# Mutator (remote · mutator.app)

Build and test short-form marketing automations from your agent. Nothing it does can post.

- Trust score: 39/100 (low)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-02

## Components

- remote · `mutator.app`: 39/100 (this document), [markdown](https://verifymcp.io/servers/app-mutator-mutator/mutator.md), [page](https://verifymcp.io/servers/app-mutator-mutator/mutator)

## Channel facts

- Endpoint: `https://mutator.app/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-02.

- **Endpoint Security**: 97/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema blocked by authentication: the endpoint requires auth we don't have to read it.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Tool Safety**: 0/100
  - Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Capabilities**: 0/100
  - Capabilities blocked by authentication: the endpoint requires auth we don't have to read them.

**Unverified: 6 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the Mutator MCP server?

Mutator is a hosted endpoint at https://mutator.app/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http app-mutator-mutator 'https://mutator.app/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "app-mutator-mutator": {
      "url": "https://mutator.app/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "app-mutator-mutator": {
      "type": "http",
      "url": "https://mutator.app/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.app-mutator-mutator]
url = "https://mutator.app/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "app-mutator-mutator": {
      "type": "remote",
      "url": "https://mutator.app/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add app-mutator-mutator --url 'https://mutator.app/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  app-mutator-mutator:
    url: "https://mutator.app/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "app-mutator-mutator": {
      "Transport": "http",
      "Url": "https://mutator.app/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add app-mutator-mutator -t streamable-http -u 'https://mutator.app/mcp'
```

### Other

```json
{
  "mcpServers": {
    "app-mutator-mutator": {
      "type": "http",
      "url": "https://mutator.app/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-02 (score 39, +1)

- [security improvement] Authorization: partial → pass

### 2026-09-28 (score 38, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 38, +2)

- [security regression] Endpoint reachability: reachable → behind authorisation
- [security improvement] Transport: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security improvement] Authorization: fail → pass
- [security] First check of Authorization: partial
- [security] First check of Judged manipulation: pass
- [security] Authorization: Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token.
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Destructive annotations: pass
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 80

### 2026-09-26 (score 36)

First indexed and scored.

## MCP tools (16)

### `mutator_whoami` (~48 tokens)

Check the connection

Confirm the API key works and report which Mutator workspace it reaches and what it may do. Call this first when the connection is new or a later call fails with an authorization error.

### `mutator_list_automations` (~49 tokens)

List automations

List every automation in the workspace with its id, name and status (draft, active or paused). Start here when the user refers to an automation by name and you need its id.

### `mutator_get_automation` (~68 tokens)

Get one automation

Read one automation in detail: status, its schedule if it has one, and its own spending limits. Use it before starting a run to check the automation is active and what a run may cost.

Input parameters:

- `automationId` (string, required): Automation id from mutator_list_automations.

### `mutator_list_runs` (~85 tokens)

List recent runs

List recent runs of one automation, newest first, with status, whether each was a dry run, and what it cost. Use it to answer 'did it work' and 'what did it cost'.

Input parameters:

- `automationId` (string, required): Automation id from mutator_list_automations.
- `limit` (integer): How many runs to return. Defaults to 10.

### `mutator_get_run` (~69 tokens)

Get one run

Read one run with its per-step detail, so a failure can be traced to the step that caused it. Runs are asynchronous: a run still marked running has not finished, so poll rather than assume.

Input parameters:

- `runId` (string, required): Run id, as returned by mutator_start_run.

### `mutator_list_approvals` (~82 tokens)

List what is waiting for approval (nothing, since 20 September 2026)

Always empty. Approvals were removed on 20 September 2026: a run publishes nothing, and a post is made by a person picking a file, an account and a time in Mutator. Tell the person that, rather than reporting an empty queue as if something were wrong. Use mutator_get_run to report what a run made.

### `mutator_get_analytics` (~58 tokens)

Get performance

Read how published content performed over a window of days — the same report the dashboard shows. Use it to answer what worked and to suggest what to run next.

Input parameters:

- `days` (integer): Window in days. Defaults to 30.

### `mutator_get_spend_limits` (~75 tokens)

Get spending limits

Report the workspace's daily and monthly spending ceilings and how much of each is already committed. Generation runs on Mutator's own accounts and is paid for in credits, and the ceilings still apply, so check this before starting anything that generates — a run that would pass a ceiling is refused before any provider is contacted.

### `mutator_start_run` (~227 tokens)

Start a run

Start a run of an automation. Defaults to a DRY RUN, which skips publishing but not generation: it makes the same paid generation calls a real run makes, costs the same credits or provider charges, and counts against the same spend limits. So start one only when the user wants a run, and leave it dry unless they have asked for a real run in this conversation. A real run still publishes nothing on its own: anything it generates goes to the workspace's library, and is posted only when a person schedules it in Mutator. Requires an idempotencyKey; replaying the same value returns the original run instead of starting a second one, so retry with the same key rather than a new one.

Input parameters:

- `automationId` (string, required): Automation id from mutator_list_automations.
- `dryRun` (boolean): Defaults to true. Pass false only when the user has explicitly asked for a real run.
- `idempotencyKey` (string, required): Your own key for this attempt, 8-80 characters. Reuse it verbatim when retrying.

### `mutator_list_brands` (~64 tokens)

List brands

List the brands in the workspace. Every automation belongs to one, so this is the first call when creating anything: mutator_create_automation needs a brandId from here. The brand carries the voice an automation writes in — audience, tone, call to action.

### `mutator_list_connections` (~90 tokens)

List connected accounts

List the accounts and providers this workspace has connected, with the id a publishing step needs. A publish step points at a connection, not at a platform name — there is no 'post to TikTok' field, only 'post to this account, which happens to be TikTok'. Read this before wiring one, because a publish step with no connection is refused at activation rather than saved and forgotten.

### `mutator_list_formats` (~136 tokens)

List content formats

The content formats this product actually knows, and the niches they suit. Use one of these when building — do not invent a format. There is no trend, virality or discovery data anywhere in Mutator: nothing here knows what is performing on any platform this week, and a niche only ORDERS this list, it never filters it. If a user asks for 'viral formats in my niche', these are the formats, ordered by fit, and the word viral is not something this tool can stand behind.

Input parameters:

- `niche` (string): Optional niche id to order the list by fit. Formats that suit no niche still appear.

### `mutator_list_step_types` (~80 tokens)

List the steps an automation can be built from

The complete vocabulary of steps, with the settings each one takes. An automation is a graph of these joined by edges. Read this before building one: the step list is closed, and a graph naming a type that is not here is refused. Most settings have defaults, so a step can usually be sent with an empty config and still run.

### `mutator_create_automation` (~168 tokens)

Create a draft automation

Create a new automation as a DRAFT, optionally with its steps already wired. It is never activated and never runs: a draft has no active version, the scheduler only fires active automations, and nothing here can activate one. The person opens it, reads it, and turns it on. An invalid graph is still saved — the problems come back as `issues` for you to fix and save again, rather than the whole call failing. Report what you built and what is left to decide; do not describe it as live.

Input parameters:

- `brandId` (string, required): From mutator_list_brands.
- `description` (string)
- `graph` (object): Optional. The steps and their connections. Omit to create an empty draft.
- `name` (string, required)

### `mutator_save_automation_graph` (~95 tokens)

Save an automation's steps as a draft

Replace an automation's steps with the ones given, saved as a DRAFT. An active automation keeps running its current version until a person activates the draft, so editing something live is safe. Problems come back as `issues` rather than failing the call — read them and save a corrected graph.

Input parameters:

- `automationId` (string, required): Automation id from mutator_list_automations.
- `graph` (object, required)

### `mutator_set_schedule` (~189 tokens)

Set an automation's schedule

Set when an automation would run, saved switched OFF. Turning a schedule on requires an already-active automation, so this can only ever prepare one — the settings survive until a person activates it. A schedule runs an automation AT MOST ONCE A DAY: it holds a single time, and frequency chooses which days rather than how many times within one. Two posts a day is not a schedule setting: it is one daily run producing two items, with maxPostsPerDay on the publishing step.

Input parameters:

- `automationId` (string, required): Automation id from mutator_list_automations.
- `frequency` (string, required)
- `timeOfDay` (string, required): 24-hour local time, "HH:mm".
- `timezone` (string, required): IANA zone, e.g. "America/New_York".
- `weekdays` (array): ISO weekdays, Monday is 1. Used by weekly and custom.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/app-mutator-mutator/mutator#diagnostics

## Score history

- 2026-10-02: 39
- 2026-10-01: 38
- 2026-09-30: 38
- 2026-09-29: 38
- 2026-09-28: 38
- 2026-09-27: 38
- 2026-09-26: 36

## Common questions

### What is the Mutator MCP server?

Mutator is an MCP server listed in the public MCP registry as app.mutator/mutator. Build and test short-form marketing automations from your agent. Nothing it does can post. This page covers its hosted endpoint (https://mutator.app/mcp).

### Is the Mutator MCP server safe to use?

Mutator scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Mutator MCP server expose?

Mutator exposes 16 tools: mutator_whoami, mutator_list_automations, mutator_get_automation, mutator_list_runs, mutator_get_run, and 11 more. Their descriptions and schemas cost roughly 1,583 tokens of context every time the server is loaded.

### Does the Mutator MCP server require authentication?

Yes. Mutator asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the Mutator MCP server still maintained?

Mutator is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mutator.app/mcp
- Website: https://mutator.app/docs/mcp
- Changelog RSS feed: https://verifymcp.io/servers/app-mutator-mutator/mutator.xml
- Changelog JSON feed: https://verifymcp.io/servers/app-mutator-mutator/mutator.json
- HTML version of this page: https://verifymcp.io/servers/app-mutator-mutator/mutator
