Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

SuperCMO

PYPI · SUPERCMO-SKILLS · SCANNED OCT 4

Marketing media generation — image, video, voice — for AI agents. BYO keys.

Available components

+10 this week 91 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
  • 1 of 5 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to SupercmoHQ/superCMO-skills). View diagnostics → Pass
  • Clear OSI-approved license (Apache-2.0).Pass
  • Actively maintained (last published 36 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability64
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 7101 tokens (~322/item across 22 items; 22 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "calendar_remove" implies "remove" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 22 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the SuperCMO MCP server?

SuperCMO runs locally as a PyPI package, launched with uvx supercmo-skills. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · supercmo-skills

# add to Claude Code
claude mcp add supercmohq-supercmo -- uvx supercmo-skills
// .cursor/mcp.json
{
  "mcpServers": {
    "supercmohq-supercmo": {
      "command": "uvx",
      "args": [
        "supercmo-skills"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "supercmohq-supercmo": {
      "command": "uvx",
      "args": [
        "supercmo-skills"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add supercmohq-supercmo -- uvx supercmo-skills
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "supercmohq-supercmo": {
      "type": "local",
      "command": [
        "uvx",
        "supercmo-skills"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add supercmohq-supercmo --command uvx --arg supercmo-skills
# ~/.hermes/config.yaml
mcp_servers:
  supercmohq-supercmo:
    command: "uvx"
    args: ["supercmo-skills"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "supercmohq-supercmo": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "supercmo-skills"
      ]
    }
  }
}
# add to Vellum
assistant mcp add supercmohq-supercmo -t stdio -c uvx -a supercmo-skills
// mcp.json
{
  "mcpServers": {
    "supercmohq-supercmo": {
      "command": "uvx",
      "args": [
        "supercmo-skills"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Oct 26 0
    • Stability: 0.97 → pass security
  • 3 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 30 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Sept 26 +8
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 +18
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 −14
    • Malware scan: pass → unverified ▼ security
  • 23 Sept 26 −1
    • Stability: pass → 0.93 functional
  • 22 Sept 26 +15
    • Malware scan: unverified → pass ▲ security
    • Stability: 0.97 → pass security
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 6 Oct 2026 · Analysed pypi/supercmo-skills@0.1.24

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem pypi
Reason Verified
Discovered via Registry attestation endpoint
Source repo SupercmoHQ/superCMO-skills
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/SupercmoHQ/superCMO-skills/.github/workflows/release.yml@refs/heads/main
Rekor log index 2626048520
Predicate type PyPI publish attestation https://docs.pypi.org/attestations/publish/v1
Subject digest sha256:e01985f3902485e5e7042b9751bb0b8778dd2cb06696731d880ecf3de83e1d19

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted hatchling.build

Background: Why install scripts are a supply-chain risk →

Dependencies 5 packages
Packages resolved 5
Stale 1
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 22 exposed · ~7,101 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
audio_generate ~417

For a user's voiceover request, load the `generating-audio` skill BEFORE calling this — it picks the right model and voice and prepares the script for reading aloud (this tool does none of that, and calling it raw gives a flat, mispronounced read). Turn written text into spoken audio: voiceovers, narration, ad reads, character lines, or any script read aloud. Pass `requests`: ONE object per clip (wrap even a single clip — `{ requests: [ { text } ] }`); add more objects (up to 10) to generate DIFFERENT lines in one call — a single approval covers the batch. Each result carries the spoken audio plus a local file `path`, or a structured error with a hint. This generates speech and nothing else: no sound effects, music, or ambience, no re-voicing an existing recording, and no dubbing a video. If the user asks for one of those, say so plainly rather than substituting a different tool. Every request needs a `voice` — the `voice_id` of a row from list_voices. There is no default voice. Models differ in expressiveness, language coverage, speed, price, and per-request character limit — call list_audio_models to compare them. Set dry_run=true to preview the exact requests without generating (no credits spent).Each entry in `results` is one of three things: finished media; a `{status:"pending", ...}` job handle to rejoin with job_status; or a failure carrying `ok: false` and an `error`. A failed entry is terminal — report its `error` and never poll or re-submit it. Read every entry rather than the top-level counters alone.

NameTypeReqDescription
dry_runboolean–If true, return the requests that would be sent (keys masked), make no API call.
requestsarrayyesOne object per audio clip (wrap even a single clip); add more objects to generate different lines in one call (up to 10).

No output schema declared.

No examples provided.

calendar_add ~748

Schedule a new calendar event that fires once or on a recurrence. Two kinds: 'task' re-invokes the agent with `prompt` when it fires — write the prompt as a complete, self-contained instruction, since the agent has no memory of this call when it runs. 'post' publishes prepared `content` through a named tool with no model call in the loop — requires `content`, `channel`, and `publish_tool`. Exactly ONE of `at` (a one-shot ISO-8601 timestamp, which must be in the future) or `rrule` (an RFC 5545 recurrence rule) is required — never both, never neither. `channel` is free text, not a router: it is a hint the tool named in `publish_tool` reads to decide where to post, so word it the way that tool expects, never a fixed enum. `publish_tool` must name a tool the caller can actually call right now — a currently-connected tool, never invented or assumed; the event hard-fails at fire time if the named tool is not connected. `media` is an optional list of local file paths and/or URLs to publish alongside `content`. `timezone` is an IANA name (e.g. 'America/New_York') the schedule is interpreted in.

NameTypeReqDescription
atstring–One-shot fire time, ISO-8601 (e.g. '2026-09-01T14:30:00+05:30'). Must be in the future. Exactly one of `at` or `rrule` is required — never both, never neither.
channelstring–REQUIRED when kind='post'. Free text naming where to publish (e.g. 'LinkedIn company page', 'Instagram @brand') — a hint the tool named in `publish_tool` reads to decide where to post. This is NOT a…
contentstring–REQUIRED when kind='post'. The exact prepared text to publish.
kindstringyesWhich kind of event this is. 'task' re-invokes the agent with `prompt` when it fires; 'post' publishes `content` via `publish_tool` with no model call in the loop. Determines which other fields are r…
mediaarray–Optional media to publish alongside `content` — a list of local file paths and/or URLs.
promptstring–REQUIRED when kind='task'. The instruction the agent is re-invoked with when the event fires — write it as a complete, self-contained instruction, since the agent has no memory of this call at fire t…
publish_toolstring–REQUIRED when kind='post'. The exact name of a tool the caller can currently call to publish (e.g. 'linkedin_post'). Must be a real, currently-connected tool — never guessed or invented — since the e…
rrulestring–Recurrence rule, RFC 5545 (e.g. 'FREQ=WEEKLY;BYDAY=MO,WE,FR;BYHOUR=9'), for an event that fires repeatedly. Exactly one of `at` or `rrule` is required — never both, never neither.
timezonestring–IANA timezone name (e.g. 'America/New_York', 'Asia/Kolkata') that `at` or `rrule` is interpreted in.
titlestringyesShort human-readable label for the event, shown in calendar listings.

No output schema declared.

No examples provided.

calendar_list ~335

List the caller's calendar events — tasks and posts — ordered by when they next fire. Each event includes a computed `next_occurrence`: the ISO-8601 timestamp of its next fire time, derived from the event's `at` or `rrule` so the caller never has to compute recurrence itself. Defaults to upcoming, still-scheduled events; pass `status` to also see cancelled or historical (done/failed/missed) events. Narrow further with `window_start`/`window_end` (a time range), `kind` (task vs post), or `channel` (exact match on the free-text channel), and cap how many come back with `limit`. Use this before calendar_add to check for a clash, or before calendar_update/calendar_remove to find the event's `id`.

NameTypeReqDescription
channelstring–Filter to events whose `channel` matches this free text exactly. Omit to include all channels.
kindstring–Filter to only this kind of event. Omit to list both.
limitinteger–Maximum number of events to return, ordered by next occurrence (soonest first).
statusstring–Filter to events in this lifecycle state. Omit to default to 'scheduled' (upcoming) events only.
window_endstring–Only include events whose next occurrence is at or before this ISO-8601 timestamp. Omit for no upper bound.
window_startstring–Only include events whose next occurrence is at or after this ISO-8601 timestamp. Omit for no lower bound (defaults to now).

No output schema declared.

No examples provided.

calendar_remove ~76

Cancel a calendar event by `id` — it stops firing but is not deleted, the same effect as calendar_update with status='cancelled'. Use calendar_list first if you don't already have the event's `id`.

NameTypeReqDescription
idstringyesThe event id returned by calendar_add or calendar_list, identifying which event to act on.

No output schema declared.

No examples provided.

calendar_update ~635

Change fields on an existing calendar event, or re-arm/cancel it. Pass only the fields you want to change — anything omitted is left as it was. `kind` is fixed at creation and can't be changed here. The same rules as calendar_add apply to whatever you set: exactly one of `at`/`rrule` if you're changing the schedule, and `content`+`channel`+`publish_tool` together if the event is a 'post'. `channel` stays free text read by `publish_tool`, never a routing enum, and `publish_tool` must still name a currently-connected tool. Pass `status: "cancelled"` to cancel the event without deleting it, or `status: "scheduled"` to re-arm a cancelled one.

NameTypeReqDescription
atstring–One-shot fire time, ISO-8601 (e.g. '2026-09-01T14:30:00+05:30'). Must be in the future. Exactly one of `at` or `rrule` is required — never both, never neither.
channelstring–REQUIRED when kind='post'. Free text naming where to publish (e.g. 'LinkedIn company page', 'Instagram @brand') — a hint the tool named in `publish_tool` reads to decide where to post. This is NOT a…
contentstring–REQUIRED when kind='post'. The exact prepared text to publish.
idstringyesThe event id returned by calendar_add or calendar_list, identifying which event to act on.
mediaarray–Optional media to publish alongside `content` — a list of local file paths and/or URLs.
promptstring–REQUIRED when kind='task'. The instruction the agent is re-invoked with when the event fires — write it as a complete, self-contained instruction, since the agent has no memory of this call at fire t…
publish_toolstring–REQUIRED when kind='post'. The exact name of a tool the caller can currently call to publish (e.g. 'linkedin_post'). Must be a real, currently-connected tool — never guessed or invented — since the e…
rrulestring–Recurrence rule, RFC 5545 (e.g. 'FREQ=WEEKLY;BYDAY=MO,WE,FR;BYHOUR=9'), for an event that fires repeatedly. Exactly one of `at` or `rrule` is required — never both, never neither.
statusstring–Set to 'cancelled' to stop the event from firing without deleting it, or 'scheduled' to re-arm a cancelled event.
timezonestring–IANA timezone name (e.g. 'America/New_York', 'Asia/Kolkata') that `at` or `rrule` is interpreted in.
titlestring–Short human-readable label for the event, shown in calendar listings.

No output schema declared.

No examples provided.

caption_video ~272

Burn styled, social-style captions into a video from a word-timed transcript — local ffmpeg, no credits. The usual chain is transcribe -> caption_video: run transcribe on the video (or its voiceover) to get word timestamps, then pass those here. Captions are styled and positioned with a font bundled in the package (no system-font dependency); optional karaoke highlights each word as it is spoken. Timestamps are relative to the video's own audio (t=0). Returns the output file `path` with its duration, resolution, and size, or a structured error with a hint. Requires ffmpeg. Set dry_run=true to preview without rendering.

NameTypeReqDescription
dry_runboolean–If true, return the planned output and line count; run no ffmpeg.
outputstring–Optional output file path. Omit to write a default filename into the media output directory.
styleobject–Optional caption styling.
transcriptarrayyesThe words to show, in order — each an object with the word text and its timing in seconds. This is exactly the `words` list transcribe returns.
videostringyesThe video to caption — a local file path (e.g. a video_generate `path`) or an http(s) video URL.

No output schema declared.

No examples provided.

image_analysis ~309

Look at one or more images (local file paths or image URLs) and answer a question about each — returns text, not new images. Use to read a product photo (category, materials, on-pack text, distinctive details), to judge whether a shot is product-only or shows a face, or to describe any image's content, layout, or text. Pass `requests` to read several images in ONE call — they are analyzed in parallel, so a batch costs about the same wall time as its slowest image. Give a specific 'prompt' for a focused answer; omit it for a general description. Set dry_run=true to preview the request without spending.

NameTypeReqDescription
dry_runboolean–If true, return the request that would be sent (key and image masked), make no API call.
imagestring–The image to analyze — a local file path or an http(s) image URL.
promptstring–The question to answer about this image — e.g. 'What product is this, how is it used, how does it open, and what color/material/label details define it?' Omit for a general description.
requestsarray–Analyze several images in one call (1-10). Each entry takes its own `image` and optional `prompt`. Use this instead of one call per image whenever you have more than one to read — they run in paralle…

No output schema declared.

No examples provided.

image_generate ~417

For a user's image request, load the `generating-images` skill BEFORE calling this — it picks the right model and builds the prompt (this tool does neither, and calling it raw gives weak, inconsistent results). Generate one or many still images from text prompts, optionally guided by reference images (a product photo, a character, a style or composition to follow). Pass `requests`: ONE object per image (wrap even a single image — `{ requests: [ { prompt } ] }`). Generate a batch of DIFFERENT images in a SINGLE call by adding more request objects (up to 10), each with its own prompt/model/aspect_ratio/resolution/reference_images; a single approval covers the whole batch. Each result carries a hosted image URL plus a local file `path`, or a structured error with a hint. Use for graphics, mockups, product/marketing visuals, logos, concept art, or to render a product or character from a supplied reference. Images are polled for you; a heavy image (large model / 4k / big batch) that runs long returns `{status:"pending", ...}` (a job handle, not an error) — pass that exact handle to `job_status` to retrieve it, and never re-submit a pending image. Set dry_run=true to preview the exact requests and cost without generating (no credits spent).Each entry in `results` is one of three things: finished media; a `{status:"pending", ...}` job handle to rejoin with job_status; or a failure carrying `ok: false` and an `error`. A failed entry is terminal — report its `error` and never poll or re-submit it. Read every entry rather than the top-level counters alone.

NameTypeReqDescription
dry_runboolean–If true, return the requests that would be sent (keys masked), make no API call.
requestsarrayyesOne object per image (wrap even a single image); add more objects to batch different images in one call (up to 10).

No output schema declared.

No examples provided.

job_status ~263

Retrieve a long-running generation that was submitted earlier but hasn't finished — any result from a generation tool that came back as `{status:"pending", ...}` (a job handle, not media). Pass the exact pending handle object(s) in `jobs`; NEVER re-submit a pending job with the tool that created it — that starts (and bills) a new one. Each job comes back one of three ways: **finished** (a hosted URL plus a local file `path`); still **pending** (`{status:"pending", ...}`), in which case call job_status again with the same handle after a short wait; or **failed**, carrying `ok: false` and an `error`. A failed job is terminal — it will never finish, so report the error and never poll or re-submit that handle. A batch can mix all three, so read every entry in `results` rather than the top-level counters alone. This works for any kind of pending generation and only rejoins an existing job — it neither starts nor bills a new one.

NameTypeReqDescription
jobsarrayyesThe pending job handle object(s) to retrieve — each exactly as returned by a prior video_generate / job_status call. Add more than one to retrieve a batch in one call.

No output schema declared.

No examples provided.

list_audio_models ~152

List the available speech models — for each, its strengths, price, per-request character limit, language coverage, and the audio types it supports — plus the output formats audio_generate accepts. Every model works with every voice, so voices are a separate concern — use list_voices for those. This is the authoritative source for what a model accepts; call it when choosing a model for an open-ended request, or to check a value before setting it. Pass an optional 'query' to filter models by use-case keyword (e.g. 'expressive', 'long-form', 'fast').

NameTypeReqDescription
querystring–Optional keyword to filter models by use-case (matches the name, display name, and strengths).

No output schema declared.

No examples provided.

list_image_models ~164

List the available image-generation models (with strengths, price, the aspect ratios each accepts and how many reference images it takes), plus the valid aspect ratios and resolution tiers that image_generate accepts. Use when you need to choose a model and don't already have one in mind (e.g. an open-ended request), or to check the valid aspect_ratio / resolution values, or how many reference images a model will take, before calling image_generate — most of the time the model is the default or already specified. Pass an optional 'query' to filter models by use-case keyword (e.g. 'text', 'photorealistic', 'fast').

NameTypeReqDescription
querystring–Optional keyword to filter models by use-case (matches the name, display name, and strengths).

No output schema declared.

No examples provided.

list_research_sources ~118

List the available research sources for social_research — every platform, its endpoints, and each endpoint's required and optional params plus per-call cost. Call this FIRST whenever you need competitor ads, profiles, posts, comments, transcripts, or platform search and don't already know the exact platform + endpoint + params. Pass an optional 'query' to filter by platform, endpoint, or keyword (e.g. 'ads', 'reddit', 'comments').

NameTypeReqDescription
querystring–Optional keyword to filter sources by platform, endpoint, or description.

No output schema declared.

No examples provided.

list_video_models ~167

List the available video-generation models with, for each, its full schema: modes (text / image / first-last-frame / reference), the aspect ratios, durations and resolutions it accepts, which media it takes (start/end frame and reference image/video/audio with max counts), whether it has native audio, plus strengths and price. This is the authoritative source for a model's exact ranges — call it when choosing a model for an open-ended request, or to check what a model accepts before setting aspect_ratio / duration / resolution / media. Pass an optional 'query' to filter by use-case keyword (e.g. 'cinematic', 'fast', 'audio').

NameTypeReqDescription
querystring–Optional keyword to filter models by use-case (matches the name, display name, and strengths).

No output schema declared.

No examples provided.

list_voices ~392

Find a voice to speak with, and get the `voice_id` that audio_generate requires. Returns the voices saved in the active ElevenLabs account — the user's own on their key, or the shared SuperCMO set on a managed key — each with its gender, accent, age, use-case and a `preview_url` you can hand the user so they hear it before committing. Filter by what the brief actually demands (a stated gender or accent is not negotiable) and keep `limit` small: offer a few candidates with their previews rather than a long list. A voice missing the attribute you filtered on is kept rather than dropped, because a voice the user cloned themselves often carries no labels at all. If the account holds no voices the result says so — a newly created ElevenLabs account starts empty, and voices must be added in the ElevenLabs dashboard before anything can be spoken.

NameTypeReqDescription
accentstring–Filter by accent as the provider labels it (e.g. 'american', 'british', 'indian', 'australian'). Free text, since the set grows.
agestring–Filter by apparent age of the voice.
genderstring–Filter by voice gender. Apply whenever the user stated one.
languagestring–Filter by primary language as a short code (e.g. 'en', 'hi', 'es').
limitinteger–How many voices to return. Keep it small — a handful of good candidates beats a catalogue.
searchstring–Free-text match over name, description and labels (e.g. 'warm', 'storyteller'). Passed to the provider.
use_casestring–Filter by what the voice is built for (e.g. 'advertisement', 'conversational', 'narrative_story', 'social_media', 'informative_educational').

No output schema declared.

No examples provided.

setup_status ~153

Check which SuperCMO media-generation keys are configured and which capabilities (image / video / audio) are ready — the setup doctor. Call this FIRST when a user is setting up SuperCMO, asks which keys they need, or a generation failed with 'no_provider_configured'. Returns each vendor key (set/missing, what it enables, where to get it), managed-key state, and per-capability readiness. Set check=true for a FREE key-validity probe where one exists (never a paid generation). Reports only key NAMES and set/missing — never key values.

NameTypeReqDescription
checkboolean–If true, also run a FREE key-validity probe where a provider implements one (no paid call).

No output schema declared.

No examples provided.

social_research ~576

Pull read-only structured public data from social platforms and ad libraries — competitor ads (Meta/Facebook + Instagram, LinkedIn), profiles, posts, comments, transcripts, hashtag/keyword search, and subreddit / trend discovery. Two steps: call list_research_sources FIRST to see the platforms, their endpoints, and each endpoint's params; then call this with `platform`, `endpoint`, and a `params` object built from that endpoint's required/optional params. Returns the source's structured JSON in `data`, or a structured error naming the missing or unknown params. Known endpoints are projected to their readable fields and one media URL per item, with page-level facts carried once in `advertisers` rather than repeated on every row, and `shaping` says what was dropped; `fields` widens or narrows that. Every response is also written to a file: `saved` carries its `path`, the run's `output_dir` for anything built from it, the count and the cursor, so a response can be handed straight to a script without being copied out of the conversation. Where the response is too large to read, `saved.inline` is false and `data` is omitted — use the file. Use for competitor and market research, audience listening, and trend discovery — this is read-only public data, not posting and not private data. Set dry_run=true to preview the exact request without spending.

NameTypeReqDescription
dry_runboolean–If true, return the request that would be sent (key masked), make no API call.
endpointstringyesThe endpoint on that platform — e.g. 'company_ads', 'profile', 'posts', 'comments', 'search', 'hashtag'. Call list_research_sources for each platform's endpoints.
fields––Which fields to return. Omit for the endpoint's default projection — the readable fields plus one media URL per item, which is what nearly every caller wants. Pass "*" for the vendor's payload untouc…
paramsobject–The endpoint's query parameters as an object — e.g. {"handle": "nike"} or {"companyName": "Nike", "country": "US"}. list_research_sources lists the required and optional params for each endpoint; a m…
platformstringyesThe platform to query — e.g. 'meta_ad_library', 'instagram', 'tiktok', 'youtube', 'reddit', 'x', 'linkedin', 'linkedin_ads'. Call list_research_sources for the full set.

No output schema declared.

No examples provided.

transcribe ~180

Transcribe speech from an audio or video file into text with word-level timestamps. Use it to caption a video (chain transcribe -> caption_video), to read a voiceover back, or to analyse a competitor ad's spoken script. `audio` is a local file path or an http(s) URL (audio or video). Returns {ok, text, words:[{word, start, end}], duration, language}, or a structured error. Set dry_run=true to preview the request without spending.

NameTypeReqDescription
audiostringyesThe audio or video to transcribe — a local file path or an http(s) URL.
dry_runboolean–If true, preview the request (key masked); make no API call.
languagestring–Optional ISO language-code hint (e.g. 'en'); omit to auto-detect.

No output schema declared.

No examples provided.

url_extraction ~254

Extract structured data from a web page — a product listing (Amazon, Shopify, AliExpress, any store) or any URL — guided by a prompt and/or a JSON schema. Returns the requested fields (e.g. name, brand, price, description, specs) and any gallery image URLs as a compact JSON object, plus page metadata — not the page's full text. Use when you need specific data or image URLs from a page. Set dry_run=true to preview the exact request without spending.

NameTypeReqDescription
dry_runboolean–If true, return the request that would be sent (key masked), make no API call.
promptstring–What to extract, in plain language — e.g. 'product name, brand, price, currency, variant, full description, feature bullets, specs, and all product-gallery image URLs (front/side/back/close-up/packag…
schemaobject–Optional JSON Schema describing the exact shape to return. Use for a strict, typed result; omit to let the prompt guide the extraction.
urlstringyesThe page URL to extract from (an http(s) URL).

No output schema declared.

No examples provided.

video_analysis ~290

Watch one or more videos (local file paths or video URLs) and answer a question about each — returns text, not new video. Use to read a clip before generating or matching it, to describe what happens in it, or to transcribe what is said. Pass `requests` to watch several videos in ONE call — they are analyzed in parallel, so a batch costs about the same wall time as its slowest clip. Analyzes a clip inline, so a very large file may be rejected — trim or link a shorter clip if so. Set dry_run=true to preview the request without spending.

NameTypeReqDescription
dry_runboolean–If true, return the request that would be sent (key and video masked), make no API call.
promptstring–The question to answer about this video — e.g. 'Describe the shots, the camera moves, the pacing, and transcribe what is said.' Omit for a general description.
requestsarray–Analyze several videos in one call (1-10). Each entry takes its own `video` and optional `prompt`. Use this instead of one call per video whenever you have more than one to watch — they run in parall…
videostring–The video to analyze — a local file path or an http(s) video URL.

No output schema declared.

No examples provided.

video_generate ~396

For a user's video request, load the `generating-videos` skill BEFORE calling this — it picks the right model and builds the motion prompt (this tool does neither, and calling it raw gives weak, generic clips). Generate one or many short video clips from text prompts, optionally guided by a start (and end) frame or by reference images, videos, or audio. Pass `requests`: ONE object per clip (wrap even a single clip — `{ requests: [ { prompt } ] }`); add more objects (up to 10) to batch DIFFERENT clips in one call, and repeat an object for variations of one prompt — a single approval covers the batch. Models differ in the aspect ratios, durations, resolutions, and media they accept — call list_video_models to check. Video generation is long-running: each clip is submitted and polled for you. A clip that finishes in time returns a hosted video URL plus a local file `path`; a clip still generating returns `{status:"pending", ...}` (a job handle, NOT an error) — pass that exact handle to `job_status` to retrieve it, and never re-submit a pending clip. Set dry_run=true to preview the exact requests without generating (no credits spent).Each entry in `results` is one of three things: finished media; a `{status:"pending", ...}` job handle to rejoin with job_status; or a failure carrying `ok: false` and an `error`. A failed entry is terminal — report its `error` and never poll or re-submit it. Read every entry rather than the top-level counters alone.

NameTypeReqDescription
dry_runboolean–If true, return the requests that would be sent (keys masked), make no API call.
requestsarrayyesOne object per clip (wrap even a single clip); add more objects to batch different clips in one call (up to 10).

No output schema declared.

No examples provided.

video_overlay ~302

Stamp a logo, timed text, and a branded end card onto a video — local ffmpeg, no credits. Overlay a logo watermark at a chosen corner, drop in timed text (CTAs, offers, captions you place yourself), and/or append an end-card image as a short closing still. Pass at least one of logo / texts / end_card. Text is rendered with a bundled font (no system-font dependency). Returns the output file `path` with its duration and resolution, or a structured error. Requires ffmpeg. Set dry_run=true to preview.

NameTypeReqDescription
dry_runboolean–If true, return the plan; run no ffmpeg.
end_cardstring–Optional end-card image (path or URL) appended as a closing still.
end_card_durationnumber–How long the end card holds, in seconds (default 3).
logostring–Optional logo image (PNG with transparency recommended) — path or URL.
logo_positionstring–Where the logo sits (default bottom-right).
logo_scalenumber–Logo width as a fraction of the video width (default 0.15).
outputstring–Optional output file path. Omit to write a default filename into the media output directory.
textsarray–Timed text overlays.
videostringyesThe video to decorate — a local file path or an http(s) video URL.

No output schema declared.

No examples provided.

video_stitch ~485

Join finished video clips into one file, in the order given, with a hard cut between each and each clip's audio kept — this assembles existing clips, it does not generate new video. Use it to build a video longer than a single model clip: generate the shots with video_generate, then stitch them. Do NOT use it for a single clip, or for a batch of clips meant to stay separate. Three optional layers, each its own parameter: lay a voiceover over the picture (pass `narration` — ONE take per clip, in clip order, NOT one joined track; each take is aligned to its own clip so nothing drifts), lay a background-music track under the whole thing (pass `music`), or burn in subtitles from an SRT file (pass `subtitles`); clips of different sizes are scaled to a common frame. Returns the output file `path` with its duration, resolution, and size, or a structured error with a hint. Requires ffmpeg on the system. Set dry_run=true to preview the plan without running anything.

NameTypeReqDescription
clipsarrayyesThe clips to join, in play order — local file paths (e.g. the `path` a video_generate result returns) or direct http(s) video URLs. At least two.
dry_runboolean–If true, return the planned output path and inputs; run no ffmpeg.
musicstring–Optional audio file (a local path or a URL) laid under the whole video as background music, mixed below the clips' own audio.
narrationarray–Optional voiceover — ONE audio take per clip, in the same order and the same count as `clips`. Each take is padded with silence to its clip's length, so take N is heard over clip N with no timecodes…
outputstring–Optional output file path. Omit to write a default filename into the media output directory.
subtitlesstring–Optional SRT subtitle file (a local path or a URL) burned into the video.

No output schema declared.

No examples provided.

Common questions

What is the SuperCMO MCP server?

SuperCMO is an MCP server listed in the public MCP registry as io.github.SupercmoHQ/supercmo. Marketing media generation, image, video, voice, for AI agents. BYO keys. This page covers its PyPI package (supercmo-skills).

Is the SuperCMO MCP server safe to use?

SuperCMO scores 91 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the SuperCMO MCP server expose?

SuperCMO exposes 22 tools: setup_status, image_generate, list_image_models, video_generate, list_video_models, and 17 more. Their descriptions and schemas cost roughly 7,101 tokens of context every time the server is loaded.

Is the SuperCMO MCP server still maintained?

SuperCMO is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the SuperCMO MCP server under?

SuperCMO declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.