Markaestro
NPM · @MARKAESTRO/MCP · 2 COMPONENTS · SCANNED SEP 28
Schedule, publish, and review social posts and analytics for a Markaestro brand.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 92 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 0 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability85
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 3523 tokens (~100/item across 35 items; 34 tools + 1 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage82
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 47% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 36 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the Markaestro MCP server?
Markaestro runs locally as an npm package, launched with npx -y @markaestro/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @markaestro/mcp
claude mcp add com-markaestro-mcp -- npx -y @markaestro/mcp
{
"mcpServers": {
"com-markaestro-mcp": {
"command": "npx",
"args": [
"-y",
"@markaestro/mcp"
]
}
}
} {
"servers": {
"com-markaestro-mcp": {
"command": "npx",
"args": [
"-y",
"@markaestro/mcp"
]
}
}
} codex mcp add com-markaestro-mcp -- npx -y @markaestro/mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-markaestro-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"@markaestro/mcp"
],
"enabled": true
}
}
} openclaw mcp add com-markaestro-mcp --command npx --arg -y --arg @markaestro/mcp
mcp_servers:
com-markaestro-mcp:
command: "npx"
args: ["-y", "@markaestro/mcp"] {
"McpServers": {
"com-markaestro-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@markaestro/mcp"
]
}
}
} assistant mcp add com-markaestro-mcp -t stdio -c npx -a -y @markaestro/mcp
{
"mcpServers": {
"com-markaestro-mcp": {
"command": "npx",
"args": [
"-y",
"@markaestro/mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +32
- Injection markers: unverified → pass ▲ security
- First check of Judged manipulation: pass security
- Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
- Tool safety: Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. security
- Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
- Security disclosure: unverified → fail ▼ functional
- Tool coverage: unverified → 100 ▲ functional
- MCP protocol: unverified → pass ▲ functional
- Schema quality: unverified → 100 ▲ functional
- First check of Schema quality: pass functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 47 functional
- First check of Destructive annotations: 100 functional
- First check of Schema quality: good functional
- Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
- Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
- Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
- Package version: 0.3.2 → 0.3.3 functional
- 26 Sept 26 0
- Security disclosure: fail → unverified ▼ functional
- 25 Sept 26 +10
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 28
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Analysed npm/@markaestro/mcp@0.3.3
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 92 packages
| Packages resolved | 92 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
activate_evergreen_queue Activate an Evergreen queue ~66
Activate a draft or paused queue. This schedules future public posts. The user must have confirmed the caption variants (contentConfirmed on create_evergreen_queue or update_evergreen_queue); otherwise this answers EVERGREEN_CONTENT_REVIEW_REQUIRED.
| Name | Type | Req | Description |
|---|---|---|---|
| queueId | string | yes | – |
No output schema declared.
No examples provided.
bulk_posts Reschedule or restatus posts ~88
Apply one action to up to 25 posts: reschedule (needs scheduledAt), or status (draft or scheduled). Per-post failures are reported individually. To remove posts, use delete_post on each draft.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| ids | array | yes | – |
| scheduledAt | string | – | Required for reschedule |
| status | string | – | Required for the status action |
No output schema declared.
No examples provided.
create_evergreen_queue Create an Evergreen queue ~225
Create a draft Evergreen queue from an eligible published post. Creation does not activate it or schedule anything; activate_evergreen_queue does that separately.
| Name | Type | Req | Description |
|---|---|---|---|
| channels | array | – | – |
| contentConfirmed | boolean | – | True records that the user has reviewed every caption variant and confirmed the captions are accurate and still true. Activating or resuming a queue requires this confirmation. |
| expiresAt | string | – | ISO 8601 UTC timestamp, for example 2026-09-10T14:00:00Z |
| intervalDays | integer | – | – |
| localHour | integer | – | – |
| localMinute | integer | – | – |
| name | string | yes | – |
| productId | string | – | Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it. |
| reviewPolicy | string | – | – |
| scheduleMode | string | – | – |
| sourcePostId | string | yes | – |
| timeZone | string | – | – |
| variants | array | yes | – |
No output schema declared.
No examples provided.
create_post Create a post ~306
Create a post for this brand. Without scheduledAt the post is saved as a DRAFT and nothing is published; with scheduledAt it is scheduled and the worker publishes it at that time. Pass either a single channel or a targets array (one entry per channel). Upload media first with upload_media and pass the asset ids. Read channel rules with get_channel_rules before posting.
| Name | Type | Req | Description |
|---|---|---|---|
| caption | string | – | Post text. Required on linkedin. |
| channel | string | – | Single channel. Mutually exclusive with targets. |
| deliveryMode | string | – | direct_publish: official platform API. manual_reminder: a timed reminder for a person to post natively (default on facebook, instagram, tiktok). platform_inbox: TikTok inbox handoff. Required when sc… |
| destinationId | string | – | For the single-channel form, when the brand has several destinations on that channel. |
| mediaAssetIds | array | – | Asset ids from upload_media or list_media, in display order. |
| productId | string | – | Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it. |
| scheduledAt | string | – | Omit to save a draft. |
| settings | object | – | Platform settings for the single-channel form; __type must equal channel. |
| targets | array | – | Several channels at once, each with its own destination and delivery mode. |
No output schema declared.
No examples provided.
create_posts Create several posts ~68
Create up to 25 posts in one call, for example a week of scheduled content. Each item takes the same fields as create_post. Failures are per item: the response lists ok/error for each, and the successful ones are created even when others fail.
| Name | Type | Req | Description |
|---|---|---|---|
| posts | array | yes | – |
No output schema declared.
No examples provided.
delete_post Delete a draft or cancel a post ~77
Delete a draft, or cancel a scheduled, failed, or waiting-to-be-posted post before it reaches any platform. Published posts cannot be deleted or taken down from here: that stays with the user in Markaestro. Posts mid-publish cannot be deleted until the run settles.
| Name | Type | Req | Description |
|---|---|---|---|
| postId | string | yes | A Markaestro post id |
No output schema declared.
No examples provided.
get_analytics Get brand analytics ~304
Performance over a window for the connection's brand, or on an all-brands connection for the workspace or the one brand named by productId: totals with the prior period for deltas, per-channel rollups, daily series, engagement breakdown, follower trend, top posts, posting-time heatmap, content-type averages, computed insights, and coverage. Covers the whole account: posts published through Markaestro and posts published directly on the platform (discovered from the connected account); coverage.bySource says how many of each. Read this before recommending what, when, or where to post. The window is clamped to the plan's history (the response reports maxDays). Unavailable provider metrics are null, not zero.
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | – | Restrict every number to one channel |
| days | integer | – | Preset window ending today (UTC); default 28 |
| productId | string | – | One brand, on an all-brands connection; omit for the whole workspace. A single-brand connection always reports its own brand. |
| since | string | – | Explicit range start, YYYY-MM-DD (UTC); needs until |
| source | string | – | Only posts published through Markaestro, or only posts published directly on the platform; omit for the whole account |
| tz | integer | – | Viewer timezone offset in minutes east of UTC; shapes the heatmap only |
| until | string | – | Explicit range end, YYYY-MM-DD (UTC), inclusive |
No output schema declared.
No examples provided.
get_brand_profile Get a brand profile ~57
A brand's description, website, categories, voice, and visual identity as set in Markaestro. Read it before writing captions so they sound like the brand. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| productId | string | yes | Brand id from list_products |
No output schema declared.
No examples provided.
get_channel_rules Channel rules ~39
The per-channel media, caption, and delivery-mode rules the API enforces, plus the draft-then-publish model. Read before creating posts.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_evergreen_analytics Get Evergreen analytics ~50
Get source metrics, queue-lifetime metrics, tracked clicks, attributed conversions, and recent run outcomes. Unavailable provider metrics are null, not zero.
| Name | Type | Req | Description |
|---|---|---|---|
| queueId | string | yes | – |
No output schema declared.
No examples provided.
get_evergreen_queue Get an Evergreen queue ~29
Get one Intelligent Evergreen queue including its caption variants.
| Name | Type | Req | Description |
|---|---|---|---|
| queueId | string | yes | – |
No output schema declared.
No examples provided.
get_job_run Get a publish run ~44
Check the status of a publish run returned by publish_post: queued, running, succeeded, or failed, with the message and details.
| Name | Type | Req | Description |
|---|---|---|---|
| runId | string | yes | – |
No output schema declared.
No examples provided.
get_media Get a media asset ~37
Fetch one media asset: type, dimensions, processing state, thumbnail, and how many posts reference it.
| Name | Type | Req | Description |
|---|---|---|---|
| assetId | string | yes | – |
No output schema declared.
No examples provided.
get_post Get a post ~38
Fetch one post with its targets, status, media, schedule, publish results, and live URL when published.
| Name | Type | Req | Description |
|---|---|---|---|
| postId | string | yes | – |
No output schema declared.
No examples provided.
get_post_analytics_history Get post analytics history ~123
How one post earned its numbers over time: the metric snapshots taken 1h, 6h, 24h, 72h, 7d, 14d, 30d, 60d, and 90d after publish (a post published directly on the platform starts with a discovered snapshot), with the growth between stages, plus the current totals and whether polling is still active. Takes any id from get_analytics or list_post_analytics. Answers NOT_FOUND for posts outside this brand.
| Name | Type | Req | Description |
|---|---|---|---|
| postId | string | yes | – |
No output schema declared.
No examples provided.
get_tiktok_posting_options Get TikTok posting options ~103
The connected TikTok creator's live posting options: allowed privacy levels, whether comments, duets, and stitches can be enabled, and the longest video. TikTok requires a Direct Post to use these, so read them right before building one and pass the chosen privacyLevel in the tiktok settings. Test keys get a sandbox answer.
| Name | Type | Req | Description |
|---|---|---|---|
| productId | string | – | On an all-brands connection, the brand whose TikTok account to ask about |
No output schema declared.
No examples provided.
list_destinations List destinations ~67
List the publishable destinations (Facebook Page, Instagram account, TikTok account, ...) of a brand, with their ids and delivery modes. Use a destinationId on create_post only when a channel has more than one destination.
| Name | Type | Req | Description |
|---|---|---|---|
| productId | string | yes | Brand id from list_products |
No output schema declared.
No examples provided.
list_evergreen_queues List Evergreen queues ~32
List this brand's Intelligent Evergreen queues and their activation evidence, cadence, next run, and status.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_evergreen_runs List Evergreen runs ~30
List the generated occurrences and evaluation outcomes for a queue.
| Name | Type | Req | Description |
|---|---|---|---|
| queueId | string | yes | – |
No output schema declared.
No examples provided.
list_job_runs List publish runs ~59
List recent publish runs, optionally filtered by status or by the post id (resourceId).
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | – |
| limit | integer | – | – |
| resourceId | string | – | A post id |
| status | string | – | – |
No output schema declared.
No examples provided.
list_media List media ~48
List uploaded media assets with their ids, type, dimensions, and how many posts reference them.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | – |
| limit | integer | – | – |
| type | string | – | – |
No output schema declared.
No examples provided.
list_post_analytics List post analytics ~308
Every post in the window (the connection's brand, or on an all-brands connection the workspace or the brand named by productId) with its latest metrics (views, reach, likes, comments, shares, saves, clicks, engagements, engagement rate), one row per post, sorted. Includes posts published directly on the platform; each row's source says markaestro or native (canTakeDown is informational: taking a live post down is done by the user in Markaestro, not by delete_post). Use sort=engagements or sort=views to find what worked; sort=published_at (default) for a chronological read. Pair with get_post for the full caption and media of a Markaestro post (native posts have externalUrl instead).
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | – | – |
| days | integer | – | Preset window ending today (UTC); default 28 |
| limit | integer | – | Default 100 |
| productId | string | – | One brand, on an all-brands connection; omit for the whole workspace. A single-brand connection always reports its own brand. |
| since | string | – | Explicit range start, YYYY-MM-DD (UTC); needs until |
| sort | string | – | Descending; default published_at |
| source | string | – | Only posts published through Markaestro, or only posts published directly on the platform; omit for the whole account |
| until | string | – | Explicit range end, YYYY-MM-DD (UTC), inclusive |
No output schema declared.
No examples provided.
list_posts List posts ~125
List posts, newest first. Filter by status: draft, scheduled, publishing, published, platform_action_required, failed, partial_failed. On an all-brands connection, pass productId to list one brand. Use cursor from a previous page to continue.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | – |
| limit | integer | – | Default 25, max 100 |
| productId | string | – | Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it. |
| status | string | – | – |
No output schema declared.
No examples provided.
list_products List brands ~61
List the brands (products) this connection can act on, with their connected channels: one brand for a single-brand connection, every brand in the workspace for an all-brands one. Call this first to learn each productId and which channels can be posted to.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
mark_post_posted Mark a post as posted ~88
Record that a person has posted a manual-reminder or TikTok-inbox post natively, which moves it from platform_action_required to published. Only for posts in platform_action_required that the user has already posted themselves. Nothing is sent to any platform.
| Name | Type | Req | Description |
|---|---|---|---|
| externalUrl | string | – | Link to the live post, if the user has it |
| postId | string | yes | – |
No output schema declared.
No examples provided.
pause_evergreen_queue Pause an Evergreen queue ~32
Pause a queue and unschedule any pending occurrence generated by it.
| Name | Type | Req | Description |
|---|---|---|---|
| queueId | string | yes | – |
No output schema declared.
No examples provided.
preview_evergreen_queue Preview Evergreen eligibility ~44
Check whether a published post has mature measured performance and get a recommended Evergreen cadence. This does not create or schedule anything.
| Name | Type | Req | Description |
|---|---|---|---|
| sourcePostId | string | yes | – |
No output schema declared.
No examples provided.
publish_post Publish a post now ~73
Queue an immediate publish of a draft post. Returns a job run; poll get_job_run until status is succeeded or failed. For manual_reminder targets this queues a reminder for a person instead of calling the platform. The post goes public on the platform as soon as the run succeeds.
| Name | Type | Req | Description |
|---|---|---|---|
| postId | string | yes | – |
No output schema declared.
No examples provided.
refresh_analytics Refresh analytics from the platforms ~120
Pull live metrics from the platforms now instead of waiting for the next scheduled poll: posts in the window (optionally one channel, or one brand on an all-brands connection) and today's follower counts. The answer says how many posts were updated and how many remain, since a large window may take more than one refresh. Limited to a few calls a minute.
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | – | – |
| days | integer | – | Window ending now; default 28 |
| productId | string | – | One brand, on an all-brands connection |
No output schema declared.
No examples provided.
resume_evergreen_queue Resume an Evergreen queue ~33
Resume a paused queue and compute its next occurrence from the current time.
| Name | Type | Req | Description |
|---|---|---|---|
| queueId | string | yes | – |
No output schema declared.
No examples provided.
suggest_post_times Suggest times to post ~88
When this brand's audience responds best, learned by Markaestro Intelligence from the brand's own post history (not an industry table). timing is null until there is enough history; readiness says how much there is. Use it to pick scheduledAt. Needs a plan with Intelligence.
| Name | Type | Req | Description |
|---|---|---|---|
| productId | string | – | Required on an all-brands connection; a single-brand connection uses its own brand |
No output schema declared.
No examples provided.
update_evergreen_queue Update an Evergreen queue ~175
Update a queue's cadence, review policy, expiry, name, or full caption-variant set. Pass the current version from get_evergreen_queue; a stale version is rejected so concurrent edits are not overwritten.
| Name | Type | Req | Description |
|---|---|---|---|
| contentConfirmed | boolean | – | True records that the user has reviewed every caption variant and confirmed the captions are accurate and still true. Activating or resuming a queue requires this confirmation. |
| expiresAt | – | – | – |
| intervalDays | integer | – | – |
| localHour | integer | – | – |
| localMinute | integer | – | – |
| name | string | – | – |
| queueId | string | yes | – |
| reviewPolicy | string | – | – |
| scheduleMode | string | – | – |
| timeZone | string | – | – |
| variants | array | – | – |
| version | integer | yes | – |
No output schema declared.
No examples provided.
update_post Edit a draft or scheduled post ~170
Change a draft or scheduled post: its caption, its media, one channel's settings (settings.__type names the channel), or, for a scheduled post, its time. Omitted fields stay as they are. Every change is checked against the rules of every channel the post targets, and a scheduled post must still be publishable afterwards. Published and failed posts cannot be edited. Channels are fixed once a post exists; to post somewhere else, create a new post.
| Name | Type | Req | Description |
|---|---|---|---|
| caption | string | – | – |
| mediaAssetIds | array | – | Replaces the post's media, in display order |
| postId | string | yes | – |
| scheduledAt | string | – | New time for a scheduled post |
| settings | object | – | One channel's platform settings, with __type equal to that channel |
No output schema declared.
No examples provided.
upload_media Upload media ~101
Upload an image or video from a local file path, an http(s) URL, or a data: URL. Returns the media asset; pass its id in create_post mediaAssetIds. Counts against the workspace's monthly upload quota.
| Name | Type | Req | Description |
|---|---|---|---|
| contentType | string | – | Inferred from the file extension or URL when omitted |
| fileName | string | – | – |
| source | string | yes | Local file path, http(s) URL, or data: URL |
No output schema declared.
No examples provided.
What is the Markaestro MCP server?
Markaestro is an MCP server listed in the public MCP registry as com.markaestro/mcp. Schedule, publish, and review social posts and analytics for a Markaestro brand. This page covers its npm package (@markaestro/mcp).
Is the Markaestro MCP server safe to use?
Markaestro scores 70 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 28 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Markaestro MCP server expose?
Markaestro exposes 34 tools: list_products, list_destinations, get_brand_profile, list_posts, get_post, and 29 more. Their descriptions and schemas cost roughly 3,308 tokens of context every time the server is loaded.
Is the Markaestro MCP server still maintained?
Markaestro is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Markaestro MCP server under?
Markaestro declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.