io.github.xnjiang/autowhisper-mcp
NPM · AUTOWHISPER-MCP · SCANNED SEP 20
Drive your AutoWhisper AI CMO to generate and publish marketing content from any MCP client.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 96 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 19 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability73
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1716 tokens (~143/item across 12 items; 12 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management93
- Stability observed for 28 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage92
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 76% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "autowhisper_cmo" implies "send" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.xnjiang/autowhisper-mcp server?
io.github.xnjiang/autowhisper-mcp runs locally as an npm package, launched with npx -y autowhisper-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · autowhisper-mcp
claude mcp add xnjiang-autowhisper-mcp -- npx -y autowhisper-mcp
{
"mcpServers": {
"xnjiang-autowhisper-mcp": {
"command": "npx",
"args": [
"-y",
"autowhisper-mcp"
]
}
}
} {
"servers": {
"xnjiang-autowhisper-mcp": {
"command": "npx",
"args": [
"-y",
"autowhisper-mcp"
]
}
}
} codex mcp add xnjiang-autowhisper-mcp -- npx -y autowhisper-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"xnjiang-autowhisper-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"autowhisper-mcp"
],
"enabled": true
}
}
} openclaw mcp add xnjiang-autowhisper-mcp --command npx --arg -y --arg autowhisper-mcp
mcp_servers:
xnjiang-autowhisper-mcp:
command: "npx"
args: ["-y", "autowhisper-mcp"] {
"McpServers": {
"xnjiang-autowhisper-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"autowhisper-mcp"
]
}
}
} assistant mcp add xnjiang-autowhisper-mcp -t stdio -c npx -a -y autowhisper-mcp
{
"mcpServers": {
"xnjiang-autowhisper-mcp": {
"command": "npx",
"args": [
"-y",
"autowhisper-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 −2
- Stability: pass → 0.80 functional
- 15 Sept 26 0
- Stability: 0.97 → pass security
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 −2
- Stability: pass → 0.80 functional
- 8 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- Stability: 0.97 → pass security
- 7 Sept 26 −14
- Malware scan: pass → unverified ▼ security
- Package version: 0.6.0 → 0.7.0 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/autowhisper-mcp@0.7.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 96 packages
| Packages resolved | 96 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
autowhisper_action AutoWhisper delivery action ~382
Run an explicit feed or post action without an AI chat turn. High-impact actions return a confirmation message_id; confirm it with autowhisper_confirm. approve_feed_item PUBLISHES: it schedules the piece to every connected platform, and for a video draft it also starts the render and charges credits for it — approving is the spend, not a bookmark. When nothing is connected it schedules nothing, and connecting a platform later does NOT go back for it; the result line says which happened. regenerate_content rewrites an existing draft IN PLACE (same record id, new text) — it is the same action as the Revise button on the web feed card; it takes content_type + content_id, not feed_item_id, and always returns a confirmation because it spends credits.
| Name | Type | Req | Description |
|---|---|---|---|
| content_id | number | – | Required for regenerate_content. The id from the row's `content: <type> #<id>` — NOT feed_item_id. |
| content_type | string | – | Required for regenerate_content. The snake_case value from the row's `content: <type> #<id>` — NOT the class name. |
| feed_item_id | number | – | Required for feed actions. The leading `feed_item #<id>` in an autowhisper_feed row — NOT the `content: <type> #<id>` on the same row. |
| post_id | number | – | Required for post actions. |
| reason | string | – | Optional reason for rejecting a feed item. |
| scheduled_at | string | – | Required for reschedule_post; ISO8601 or natural language supported by AutoWhisper. |
| tool | string | yes | – |
| workspace_id | number | – | Workspace to act in. Omit for the user's CURRENT workspace. The target item must live in that workspace — an id from another workspace will not be found. |
No output schema declared.
No examples provided.
autowhisper_cmo Talk to your AutoWhisper CMO ~295
Send a natural-language instruction to your AutoWhisper AI CMO and get its reply. Best at: (1) generating batches of on-brand ad creatives (UGC video, posts, images) for paid campaigns, (2) advising which creative to fund and how to target, (3) keeping every social channel alive across 30+ networks, plus analytics. Examples: "Make a batch of ad creatives for my product https://mystore.com/widget", "Which creative should I run first, and how should I target?", "Keep my channels posted this week". Honest scope: posting ≠ traffic — reach comes from the user's paid ads. To add a product, pass a product URL (the CMO extracts the image from the page) — a text-only description will not create it, and placeholder/stock images are rejected.
| Name | Type | Req | Description |
|---|---|---|---|
| instruction | string | yes | What you want the CMO to do, in natural language. |
| product_id | string | – | Optional: act on a specific product by its id. |
| workspace_id | number | – | Workspace to act in. Omitting it uses the account's FIRST active workspace, which may not be the one you were just reading — and the workspace decides the generated content's LANGUAGE. Pass the works… |
No output schema declared.
No examples provided.
autowhisper_confirm Confirm an AutoWhisper action ~136
Approve or decline a high-impact action the CMO or autowhisper_action asked you to confirm. Pass the message_id it gave you and decision "yes" or "no".
| Name | Type | Req | Description |
|---|---|---|---|
| decision | string | yes | "yes" to perform the action, "no" to decline. |
| message_id | number | yes | The message_id from the confirmation request. |
| workspace_id | number | – | The workspace the confirmation lives in — pass the SAME one you used for autowhisper_cmo. Omitting it falls back to the account's first active workspace and 404s on a bubble that lives anywhere else. |
No output schema declared.
No examples provided.
autowhisper_connect Connect this agent to AutoWhisper ~112
Authorise this MCP server against the user's AutoWhisper account. Returns a link; the user clicks Approve once and this server is authorised immediately — no restart, nothing to copy and paste. Call this when a tool reports it is not connected, or when a call returns Unauthorized. Show the user the link and tell them you are waiting.
| Name | Type | Req | Description |
|---|---|---|---|
| device_name | string | – | What the user will see on the approval screen, e.g. 'Claude Desktop'. Name yourself so they recognise the request. |
No output schema declared.
No examples provided.
autowhisper_edit_content AutoWhisper edit content ~209
Directly update exact content fields without a generation run or credit spend. Pass body for the full replacement copy/story. IDs: content_id is the CONTENT id — in autowhisper_feed output that is the `content: <type> #<id>` part of a row, NOT the leading `feed_item #<id>` (that one belongs to autowhisper_action). content_type is the same snake_case value shown there.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | – | – |
| content_id | number | yes | The CONTENT id from the feed row's `content: <type> #<id>` — not the feed_item id. |
| content_type | string | yes | Content type in snake_case, as printed in the feed row's `content:` part. |
| cta | string | – | – |
| hook | string | – | – |
| keywords | array | – | – |
| title | string | – | – |
| tone | string | – | – |
| workspace_id | number | – | – |
No output schema declared.
No examples provided.
autowhisper_feed AutoWhisper CMO feed ~120
Fast read-only CMO feed list for ONE workspace (the user's current one unless workspace_id is given), with status counts and available actions. Use for pending review/feed/status questions.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Maximum feed items to return, capped by the API. |
| status | string | – | Feed status to return. Defaults to pending. |
| workspace_id | number | – | Workspace to read. Omit for the user's CURRENT workspace — other workspaces are NOT included. To reach another one, get its id from autowhisper_status. |
No output schema declared.
No examples provided.
autowhisper_platforms AutoWhisper platforms ~76
Fast read-only connected-platform list and connection health for ONE workspace (the user's current one unless workspace_id is given).
| Name | Type | Req | Description |
|---|---|---|---|
| workspace_id | number | – | Workspace to read. Omit for the user's CURRENT workspace — other workspaces are NOT included. To reach another one, get its id from autowhisper_status. |
No output schema declared.
No examples provided.
autowhisper_posts AutoWhisper posts ~109
Fast delivery-queue list for ONE workspace (the user's current one unless workspace_id is given). Use for scheduled, failed, and published post facts.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Maximum posts to return, capped by the API. |
| status | string | – | Optional post status filter. |
| workspace_id | number | – | Workspace to read. Omit for the user's CURRENT workspace — other workspaces are NOT included. To reach another one, get its id from autowhisper_status. |
No output schema declared.
No examples provided.
autowhisper_products AutoWhisper products ~118
Fast read-only product list for ONE workspace (the user's current one unless workspace_id is given). Use instead of autowhisper_cmo when the user only wants to list/search products.
| Name | Type | Req | Description |
|---|---|---|---|
| include_archived | boolean | – | Include archived products. |
| limit | number | – | Maximum products to return, capped by the API. |
| workspace_id | number | – | Workspace to read. Omit for the user's CURRENT workspace — other workspaces are NOT included. To reach another one, get its id from autowhisper_status. |
No output schema declared.
No examples provided.
autowhisper_products_summary AutoWhisper product counts ~54
Fast read-only product counts, account-wide AND per workspace. Unlike the other read tools this one spans EVERY workspace — use it for 'how many products do I have in total?' and to discover workspace ids.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
autowhisper_status AutoWhisper CMO status ~78
Fast read-only CMO snapshot for the user's CURRENT workspace (products, feed, platforms, automation settings) plus the account-level wallet and a directory of EVERY workspace with its id. Call this first to learn which workspaces exist and which one is current — every other read tool defaults to the current one and does NOT span the others.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
autowhisper_wallet AutoWhisper wallet ~27
Fast read-only credit balance. Use before proposing or starting credit-spending generation.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the io.github.xnjiang/autowhisper-mcp server?
io.github.xnjiang/autowhisper-mcp is listed in the public MCP registry as io.github.xnjiang/autowhisper-mcp. Drive your AutoWhisper AI CMO to generate and publish marketing content from any MCP client. This page covers its npm package (autowhisper-mcp).
Is the io.github.xnjiang/autowhisper-mcp server safe to use?
io.github.xnjiang/autowhisper-mcp scores 80 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.xnjiang/autowhisper-mcp server expose?
io.github.xnjiang/autowhisper-mcp exposes 12 tools: autowhisper_connect, autowhisper_products_summary, autowhisper_products, autowhisper_status, autowhisper_feed, and 7 more. Their descriptions and schemas cost roughly 1,716 tokens of context every time the server is loaded.
Is the io.github.xnjiang/autowhisper-mcp server still maintained?
io.github.xnjiang/autowhisper-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.xnjiang/autowhisper-mcp server under?
io.github.xnjiang/autowhisper-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.