# runsheet-mcp

Runsheet's local MCP server. Uploads videos from your own machine straight to YouTube and schedules them, and forwards the rest of Runsheet's YouTube toolkit to Claude, Cursor or any MCP client.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.2
- **Author:** Kalpesh Mahida
- **License:** MIT
- **npm:** runsheet-mcp
- **Endpoints:** streamable-http https://runsheet.buildifyapp.in/api/mcp
- **Source:** https://github.com/KalpeshMahida0212/runsheet-mcp
- **Endpoint health:** reachable (last checked 2026-09-24T09:57:34.222Z, 1 sample) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 4 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-28T15:22:59.051Z
- **Version scanned:** 1.0.2
- **CVEs:** none found by OSV at scan time

## Tools

3 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `runsheet_upload_video` — Upload a video file from THIS machine to YouTube through Runsheet, and schedule it. The file is read from local disk and streamed straight to YouTube; it is nev
- `runsheet_list_local_videos` — List video files in a folder on THIS machine, with their size, duration and whether each is vertical or landscape. Use this before runsheet_upload_video to see 
- `runsheet-local`

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"runsheet\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"runsheet-mcp\"\n      ],\n      \"env\": {\n        \"RUNSHEET_API_KEY\": \"<YOUR_RUNSHEET_API_KEY>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `RUNSHEET_API_KEY` — Runsheet API Key (required)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 1 credential (1 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Extensive blast radius — mutates data; runs locally and hosted.
- Floor 48, ceiling 48 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/runsheet-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/runsheet-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/runsheet-mcp
- HTML page: https://forgeregistry.com/registry/runsheet-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
