Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Markaestro

NPM · @MARKAESTRO/MCP · 2 COMPONENTS · SCANNED SEP 28

Schedule, publish, and review social posts and analytics for a Markaestro brand.

70 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 92 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability85
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 3523 tokens (~100/item across 35 items; 34 tools + 1 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage82
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 47% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 36 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the Markaestro MCP server?

Markaestro runs locally as an npm package, launched with npx -y @markaestro/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @markaestro/mcp

# add to Claude Code
claude mcp add com-markaestro-mcp -- npx -y @markaestro/mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "com-markaestro-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@markaestro/mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-markaestro-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@markaestro/mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add com-markaestro-mcp -- npx -y @markaestro/mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-markaestro-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@markaestro/mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-markaestro-mcp --command npx --arg -y --arg @markaestro/mcp
# ~/.hermes/config.yaml
mcp_servers:
  com-markaestro-mcp:
    command: "npx"
    args: ["-y", "@markaestro/mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-markaestro-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@markaestro/mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add com-markaestro-mcp -t stdio -c npx -a -y @markaestro/mcp
// mcp.json
{
  "mcpServers": {
    "com-markaestro-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@markaestro/mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +32
    • Injection markers: unverified → pass ▲ security
    • First check of Judged manipulation: pass security
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • Tool safety: Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Security disclosure: unverified → fail ▼ functional
    • Tool coverage: unverified → 100 ▲ functional
    • MCP protocol: unverified → pass ▲ functional
    • Schema quality: unverified → 100 ▲ functional
    • First check of Schema quality: pass functional
    • First check of Schema quality: fail functional
    • First check of Tool coverage: 47 functional
    • First check of Destructive annotations: 100 functional
    • First check of Schema quality: good functional
    • Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Package version: 0.3.2 → 0.3.3 functional
  • 26 Sept 26 0
    • Security disclosure: fail → unverified ▼ functional
  • 25 Sept 26 +10
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 28

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 28 Sept 2026 · Analysed npm/@markaestro/mcp@0.3.3

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Dependencies 92 packages
Packages resolved 92
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 34 exposed · ~3,308 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
activate_evergreen_queue ~66

Activate a draft or paused queue. This schedules future public posts. The user must have confirmed the caption variants (contentConfirmed on create_evergreen_queue or update_evergreen_queue); otherwise this answers EVERGREEN_CONTENT_REVIEW_REQUIRED.

NameTypeReqDescription
queueIdstringyes–

No output schema declared.

No examples provided.

bulk_posts ~88

Apply one action to up to 25 posts: reschedule (needs scheduledAt), or status (draft or scheduled). Per-post failures are reported individually. To remove posts, use delete_post on each draft.

NameTypeReqDescription
actionstringyes–
idsarrayyes–
scheduledAtstring–Required for reschedule
statusstring–Required for the status action

No output schema declared.

No examples provided.

create_evergreen_queue ~225

Create a draft Evergreen queue from an eligible published post. Creation does not activate it or schedule anything; activate_evergreen_queue does that separately.

NameTypeReqDescription
channelsarray––
contentConfirmedboolean–True records that the user has reviewed every caption variant and confirmed the captions are accurate and still true. Activating or resuming a queue requires this confirmation.
expiresAtstring–ISO 8601 UTC timestamp, for example 2026-09-10T14:00:00Z
intervalDaysinteger––
localHourinteger––
localMinuteinteger––
namestringyes–
productIdstring–Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it.
reviewPolicystring––
scheduleModestring––
sourcePostIdstringyes–
timeZonestring––
variantsarrayyes–

No output schema declared.

No examples provided.

create_post ~306

Create a post for this brand. Without scheduledAt the post is saved as a DRAFT and nothing is published; with scheduledAt it is scheduled and the worker publishes it at that time. Pass either a single channel or a targets array (one entry per channel). Upload media first with upload_media and pass the asset ids. Read channel rules with get_channel_rules before posting.

NameTypeReqDescription
captionstring–Post text. Required on linkedin.
channelstring–Single channel. Mutually exclusive with targets.
deliveryModestring–direct_publish: official platform API. manual_reminder: a timed reminder for a person to post natively (default on facebook, instagram, tiktok). platform_inbox: TikTok inbox handoff. Required when sc…
destinationIdstring–For the single-channel form, when the brand has several destinations on that channel.
mediaAssetIdsarray–Asset ids from upload_media or list_media, in display order.
productIdstring–Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it.
scheduledAtstring–Omit to save a draft.
settingsobject–Platform settings for the single-channel form; __type must equal channel.
targetsarray–Several channels at once, each with its own destination and delivery mode.

No output schema declared.

No examples provided.

create_posts ~68

Create up to 25 posts in one call, for example a week of scheduled content. Each item takes the same fields as create_post. Failures are per item: the response lists ok/error for each, and the successful ones are created even when others fail.

NameTypeReqDescription
postsarrayyes–

No output schema declared.

No examples provided.

delete_post ~77

Delete a draft, or cancel a scheduled, failed, or waiting-to-be-posted post before it reaches any platform. Published posts cannot be deleted or taken down from here: that stays with the user in Markaestro. Posts mid-publish cannot be deleted until the run settles.

NameTypeReqDescription
postIdstringyesA Markaestro post id

No output schema declared.

No examples provided.

get_analytics ~304

Performance over a window for the connection's brand, or on an all-brands connection for the workspace or the one brand named by productId: totals with the prior period for deltas, per-channel rollups, daily series, engagement breakdown, follower trend, top posts, posting-time heatmap, content-type averages, computed insights, and coverage. Covers the whole account: posts published through Markaestro and posts published directly on the platform (discovered from the connected account); coverage.bySource says how many of each. Read this before recommending what, when, or where to post. The window is clamped to the plan's history (the response reports maxDays). Unavailable provider metrics are null, not zero.

NameTypeReqDescription
channelstring–Restrict every number to one channel
daysinteger–Preset window ending today (UTC); default 28
productIdstring–One brand, on an all-brands connection; omit for the whole workspace. A single-brand connection always reports its own brand.
sincestring–Explicit range start, YYYY-MM-DD (UTC); needs until
sourcestring–Only posts published through Markaestro, or only posts published directly on the platform; omit for the whole account
tzinteger–Viewer timezone offset in minutes east of UTC; shapes the heatmap only
untilstring–Explicit range end, YYYY-MM-DD (UTC), inclusive

No output schema declared.

No examples provided.

get_brand_profile ~57

A brand's description, website, categories, voice, and visual identity as set in Markaestro. Read it before writing captions so they sound like the brand. Read-only.

NameTypeReqDescription
productIdstringyesBrand id from list_products

No output schema declared.

No examples provided.

get_channel_rules ~39

The per-channel media, caption, and delivery-mode rules the API enforces, plus the draft-then-publish model. Read before creating posts.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_evergreen_analytics ~50

Get source metrics, queue-lifetime metrics, tracked clicks, attributed conversions, and recent run outcomes. Unavailable provider metrics are null, not zero.

NameTypeReqDescription
queueIdstringyes–

No output schema declared.

No examples provided.

get_evergreen_queue ~29

Get one Intelligent Evergreen queue including its caption variants.

NameTypeReqDescription
queueIdstringyes–

No output schema declared.

No examples provided.

get_job_run ~44

Check the status of a publish run returned by publish_post: queued, running, succeeded, or failed, with the message and details.

NameTypeReqDescription
runIdstringyes–

No output schema declared.

No examples provided.

get_media ~37

Fetch one media asset: type, dimensions, processing state, thumbnail, and how many posts reference it.

NameTypeReqDescription
assetIdstringyes–

No output schema declared.

No examples provided.

get_post ~38

Fetch one post with its targets, status, media, schedule, publish results, and live URL when published.

NameTypeReqDescription
postIdstringyes–

No output schema declared.

No examples provided.

get_post_analytics_history ~123

How one post earned its numbers over time: the metric snapshots taken 1h, 6h, 24h, 72h, 7d, 14d, 30d, 60d, and 90d after publish (a post published directly on the platform starts with a discovered snapshot), with the growth between stages, plus the current totals and whether polling is still active. Takes any id from get_analytics or list_post_analytics. Answers NOT_FOUND for posts outside this brand.

NameTypeReqDescription
postIdstringyes–

No output schema declared.

No examples provided.

get_tiktok_posting_options ~103

The connected TikTok creator's live posting options: allowed privacy levels, whether comments, duets, and stitches can be enabled, and the longest video. TikTok requires a Direct Post to use these, so read them right before building one and pass the chosen privacyLevel in the tiktok settings. Test keys get a sandbox answer.

NameTypeReqDescription
productIdstring–On an all-brands connection, the brand whose TikTok account to ask about

No output schema declared.

No examples provided.

list_destinations ~67

List the publishable destinations (Facebook Page, Instagram account, TikTok account, ...) of a brand, with their ids and delivery modes. Use a destinationId on create_post only when a channel has more than one destination.

NameTypeReqDescription
productIdstringyesBrand id from list_products

No output schema declared.

No examples provided.

list_evergreen_queues ~32

List this brand's Intelligent Evergreen queues and their activation evidence, cadence, next run, and status.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_evergreen_runs ~30

List the generated occurrences and evaluation outcomes for a queue.

NameTypeReqDescription
queueIdstringyes–

No output schema declared.

No examples provided.

list_job_runs ~59

List recent publish runs, optionally filtered by status or by the post id (resourceId).

NameTypeReqDescription
cursorstring––
limitinteger––
resourceIdstring–A post id
statusstring––

No output schema declared.

No examples provided.

list_media ~48

List uploaded media assets with their ids, type, dimensions, and how many posts reference them.

NameTypeReqDescription
cursorstring––
limitinteger––
typestring––

No output schema declared.

No examples provided.

list_post_analytics ~308

Every post in the window (the connection's brand, or on an all-brands connection the workspace or the brand named by productId) with its latest metrics (views, reach, likes, comments, shares, saves, clicks, engagements, engagement rate), one row per post, sorted. Includes posts published directly on the platform; each row's source says markaestro or native (canTakeDown is informational: taking a live post down is done by the user in Markaestro, not by delete_post). Use sort=engagements or sort=views to find what worked; sort=published_at (default) for a chronological read. Pair with get_post for the full caption and media of a Markaestro post (native posts have externalUrl instead).

NameTypeReqDescription
channelstring––
daysinteger–Preset window ending today (UTC); default 28
limitinteger–Default 100
productIdstring–One brand, on an all-brands connection; omit for the whole workspace. A single-brand connection always reports its own brand.
sincestring–Explicit range start, YYYY-MM-DD (UTC); needs until
sortstring–Descending; default published_at
sourcestring–Only posts published through Markaestro, or only posts published directly on the platform; omit for the whole account
untilstring–Explicit range end, YYYY-MM-DD (UTC), inclusive

No output schema declared.

No examples provided.

list_posts ~125

List posts, newest first. Filter by status: draft, scheduled, publishing, published, platform_action_required, failed, partial_failed. On an all-brands connection, pass productId to list one brand. Use cursor from a previous page to continue.

NameTypeReqDescription
cursorstring––
limitinteger–Default 25, max 100
productIdstring–Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it.
statusstring––

No output schema declared.

No examples provided.

list_products ~61

List the brands (products) this connection can act on, with their connected channels: one brand for a single-brand connection, every brand in the workspace for an all-brands one. Call this first to learn each productId and which channels can be posted to.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

mark_post_posted ~88

Record that a person has posted a manual-reminder or TikTok-inbox post natively, which moves it from platform_action_required to published. Only for posts in platform_action_required that the user has already posted themselves. Nothing is sent to any platform.

NameTypeReqDescription
externalUrlstring–Link to the live post, if the user has it
postIdstringyes–

No output schema declared.

No examples provided.

pause_evergreen_queue ~32

Pause a queue and unschedule any pending occurrence generated by it.

NameTypeReqDescription
queueIdstringyes–

No output schema declared.

No examples provided.

preview_evergreen_queue ~44

Check whether a published post has mature measured performance and get a recommended Evergreen cadence. This does not create or schedule anything.

NameTypeReqDescription
sourcePostIdstringyes–

No output schema declared.

No examples provided.

publish_post ~73

Queue an immediate publish of a draft post. Returns a job run; poll get_job_run until status is succeeded or failed. For manual_reminder targets this queues a reminder for a person instead of calling the platform. The post goes public on the platform as soon as the run succeeds.

NameTypeReqDescription
postIdstringyes–

No output schema declared.

No examples provided.

refresh_analytics ~120

Pull live metrics from the platforms now instead of waiting for the next scheduled poll: posts in the window (optionally one channel, or one brand on an all-brands connection) and today's follower counts. The answer says how many posts were updated and how many remain, since a large window may take more than one refresh. Limited to a few calls a minute.

NameTypeReqDescription
channelstring––
daysinteger–Window ending now; default 28
productIdstring–One brand, on an all-brands connection

No output schema declared.

No examples provided.

resume_evergreen_queue ~33

Resume a paused queue and compute its next occurrence from the current time.

NameTypeReqDescription
queueIdstringyes–

No output schema declared.

No examples provided.

suggest_post_times ~88

When this brand's audience responds best, learned by Markaestro Intelligence from the brand's own post history (not an industry table). timing is null until there is enough history; readiness says how much there is. Use it to pick scheduledAt. Needs a plan with Intelligence.

NameTypeReqDescription
productIdstring–Required on an all-brands connection; a single-brand connection uses its own brand

No output schema declared.

No examples provided.

update_evergreen_queue ~175

Update a queue's cadence, review policy, expiry, name, or full caption-variant set. Pass the current version from get_evergreen_queue; a stale version is rejected so concurrent edits are not overwritten.

NameTypeReqDescription
contentConfirmedboolean–True records that the user has reviewed every caption variant and confirmed the captions are accurate and still true. Activating or resuming a queue requires this confirmation.
expiresAt–––
intervalDaysinteger––
localHourinteger––
localMinuteinteger––
namestring––
queueIdstringyes–
reviewPolicystring––
scheduleModestring––
timeZonestring––
variantsarray––
versionintegeryes–

No output schema declared.

No examples provided.

update_post ~170

Change a draft or scheduled post: its caption, its media, one channel's settings (settings.__type names the channel), or, for a scheduled post, its time. Omitted fields stay as they are. Every change is checked against the rules of every channel the post targets, and a scheduled post must still be publishable afterwards. Published and failed posts cannot be edited. Channels are fixed once a post exists; to post somewhere else, create a new post.

NameTypeReqDescription
captionstring––
mediaAssetIdsarray–Replaces the post's media, in display order
postIdstringyes–
scheduledAtstring–New time for a scheduled post
settingsobject–One channel's platform settings, with __type equal to that channel

No output schema declared.

No examples provided.

upload_media ~101

Upload an image or video from a local file path, an http(s) URL, or a data: URL. Returns the media asset; pass its id in create_post mediaAssetIds. Counts against the workspace's monthly upload quota.

NameTypeReqDescription
contentTypestring–Inferred from the file extension or URL when omitted
fileNamestring––
sourcestringyesLocal file path, http(s) URL, or data: URL

No output schema declared.

No examples provided.

Common questions

What is the Markaestro MCP server?

Markaestro is an MCP server listed in the public MCP registry as com.markaestro/mcp. Schedule, publish, and review social posts and analytics for a Markaestro brand. This page covers its npm package (@markaestro/mcp).

Is the Markaestro MCP server safe to use?

Markaestro scores 70 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 28 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Markaestro MCP server expose?

Markaestro exposes 34 tools: list_products, list_destinations, get_brand_profile, list_posts, get_post, and 29 more. Their descriptions and schemas cost roughly 3,308 tokens of context every time the server is loaded.

Is the Markaestro MCP server still maintained?

Markaestro is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the Markaestro MCP server under?

Markaestro declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.