# to.hooka/mcp (npm · hooka-mcp)

Run TikTok cold-DM outreach from your LLM: senders, campaigns and inbox via the Hooka API.

- Trust score: 60/100 (medium)
- Change this week: +16
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `hooka-mcp`: 60/100 (this document), [markdown](https://verifymcp.io/servers/to-hooka-mcp/hooka-mcp.md), [page](https://verifymcp.io/servers/to-hooka-mcp/hooka-mcp)

## Channel facts

- Registry: `npm`
- Package: `hooka-mcp`
- Version: `0.1.2`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 87/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 19/100
  - Repository check failed: no source repository is declared.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 38 days ago).
  - Security-disclosure policy not yet verified: we couldn't inspect the source repository.
- **Schema Quality & AI Usability**: 82/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 1347 tokens (~53/item across 25 items; 23 tools + 2 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 83/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 48% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add to-hooka-mcp -- npx -y hooka-mcp
```

### Codex

```bash
codex mcp add to-hooka-mcp -- npx -y hooka-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "to-hooka-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "hooka-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add to-hooka-mcp --command npx --arg -y --arg hooka-mcp
```

### Hermes

```yaml
mcp_servers:
  to-hooka-mcp:
    command: "npx"
    args: ["-y", "hooka-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "to-hooka-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "hooka-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 60, +36)

- [security regression] Provenance: unverified → fail
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Install scripts: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional regression] Capabilities: pass → unverified
- [functional improvement] Schema quality: unverified → good
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] License: unverified → pass
- [functional] Licence: MIT

### 2026-08-01 (score 24, +5)

- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] MCP protocol: unverified → pass

### 2026-07-31 (score 19, +19)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 0, −44)

- [security regression] Malware scan: pass → unverified
- [functional regression] Schema quality: 100 → unverified
- [functional regression] Tool coverage: 100 → unverified

### 2026-07-27 (score 44)

First indexed and scored.

## MCP tools (23)

### `list_senders` (~70 tokens)

Listar senders

Lista las cuentas de TikTok conectadas (senders): estado, salud, tope diario y enviados hoy.

Input parameters:

- `limit` (integer): Máximo de resultados (1-100, por defecto 50).
- `starting_after` (string): Cursor: id del último elemento de la página anterior.

### `get_sender` (~44 tokens)

Ver sender

Detalle de un sender. Útil para hacer poll del estado de conexión (awaiting_scan → connected).

Input parameters:

- `id` (string, required): id del sender (snd_…)

### `create_sender` (~76 tokens)

Conectar una cuenta TikTok (QR)

Inicia la conexión de una cuenta de TikTok. Devuelve un qr_code (data URL PNG) que el USUARIO debe escanear con la app de TikTok. Después usa get_sender para hacer poll hasta status="connected". No se pide la contraseña.

Input parameters:

- `label` (string): Etiqueta interna para identificar la cuenta.

### `refresh_sender_connection` (~37 tokens)

Regenerar QR del sender

Genera un nuevo QR si el anterior caducó (409 si la cuenta ya está conectada).

Input parameters:

- `id` (string, required)

### `delete_sender` (~49 tokens)

Desconectar sender

Desconecta una cuenta TikTok y pausa las campañas que dependían solo de ella. Irreversible (hay que re-escanear el QR para reconectar).

Input parameters:

- `id` (string, required)

### `list_campaigns` (~59 tokens)

Listar campañas

Lista las campañas del workspace (excluye archivadas).

Input parameters:

- `limit` (integer): Máximo de resultados (1-100, por defecto 50).
- `starting_after` (string): Cursor: id del último elemento de la página anterior.

### `get_campaign` (~45 tokens)

Ver campaña

Detalle de una campaña con stats en vivo (total, queued, sent, replied, failed, reply_rate).

Input parameters:

- `id` (string, required): id de campaña (cmp_…)

### `create_campaign` (~142 tokens)

Crear campaña

Crea una campaña en estado "draft" (NO empieza a enviar hasta start_campaign). Define mensaje (con variantes A/B/C que rotan), follow-ups y targets. Respeta límites de plan y dedup.

Input parameters:

- `client_reference` (string)
- `follow_ups` (array): Secuencia de follow-ups (se paran solos si el lead responde).
- `message` (required): Texto del DM inicial, o {variants:[...]} para rotación A/B/C. Soporta {{variables}}.
- `name` (string, required)
- `settings` (object)
- `targets` (array): Destinatarios iniciales (también con add_targets).

### `add_targets` (~52 tokens)

Añadir destinatarios

Añade hasta 1000 destinatarios a una campaña. Devuelve aceptados y omitidos (con motivo: duplicate/suppressed/invalid).

Input parameters:

- `id` (string, required)
- `targets` (array, required)

### `list_targets` (~85 tokens)

Listar destinatarios

Lista los destinatarios de una campaña (filtra por status: pending/processing/sent/replied/failed/skipped).

Input parameters:

- `id` (string, required)
- `limit` (integer): Máximo de resultados (1-100, por defecto 50).
- `starting_after` (string): Cursor: id del último elemento de la página anterior.
- `status` (string)

### `start_campaign` (~64 tokens)

Arrancar campaña

⚠️ Arranca el envío: empieza a mandar DMs REALES a personas en TikTok y consume cupo de plan. Acción irreversible (los DMs enviados no se pueden retirar). Pide confirmación al usuario antes de ejecutar.

Input parameters:

- `id` (string, required)

### `pause_campaign` (~25 tokens)

Pausar campaña

Pausa el envío de una campaña en curso.

Input parameters:

- `id` (string, required)

### `resume_campaign` (~33 tokens)

Reanudar campaña

⚠️ Reanuda el envío de DMs reales de una campaña pausada.

Input parameters:

- `id` (string, required)

### `list_conversations` (~77 tokens)

Listar conversaciones

Lista las conversaciones del inbox (filtra por status y/o sender_id).

Input parameters:

- `limit` (integer): Máximo de resultados (1-100, por defecto 50).
- `sender_id` (string)
- `starting_after` (string): Cursor: id del último elemento de la página anterior.
- `status` (string)

### `get_messages` (~61 tokens)

Ver mensajes de una conversación

Historial de mensajes de una conversación.

Input parameters:

- `id` (string, required)
- `limit` (integer): Máximo de resultados (1-100, por defecto 50).
- `starting_after` (string): Cursor: id del último elemento de la página anterior.

### `send_reply` (~63 tokens)

Responder en el inbox

⚠️ Encola una respuesta a una conversación: envía un DM REAL a una persona en TikTok. Acción irreversible. Pide confirmación al usuario y revisa el texto antes de ejecutar.

Input parameters:

- `id` (string, required)
- `text` (string, required)

### `list_suppressions` (~64 tokens)

Listar lista No-contactar

Lista los @usernames suprimidos (do-not-contact) del workspace.

Input parameters:

- `limit` (integer): Máximo de resultados (1-100, por defecto 50).
- `starting_after` (string): Cursor: id del último elemento de la página anterior.

### `add_suppressions` (~43 tokens)

Añadir a No-contactar

Añade @usernames a la lista de supresión (nunca recibirán DMs).

Input parameters:

- `reason` (string)
- `usernames` (array, required)

### `remove_suppression` (~29 tokens)

Quitar de No-contactar

Quita un @username de la lista de supresión.

Input parameters:

- `username` (string, required)

### `list_events` (~81 tokens)

Listar eventos

Lista eventos del workspace (fallback/backfill de webhooks). Filtra por type y after (id).

Input parameters:

- `after` (string)
- `limit` (integer): Máximo de resultados (1-100, por defecto 50).
- `starting_after` (string): Cursor: id del último elemento de la página anterior.
- `type` (string)

### `list_webhook_endpoints` (~19 tokens)

Listar webhooks

Lista los endpoints de webhook configurados.

### `create_webhook_endpoint` (~58 tokens)

Crear webhook

Crea un endpoint de webhook. Devuelve un secret (whsec_…) que se muestra UNA sola vez.

Input parameters:

- `enabled_events` (array, required): Tipos de evento o ['*'] para todos.
- `url` (string, required)

### `get_workspace` (~31 tokens)

Ver workspace (whoami)

Devuelve el workspace de la API key actual. Úsalo al iniciar para verificar que la key es válida.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/to-hooka-mcp/hooka-mcp#diagnostics

## Score history

- 2026-08-03: 60
- 2026-08-02: 60
- 2026-08-01: 24
- 2026-07-31: 19
- 2026-07-30: 0
- 2026-07-28: 44
- 2026-07-27: 44

## Links

- npm package: https://www.npmjs.com/package/hooka-mcp
- Socket report: https://socket.dev/npm/package/hooka-mcp
- Changelog RSS feed: https://verifymcp.io/servers/to-hooka-mcp/hooka-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/to-hooka-mcp/hooka-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/to-hooka-mcp/hooka-mcp
