No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by ma2za · MCP Server · ★ 173
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is python-substack safe to install? View the security audit →
Python Substack This is an unofficial library providing a Python interface for Substack. I am in no way affiliated with Substack. Installation You can install python-substack using: $ pip install python-substack For the MCP server tools, install the extra dependency set: $ poetry install --with mcp NOTE: We had to upgrade the package requirements to support Python 3.10 because 3.9 is basically vintage now. If you still run 3.9, please join us in the future (or bring snacks). Setup Set the following environment variables by creating a .env file: EMAIL= PASSWORD= PUBLICATIONURL= # Optional: your publication URL COOKIESPATH= # Optional: path to cookies JSON file COOKIESSTRING= # Optional: cookie string for authentication If you don't have a password Recently Substack has been setting up new accounts without a password. If you sign out and sign back in, it just uses your email address with a "magic" link. Set a password: Sign out of Substack At the sign-in page, click "Sign in with password" under the text box Then choose, "Set a new password" The .env file will be ignored by git but always be careful. Usage Check out the examples folder for some
| Stars | 173 |
| Forks | 30 |
| Language | Python |
| Category | MCP Server |
| License | MIT |
| Quality Score | 73.2117317040455/100 |
| Open Issues | 1 |
| Last Updated | 2026-09-11 |
| Created | 2022-06-26 |
| Platforms | cli, mcp, python |
| Est. Tokens | ~15k |
Looking for a python-substack alternative? If you're comparing python-substack with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
A Model Context Protocol (MCP) Server for Substack enabling LLM clients to interact with Substack's API for au
MCP-native security automation workbench (SDK + CLI + MCP) — authorized testing + static AI/MCP attack-surface
Guardrailed video editing MCP server for AI agents. FFmpeg, Hyperframes, repurposing tools, Python client, and
Guardrailed video editing MCP server for AI agents. FFmpeg, Hyperframes, repurposing tools, Python client, and
Runtime-free Bash-first wrapper for LLM APIs. Groq-native, extensible to Gemini/Mistral/HuggingFace. Secure, a
A local Apple Documentation crawler and MCP server. Written in Swift.
Explore other popular mcp server tools:
python-substack is Write and safely manage Substack drafts from Markdown with Python, CLI, and MCP.. It is categorized as a MCP Server with 173 GitHub stars.
python-substack is primarily written in Python. It covers topics such as api-wrapper, automation, cli.
You can find installation instructions and usage details in the python-substack GitHub repository at github.com/ma2za/python-substack. The project has 173 stars and 30 forks, indicating an active community.
python-substack is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to python-substack on Agent Skills Hub include substack-mcp, AutoRedTeam-Orchestrator, kinocut. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: