io.github.CDCStream/captapi

MCPCommunity
v0.2.1io.github.CDCStreamUnknownAktualisiert vor 2 Mon.npmGitHub

Social media data from YouTube, TikTok, Instagram & Facebook. 62 tools, one API key.

Official Captapi MCP server. Give Claude, Cursor, VS Code, and any MCP-compatible AI agent direct access to 62 social media data endpoints across YouTube, TikTok, Instagram, and Facebook — transcripts, summaries, comments, channel stats, search, bulk lists, and downloads. One Captapi key works across every platform. The agent calls a tool, Captapi handles proxies, rate limits, retries, and auth,…

Läuft in
ClaudeCursorCopilotChatGPTGemini

Abgeleitet aus den Transporten, die dieser Eintrag deklariert (stdio, streamable-http). Ein Client, der hier nicht steht, ist damit nicht ausgeschlossen — Forge kann ihn nur nicht bestätigen.

Automatisch aus öffentlichen Quellen indexiert. Vom Entwickler auf Forge noch nicht verifiziert.Diesen Eintrag beanspruchen →
vor 2 Mon.Letzte Aktualisierung
Blast radius
Contained – CriticalNot fully measured

Contained to critical — not scanned yet — tool surface unknown. Known so far: runs locally and hosted.

ContainedModerateExtensiveCritical

At worst: Arbitrary execution, or execution together with a live credential. A compromise here is a compromise of the host or the account.

What raises it
  • Runs locally and hosteddeclared+12

    Ships both an installable package and a hosted endpoint. Whichever you pick, the other is available: local execution borrows your machine's authority, hosted execution sends your prompts and tool arguments to a third party.

What Forge could not measure
  • executionup to +40

    not scanned yet — tool surface unknown. Nothing is known about what this entry can do, which is not the same as it being able to do little.

  • credentialsup to +18

    No credential declaration found, from the publisher, the upstream registry, or the README. That is an absence of evidence, not evidence this entry needs nothing.

  • supplyup to +6

    Never scanned, so neither the install-time scripts nor the size of the dependency tree behind this entry has been read.

Blast radius measures what this entry can reach, not how likely it is to misbehave — that is the trust score, and the two are deliberately separate axes. A high blast radius is not a defect: a filesystem server is supposed to write files. It never moves the trust grade in either direction. How this is calculated →

Paket
Autorio.github.CDCStream
LizenzUnknown
Version0.2.1
Quellemcp-registry
Trust-Status
F
10/100Nicht vertrauenswürdig
Im Forge-Index gelistet+10/10
Publisher-Identität verifiziert+0/20
Publisher: führe `forge publish` im Repo des Pakets aus, um die Inhaberschaft zu beanspruchen
Ed25519-Publish-Signatur+0/5
Wird automatisch ergänzt, wenn der Publisher `forge publish` ausführt
Domain-Verifizierung+0/5
Publisher: hinterlege /.well-known/forge.json auf der Paket-Homepage mit { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+0/5
Veröffentliche aus GitHub Actions mit --provenance, damit die Attestation dieses Paket an dieses Repo bindet
npm-Maintainer-Übereinstimmung+0/5
Wird erreicht, sobald deine Identität oben verifiziert ist und dieser Login npm-Maintainer dieses Pakets ist
CVE-Scan · nicht ausgeführt+0/30
Noch nicht gescannt — das Paket muss auf npm liegen
Statische Analyse · sauber+0/20
Noch nicht gescannt — das Paket muss auf npm liegen
Füge das in Claude Code, Cursor oder einen beliebigen KI-Assistenten ein, um alle Lücken zu schließen
StatusVon der Community indexiert
PublisherNicht verifiziert
SignaturNicht signiert
Domain
Herkunft
AbhängigkeitenNicht auditiert
Tool-Oberfläche
Sicherheits-ScanNicht ausgeführtWie gut funktioniert dieser Scan?
EvaluierungenKeine
Indexiert13. Juni 2026

Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.

Tools

Noch nicht sondiert

Forge hat gegen diesen Endpunkt keinen tools/list-Handshake abgeschlossen und hat daher keine Beobachtung dessen, was der Server offenlegt. Nichts hiervon sagt, dass er nichts offenlegt.

Über

Official Captapi MCP server. Give Claude, Cursor, VS Code, and any MCP-compatible AI agent direct access to 62 social media data endpoints across YouTube, TikTok, Instagram, and Facebook — transcripts, summaries, comments, channel stats, search, bulk lists, and downloads. One Captapi key works across every platform. The agent calls a tool, Captapi handles proxies, rate limits, retries, and auth, and returns clean JSON. You need a Captapi API key (). Get one at captapi.com/dashboard/api-keys.…

Schlagwörter
mcp
Alternativen
Tool-Oberflächen werden verglichen…

Keine Abdeckung der Abhängigkeiten

Dieses Paket wurde noch nicht gescannt, daher wurde kein Abhängigkeitsbaum aufgelöst.