XTapDown
NPM · XTAPDOWN-MCP · SCANNED SEP 20
14 X (Twitter) creator tools — tweet download, hashtags, hooks, engagement & ads-revenue calc.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 96 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 86 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability81
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1451 tokens (~103/item across 14 items; 14 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management93
- Stability observed for 28 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 14 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 14 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the XTapDown MCP server?
XTapDown runs locally as an npm package, launched with npx -y xtapdown-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · xtapdown-mcp
claude mcp add farukkolip-xtapdown-mcp -- npx -y xtapdown-mcp
{
"mcpServers": {
"farukkolip-xtapdown-mcp": {
"command": "npx",
"args": [
"-y",
"xtapdown-mcp"
]
}
}
} {
"servers": {
"farukkolip-xtapdown-mcp": {
"command": "npx",
"args": [
"-y",
"xtapdown-mcp"
]
}
}
} codex mcp add farukkolip-xtapdown-mcp -- npx -y xtapdown-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"farukkolip-xtapdown-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"xtapdown-mcp"
],
"enabled": true
}
}
} openclaw mcp add farukkolip-xtapdown-mcp --command npx --arg -y --arg xtapdown-mcp
mcp_servers:
farukkolip-xtapdown-mcp:
command: "npx"
args: ["-y", "xtapdown-mcp"] {
"McpServers": {
"farukkolip-xtapdown-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"xtapdown-mcp"
]
}
}
} assistant mcp add farukkolip-xtapdown-mcp -t stdio -c npx -a -y xtapdown-mcp
{
"mcpServers": {
"farukkolip-xtapdown-mcp": {
"command": "npx",
"args": [
"-y",
"xtapdown-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 −3
- Stability: pass → 0.80 functional
- 15 Sept 26 0
- Stability: 0.97 → pass security
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
- Security disclosure: unverified → fail ▼ functional
- 9 Sept 26 −3
- Stability: pass → 0.80 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/xtapdown-mcp@1.2.1
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 96 packages
| Packages resolved | 96 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
build_x_search_url ~303
Build an X (Twitter) advanced search URL from structured filters. Returns a clickable URL using X's official advanced search operators (from:, since:, until:, min_faves:, lang:, filter:media etc).
| Name | Type | Req | Description |
|---|---|---|---|
| excludeReplies | boolean | – | -filter:replies — exclude replies |
| excludeRetweets | boolean | – | -filter:retweets — exclude reposts |
| from | string | – | Posts from a specific username (no @) |
| lang | string | – | ISO 639-1 language code (e.g. 'en', 'es', 'tr') |
| mediaFilter | string | – | Media type filter |
| mentions | string | – | Posts mentioning a username (no @) |
| minBookmarks | integer | – | Minimum bookmarks (the strongest save signal in 2026) |
| minFaves | integer | – | Minimum likes |
| minReplies | integer | – | Minimum replies |
| minRetweets | integer | – | Minimum reposts |
| query | string | – | Free-text keywords (e.g. 'AI agents') |
| sinceDate | string | – | YYYY-MM-DD lower bound (inclusive) |
| sortMode | string | – | 'top' (relevance) or 'live' (recent) |
| to | string | – | Posts replying to a specific username (no @) |
| untilDate | string | – | YYYY-MM-DD upper bound (inclusive) |
| verifiedOnly | boolean | – | filter:verified — verified accounts only |
No output schema declared.
No examples provided.
calculate_x_ads_revenue ~148
Estimate monthly X Premium Creator Ads Revenue Share payout from impressions. X pays creators based on ads shown in REPLIES to their posts, not the posts themselves — so reply density is the lever. Requires X Premium + 500 verified followers + 25M impressions over the trailing 3 months for eligibility.
| Name | Type | Req | Description |
|---|---|---|---|
| avgRepliesPerPost | number | – | Average replies per post (drives ad inventory in replies — default 20) |
| cpmEstimate | number | – | Estimated CPM in USD for reply ads (industry estimate $1.50-$4 — default $2.50) |
| monthlyImpressions | integer | yes | Total impressions on your posts in the past 30 days |
No output schema declared.
No examples provided.
calculate_x_engagement_rate ~161
Calculate X (Twitter) engagement rate using the public follower-based formula: (likes + reposts + replies + bookmarks + quotes) / followers × 100. Returns the percentage and the tier-aware benchmark band (Excellent / Good / Average / Low / Inactive).
| Name | Type | Req | Description |
|---|---|---|---|
| bookmarks | integer | – | Bookmarks (optional, default 0) |
| followers | integer | yes | Account follower count |
| likes | integer | yes | Likes on the post (or sum across posts) |
| posts | integer | – | Number of posts the engagement is summed over (default 1) |
| quotes | integer | – | Quote tweets (optional, default 0) |
| replies | integer | yes | Reply count |
| reposts | integer | yes | Reposts / retweets |
No output schema declared.
No examples provided.
count_tweet_characters ~83
Count tweet characters using X's official weighted-length formula. CJK ideographs, fullwidth chars, and most emoji count as 2; URLs always count as 23 (t.co shortening). Returns char count, remaining budget for free + Premium limits, and a warning if a thread split is needed.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | Tweet text to measure |
No output schema declared.
No examples provided.
download_tweet ~79
Download an X (Twitter) post — video, GIF, images, or article. Returns direct media URLs, author info, and engagement stats. Uses the public X syndication endpoint, no auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | X / Twitter post URL (e.g. https://x.com/user/status/12345 or twitter.com equivalent) |
No output schema declared.
No examples provided.
find_viral_tweets_for_niche ~65
Get the top X (Twitter) creators in a niche plus 3 viral tweet templates with explanations of why each one works. Pulls from XTapDown's curated viral pattern library.
| Name | Type | Req | Description |
|---|---|---|---|
| niche | string | yes | Niche to surface viral patterns for |
No output schema declared.
No examples provided.
generate_fancy_unicode_text ~71
Convert plain ASCII text into a fancy Unicode style suitable for X bios and tweets. 7 styles supported: bold, italic, boldItalic, monospace, script, doubleStruck, smallCaps.
| Name | Type | Req | Description |
|---|---|---|---|
| style | string | yes | Style preset |
| text | string | yes | ASCII text to transform |
No output schema declared.
No examples provided.
generate_tweet_hook ~82
Generate proven tweet hook formulas for a category. Returns 3 ready-to-use templates with examples and execution tips. Hooks must land in line one because the rest of the post is hidden until tap.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | Hook category |
| topic | string | – | Optional topic (e.g. 'AI agents', 'crypto') to customize the examples |
No output schema declared.
No examples provided.
get_best_time_to_post_x ~68
Get the best times to post on X (Twitter) for a country, with day-by-day windows and the reasoning behind each slot. X engagement curves differ from TikTok — weighted toward morning commute, lunch, and evening news windows.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | yes | Country code |
No output schema declared.
No examples provided.
get_tweet_screenshot_url ~99
Generate a deep-link to XTapDown's tweet screenshot tool with the tweet URL and styling pre-filled. The PNG/JPG rendering happens client-side in the browser — this tool returns a ready-to-open URL plus a checklist of available styles.
| Name | Type | Req | Description |
|---|---|---|---|
| background | string | – | Decorative background preset |
| theme | string | – | Native X theme to render against |
| tweetUrl | string | yes | X (Twitter) post URL to screenshot |
No output schema declared.
No examples provided.
get_x_hashtags ~64
Get curated X (Twitter) hashtags for a niche, plus 3 strategy tips on how to use them. Hashtag rules on X differ sharply from TikTok or Instagram — max 1-3 tags per post.
| Name | Type | Req | Description |
|---|---|---|---|
| niche | string | yes | Niche label |
No output schema declared.
No examples provided.
get_x_search_operators_cheatsheet ~65
Return the complete X (Twitter) advanced search operators reference, grouped by category, with syntax / example / description for each operator. Updated for 2026.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Filter by category — or 'all' for the full sheet |
No output schema declared.
No examples provided.
get_x_trends ~76
Get the current top trending topics on X (Twitter) for a country. Live data refreshed roughly hourly by the XTapDown trends collector.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | yes | Country code (ISO 3166-1 alpha-2) |
| limit | integer | – | Max trends to return (1-50, default 20) |
No output schema declared.
No examples provided.
split_long_text_into_thread ~87
Split a long text into a numbered tweet thread (each tweet ≤ 280 chars). Uses X's weighted-length formula and t.co URL shortening (URLs always count as 23). Prefers sentence boundaries, then paragraph, then word.
| Name | Type | Req | Description |
|---|---|---|---|
| numbered | boolean | – | Append ' i/N' numbering to each tweet |
| text | string | yes | Long text to thread-split |
No output schema declared.
No examples provided.
What is the XTapDown MCP server?
XTapDown is an MCP server listed in the public MCP registry as io.github.farukkolip/xtapdown-mcp. 14 X (Twitter) creator tools, tweet download, hashtags, hooks, engagement & ads-revenue calc. This page covers its npm package (xtapdown-mcp).
Is the XTapDown MCP server safe to use?
XTapDown scores 84 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the XTapDown MCP server expose?
XTapDown exposes 14 tools: download_tweet, get_x_hashtags, get_best_time_to_post_x, generate_tweet_hook, calculate_x_engagement_rate, and 9 more. Their descriptions and schemas cost roughly 1,451 tokens of context every time the server is loaded.
Is the XTapDown MCP server still maintained?
XTapDown is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the XTapDown MCP server under?
XTapDown declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.