Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Hermoso

NPM · HERMOSO · 2 COMPONENTS · SCANNED SEP 20

Marketing on autopilot from your agent. 841 tools, usable alone. Publishing and ads cost no credits.

0 this week 42 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 95 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability0
  • Schema quality not yet verified: the captured schema was too large for us to store in full, so we will not judge it on a partial copy.Unverified
Stability & Change Management0
  • Stability not yet verified: the captured schema was too large for us to store in full, and comparing a partial copy would report our own trimming as a change.Unverified
Tool Coverage0
  • Tool coverage not yet verified: the captured tool definitions were too large for us to store in full, so we will not judge them on a partial copy.Unverified
Tool Safety0
  • Tool safety not yet verified: the captured tool definitions were too large for us to store in full, and the trim removes the very descriptions this category reads.Unverified
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
  • Supports UI / widget rendering.Pass

Unverified: 4 categories

Categories scored 0 because our sandbox run of this package has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →

Install

How do I install the Hermoso MCP server?

Hermoso runs locally as an npm package, launched with npx -y hermoso. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · hermoso

# add to Claude Code
claude mcp add hermoso-ai-hermoso -- npx -y hermoso
// .cursor/mcp.json
{
  "mcpServers": {
    "hermoso-ai-hermoso": {
      "command": "npx",
      "args": [
        "-y",
        "hermoso"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "hermoso-ai-hermoso": {
      "command": "npx",
      "args": [
        "-y",
        "hermoso"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add hermoso-ai-hermoso -- npx -y hermoso
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "hermoso-ai-hermoso": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "hermoso"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add hermoso-ai-hermoso --command npx --arg -y --arg hermoso
# ~/.hermes/config.yaml
mcp_servers:
  hermoso-ai-hermoso:
    command: "npx"
    args: ["-y", "hermoso"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "hermoso-ai-hermoso": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "hermoso"
      ]
    }
  }
}
# add to Vellum
assistant mcp add hermoso-ai-hermoso -t stdio -c npx -a -y hermoso
// mcp.json
{
  "mcpServers": {
    "hermoso-ai-hermoso": {
      "command": "npx",
      "args": [
        "-y",
        "hermoso"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 19 Sept 26 +25
    • Known CVEs: unverified → pass security
    • Malware scan: unverified → pass security
    • Dependency health: unverified → 0.84 functional
  • 18 Sept 26 −15
    • Malware scan: pass → unverified security
    • Known CVEs: unverified → pass security
    • Dependency health: unverified → 0.84 functional
    • Package version: 0.1.252 → 0.1.256 functional
    • Package version: 0.1.252 → 0.1.254 functional
  • 17 Sept 26 −10
    • Known CVEs: pass → unverified security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Tool safety: Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. security
    • Dependency health: 0.84 → unverified functional
    • Capabilities: pass → unverified functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Package version: 0.1.249 → 0.1.252 functional
    • Package version: 0.1.249 → 0.1.251 functional
    • Package version: 0.1.249 → 0.1.250 functional
  • 16 Sept 26 +15
    • Malware scan: unverified → pass security
  • 15 Sept 26 0
    • Known CVEs: pass → unverified security
    • Malware scan: unverified → pass security
    • Dependency health: 0.84 → unverified functional
    • Package version: 0.1.242 → 0.1.249 functional
    • Package version: 0.1.242 → 0.1.248 functional
    • Package version: 0.1.242 → 0.1.247 functional
    • Package version: 0.1.242 → 0.1.244 functional
    • Package version: 0.1.242 → 0.1.243 functional
  • 14 Sept 26 −15
    • Malware scan: pass → unverified security
    • Package version: 0.1.239 → 0.1.242 functional
    • Package version: 0.1.239 → 0.1.241 functional
  • 13 Sept 26 +15
    • Known CVEs: pass → unverified security
    • Malware scan: unverified → pass security
    • Dependency health: 0.84 → unverified functional
    • Package version: 0.1.230 → 0.1.239 functional
    • Package version: 0.1.230 → 0.1.238 functional
    • Package version: 0.1.230 → 0.1.237 functional
    • Package version: 0.1.230 → 0.1.236 functional
    • Package version: 0.1.230 → 0.1.234 functional
    • Package version: 0.1.230 → 0.1.233 functional
    • Package version: 0.1.230 → 0.1.231 functional
  • 12 Sept 26 +10
    • Known CVEs: unverified → pass security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Tool safety: Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. security
    • Capabilities: pass → unverified functional
    • Dependency health: unverified → 0.84 functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Package version: 0.1.225 → 0.1.230 functional
    • Package version: 0.1.225 → 0.1.229 functional
    • Package version: 0.1.225 → 0.1.228 functional
    • Package version: 0.1.225 → 0.1.227 functional
    • Package version: 0.1.225 → 0.1.226 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Analysed npm/hermoso@0.1.256

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Dependencies 95 packages
Packages resolved 95
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 175 exposed · ~66,083 tokens partial

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
add_subtitles ~194

No description provided.

NameTypeReqDescription
burnboolean
textStyle
videostringyes

No output schema declared.

No examples provided.

analyze_video ~86

No description provided.

NameTypeReqDescription
urlstringyes

No output schema declared.

No examples provided.

append_to_doc ~88

No description provided.

NameTypeReqDescription
documentIdstringyes
textstringyes

No output schema declared.

No examples provided.

append_to_sheet ~109

No description provided.

NameTypeReqDescription
rangestring
rowsarrayyes
spreadsheetIdstringyes

No output schema declared.

No examples provided.

backfill_posts ~352

No description provided.

NameTypeReqDescription
accountRefstring
channelstringyes
confirmboolean
cursorstring
limitnumber

No output schema declared.

No examples provided.

billing_status ~165

No description provided.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

buy_credits ~408

No description provided.

NameTypeReqDescription
confirmboolean
packstring
quote_tokenstring

No output schema declared.

No examples provided.

call_tool ~217

No description provided.

NameTypeReqDescription
argsobject
namestringyes

No output schema declared.

No examples provided.

cancel_scheduled ~144

No description provided.

NameTypeReqDescription
brandstring
idstringyes

No output schema declared.

No examples provided.

change_voice ~141

No description provided.

NameTypeReqDescription
videostringyes
voicestring

No output schema declared.

No examples provided.

check_ad_policy ~199

No description provided.

NameTypeReqDescription
categorystring
claimsstring
copystringyes
imageDescriptionstring

No output schema declared.

No examples provided.

clear_sheet_range ~223

No description provided.

NameTypeReqDescription
confirmboolean
confirmCellsnumber
rangestringyes
sheetUrlstring
spreadsheetIdstring

No output schema declared.

No examples provided.

clip_video ~760

No description provided.

NameTypeReqDescription
aspectRatiostring
captionsboolean
countnumber
videostringyes

No output schema declared.

No examples provided.

clone_static ~171

No description provided.

NameTypeReqDescription
brandIdstring
imageUrlstringyes

No output schema declared.

No examples provided.

clone_video ~381

No description provided.

NameTypeReqDescription
brand
changesstring
durationSecondsnumber
languagestring
productstring
urlstringyes

No output schema declared.

No examples provided.

collect_post_metrics ~260

No description provided.

NameTypeReqDescription
includeMeteredboolean
maxnumber
remeasureboolean

No output schema declared.

No examples provided.

competitor_teardown ~217

No description provided.

NameTypeReqDescription
adsarray
competitorobjectyes
languagestring

No output schema declared.

No examples provided.

connect_connector ~460

No description provided.

NameTypeReqDescription
fieldsobject
providerstringyes

No output schema declared.

No examples provided.

convert_onedrive_file ~308

No description provided.

NameTypeReqDescription
fileIdstringyes
formatstring
heightnumber
widthnumber

No output schema declared.

No examples provided.

create_brand ~157

No description provided.

NameTypeReqDescription
activateboolean
namestringyes

No output schema declared.

No examples provided.

create_doc ~92

No description provided.

NameTypeReqDescription
textstring
titlestring

No output schema declared.

No examples provided.

create_drive_folder ~138

No description provided.

NameTypeReqDescription
namestringyes
parentIdstring

No output schema declared.

No examples provided.

create_onedrive_folder ~118

No description provided.

NameTypeReqDescription
namestringyes
parentIdstring

No output schema declared.

No examples provided.

create_sheet ~114

No description provided.

NameTypeReqDescription
rowsarray
titlestring

No output schema declared.

No examples provided.

delete_brand ~310

No description provided.

NameTypeReqDescription
brandstringyes
confirmboolean
confirmConnectorsnumber
confirmNamestring

No output schema declared.

No examples provided.

delete_creator ~92

No description provided.

NameTypeReqDescription
idstringyes

No output schema declared.

No examples provided.

delete_drive_file ~96

No description provided.

NameTypeReqDescription
confirmboolean
fileIdstringyes
permanentboolean

No output schema declared.

No examples provided.

delete_linkedin_lead_subscription ~108

No description provided.

NameTypeReqDescription
adAccountIdstring
pageIdstring
subscriptionIdstringyes

No output schema declared.

No examples provided.

delete_onedrive_file ~76

No description provided.

NameTypeReqDescription
confirmboolean
fileIdstringyes

No output schema declared.

No examples provided.

delete_playbook ~65

No description provided.

NameTypeReqDescription
idstringyes

No output schema declared.

No examples provided.

delete_skill ~61

No description provided.

NameTypeReqDescription
idstringyes

No output schema declared.

No examples provided.

diagnose_posts ~498

No description provided.

NameTypeReqDescription
channelstring
convertingboolean
limitnumber

No output schema declared.

No examples provided.

disconnect_connector ~332

No description provided.

NameTypeReqDescription
accountstring
confirmboolean
providerstringyes

No output schema declared.

No examples provided.

draft_brand ~268

No description provided.

NameTypeReqDescription
descriptionstring
domainstring
platformstring
saveboolean
socialHandlestring

No output schema declared.

No examples provided.

dub_video ~216

No description provided.

NameTypeReqDescription
languagestringyes
scriptstring
videostringyes
voicestring

No output schema declared.

No examples provided.

duplicate_scheduled ~551

No description provided.

NameTypeReqDescription
atstring
boardIdstring
brandstring
captionsobject
channelsarray
chatIdstring
idstringyes
imageUrlstring
imageUrlsarray
linkstring
linkedinOrganizationIdstring
locationIdstring
messagestring
pageIdstring
timezonestring
titlestring
useQueueboolean
videoUrlstring
visibilitystring

No output schema declared.

No examples provided.

edit_video ~353

No description provided.

NameTypeReqDescription
elementsarray
instructionstringyes
interactionIdstring
keepAudioboolean
videostringyes

No output schema declared.

No examples provided.

enable_tools ~427

No description provided.

NameTypeReqDescription
groupsarrayyes

No output schema declared.

No examples provided.

error_detail ~80

No description provided.

NameTypeReqDescription
fingerprintstringyes

No output schema declared.

No examples provided.

export_swipefile_deck ~249

No description provided.

NameTypeReqDescription
collectionstring
limitnumber
titlestring

No output schema declared.

No examples provided.

fetch_app_screens ~200

No description provided.

NameTypeReqDescription
appNamestring
brandIdstring

No output schema declared.

No examples provided.

fetch_asset ~62

No description provided.

NameTypeReqDescription
namestring
urlstringyes

No output schema declared.

No examples provided.

fetch_social_data ~220

No description provided.

NameTypeReqDescription
paramsobject
pathstringyes

No output schema declared.

No examples provided.

find_competitors ~108

No description provided.

NameTypeReqDescription
domainstringyes
modestring

No output schema declared.

No examples provided.

find_creators ~333

No description provided.

NameTypeReqDescription
enrichboolean
limitnumber
minAvgViewsnumber
minEngagementnumber
nichestringyes
platformsarray
queriesnumber

No output schema declared.

No examples provided.

find_tools ~334

No description provided.

NameTypeReqDescription
groupstring
limitnumber
onlyHealthyboolean
querystring

No output schema declared.

No examples provided.

finish_video ~289

No description provided.

NameTypeReqDescription
accentstring
grainboolean
headerstring
pillsboolean
pointsarray
substring
videoUrlstringyes

No output schema declared.

No examples provided.

fix_beat ~235

No description provided.

NameTypeReqDescription
endSecondsnumberyes
promptstringyes
refImagestring
speechWindowsarray
startSecondsnumberyes
videoUrlstringyes

No output schema declared.

No examples provided.

forget ~64

No description provided.

NameTypeReqDescription
idstringyes

No output schema declared.

No examples provided.

format_sheet ~196

No description provided.

NameTypeReqDescription
autoResizeboolean
boldHeaderboolean
freezeRowsnumber
sheetUrlstring
spreadsheetIdstring
tabstring

No output schema declared.

No examples provided.

Common questions

What is the Hermoso MCP server?

Hermoso is an MCP server listed in the public MCP registry as io.github.hermoso-ai/hermoso. Marketing on autopilot from your agent. 841 tools, usable alone. Publishing and ads cost no credits. This page covers its npm package (hermoso).

Is the Hermoso MCP server safe to use?

Hermoso scores 42 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

Is the Hermoso MCP server still maintained?

Hermoso is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the Hermoso MCP server under?

Hermoso declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.