate limit tracking with clear error messages TypeScript - Full type safety, modular file structure Prerequisites Node.js = 18.0.0 X (Twitter) Developer Account Claude desktop app (or any MCP-compatible client) X API Access & Pricing
| Stars | 75 |
| Forks | 19 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 61.0633204188898/100 |
| Open Issues | 1 |
| Last Updated | 2026-06-21 |
| Created | 2024-12-21 |
| Platforms | mcp, node |
| Est. Tokens | ~6k |
These tools work well together with x-mcp-server for enhanced workflows:
Explore other popular mcp server tools:
x-mcp-server is an open-source mcp server by DataWhisker with 75 GitHub stars.
x-mcp-server is primarily written in TypeScript.
You can find installation instructions and usage details in the x-mcp-server GitHub repository at github.com/DataWhisker/x-mcp-server. The project has 75 stars and 19 forks, indicating an active community.
x-mcp-server is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: