io.github.CDCStream/captapi

MCPcommunity
v0.2.1io.github.CDCStreamUnknownAggiornato 2 mesi fanpmGitHub

Social media data from YouTube, TikTok, Instagram & Facebook. 62 tools, one API key.

Official Captapi MCP server. Give Claude, Cursor, VS Code, and any MCP-compatible AI agent direct access to 62 social media data endpoints across YouTube, TikTok, Instagram, and Facebook — transcripts, summaries, comments, channel stats, search, bulk lists, and downloads. One Captapi key works across every platform. The agent calls a tool, Captapi handles proxies, rate limits, retries, and auth,…

Funziona in
ClaudeCursorCopilotChatGPTGemini

Dedotto dai trasporti dichiarati da questo annuncio (stdio, streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.

Indicizzato automaticamente da fonti pubbliche. Non ancora verificato dal suo sviluppatore su Forge.Rivendica questo annuncio →
2 mesi faUltimo aggiornamento
Blast radius
Contained – CriticalNot fully measured

Contained to critical — not scanned yet — tool surface unknown. Known so far: runs locally and hosted.

ContainedModerateExtensiveCritical

At worst: Arbitrary execution, or execution together with a live credential. A compromise here is a compromise of the host or the account.

What raises it
  • Runs locally and hosteddeclared+12

    Ships both an installable package and a hosted endpoint. Whichever you pick, the other is available: local execution borrows your machine's authority, hosted execution sends your prompts and tool arguments to a third party.

What Forge could not measure
  • executionup to +40

    not scanned yet — tool surface unknown. Nothing is known about what this entry can do, which is not the same as it being able to do little.

  • credentialsup to +18

    No credential declaration found, from the publisher, the upstream registry, or the README. That is an absence of evidence, not evidence this entry needs nothing.

  • supplyup to +6

    Never scanned, so neither the install-time scripts nor the size of the dependency tree behind this entry has been read.

Blast radius measures what this entry can reach, not how likely it is to misbehave — that is the trust score, and the two are deliberately separate axes. A high blast radius is not a defect: a filesystem server is supposed to write files. It never moves the trust grade in either direction. How this is calculated →

Pacchetto
Autoreio.github.CDCStream
LicenzaUnknown
Versione0.2.1
Fontemcp-registry
Stato di fiducia
F
10/100Non affidabile
Presente nell’indice di Forge+10/10
Identità del publisher verificata+0/20
Publisher: esegui `forge publish` dal repo del pacchetto per rivendicarne la proprietà
Firma di pubblicazione Ed25519+0/5
Inclusa automaticamente quando il publisher esegue `forge publish`
Verifica del dominio+0/5
Publisher: ospita /.well-known/forge.json sulla homepage del pacchetto con { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+0/5
Pubblica da GitHub Actions con --provenance perché l’attestation leghi questo pacchetto a questo repo
Corrispondenza del maintainer npm+0/5
Si ottiene quando la tua identità è verificata qui sopra e quel login è maintainer npm di questo pacchetto
Analisi CVE · non eseguita+0/30
Non ancora analizzato — il pacchetto deve essere su npm
Analisi statica · pulita+0/20
Non ancora analizzato — il pacchetto deve essere su npm
Incollalo in Claude Code, Cursor o qualsiasi assistente di IA per colmare tutte le lacune
StatoIndicizzato dalla community
PublisherNon verificato
FirmaNon firmato
Dominio
Provenienza
DipendenzeNon verificate
Superficie di strumenti
Analisi di sicurezzaNon eseguitaQuanto è efficace questa analisi?
ValutazioniNessuna
Indicizzato13 giu 2026

La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.

Strumenti

Non ancora sondato

Forge non ha completato alcun handshake tools/list verso questo endpoint, quindi non ha alcuna osservazione di ciò che il server espone. Nulla di tutto ciò dice che non esponga nulla.

Descrizione

Official Captapi MCP server. Give Claude, Cursor, VS Code, and any MCP-compatible AI agent direct access to 62 social media data endpoints across YouTube, TikTok, Instagram, and Facebook — transcripts, summaries, comments, channel stats, search, bulk lists, and downloads. One Captapi key works across every platform. The agent calls a tool, Captapi handles proxies, rate limits, retries, and auth, and returns clean JSON. You need a Captapi API key (). Get one at captapi.com/dashboard/api-keys.…

Parole chiave
mcp
Alternative
Confronto delle superfici di strumenti…

Nessuna copertura delle dipendenze

Questo pacchetto non è ancora stato scansionato, quindi non è stato risolto alcun albero delle dipendenze.