# io.github.xnjiang/autowhisper-mcp (npm · autowhisper-mcp)

Drive your AutoWhisper AI CMO to generate and publish marketing content from any MCP client.

- Trust score: 34/100 (low)
- Change this week: +28
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-04

## Components

- npm · `autowhisper-mcp`: 34/100 (this document), [markdown](https://verifymcp.io/servers/xnjiang-autowhisper-mcp/autowhisper-mcp.md), [page](https://verifymcp.io/servers/xnjiang-autowhisper-mcp/autowhisper-mcp)

## Channel facts

- Registry: `npm`
- Package: `autowhisper-mcp`
- Version: `0.4.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-04.

- **Supply Chain Security**: 83/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 6 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 0/100
  - Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.
- **Tool Coverage**: 0/100
  - Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess.
- **Capabilities**: 0/100
  - Protocol version not yet verified: our sandbox run of this package did not complete, so we never saw its MCP handshake.

**Unverified: 4 categories.** Categories scored 0 because our sandbox run of this package has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you.

## Install

### Claude

```bash
claude mcp add xnjiang-autowhisper-mcp -- npx -y autowhisper-mcp
```

### Codex

```bash
codex mcp add xnjiang-autowhisper-mcp -- npx -y autowhisper-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "xnjiang-autowhisper-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "autowhisper-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add xnjiang-autowhisper-mcp --command npx --arg -y --arg autowhisper-mcp
```

### Hermes

```yaml
mcp_servers:
  xnjiang-autowhisper-mcp:
    command: "npx"
    args: ["-y", "autowhisper-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "xnjiang-autowhisper-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "autowhisper-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-04 (score 34, −1)

- [security regression] CVE-2026-69207 affects this package: medium
- [security regression] Known CVEs: partial → fail

### 2026-08-02 (score 35, +30)

- [security regression] Provenance: unverified → fail
- [security improvement] GHSA-frvp-7c67-39w9 no longer affects this package
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Install scripts: unverified → pass
- [security improvement] Malware scan: unverified → pass
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] License: unverified → pass
- [functional] Licence: MIT
- [functional] Package version: 0.3.0 → 0.4.0

### 2026-08-01 (score 5, 0)

- [security] Stability: Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.
- [functional] Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess.
- [functional] Capabilities: Protocol version not yet verified: our sandbox run of this package did not complete, so we never saw its MCP handshake.
- [functional] Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess.

### 2026-07-31 (score 5, −1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 6, 0)

- [functional] Tool coverage: Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess.
- [functional] Schema quality: Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess.

### 2026-07-28 (score 6, −41)

- [security regression] Install scripts: pass → unverified
- [security regression] Provenance: fail → unverified
- [security regression] Known CVEs: fail → unverified
- [security improvement] GHSA-frvp-7c67-39w9 no longer affects this package
- [functional regression] Maintenance: pass → unverified
- [functional regression] Dependency health: partial → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional regression] License: pass → unverified
- [functional] First check of Schema quality: unverified
- [functional] Licence: MIT
- [functional] Package version: 0.3.0 → 0.4.0

### 2026-07-27 (score 47)

First indexed and scored.

## MCP tools (11)

### `autowhisper_products_summary` (~35 tokens)

AutoWhisper product counts

Fast read-only product counts by account and workspace. Use for questions like 'how many products do I have?'.

### `autowhisper_products` (~76 tokens)

AutoWhisper products

Fast read-only product list. Use instead of autowhisper_cmo when the user only wants to list/search current products.

Input parameters:

- `include_archived` (boolean): Include archived products.
- `limit` (number): Maximum products to return, capped by the API.
- `workspace_id` (number): Optional workspace id.

### `autowhisper_status` (~33 tokens)

AutoWhisper CMO status

Fast read-only account/CMO snapshot: products, feed, connected platforms, wallet, and automation settings.

### `autowhisper_feed` (~76 tokens)

AutoWhisper CMO feed

Fast read-only CMO feed list with status counts and available actions. Use for pending review/feed/status questions.

Input parameters:

- `limit` (number): Maximum feed items to return, capped by the API.
- `status` (string): Feed status to return. Defaults to pending.
- `workspace_id` (number): Optional workspace id.

### `autowhisper_posts` (~70 tokens)

AutoWhisper posts

Fast delivery-queue list for the active workspace. Use for scheduled, failed, and published post facts.

Input parameters:

- `limit` (number): Maximum posts to return, capped by the API.
- `status` (string): Optional post status filter.
- `workspace_id` (number): Optional workspace id.

### `autowhisper_wallet` (~27 tokens)

AutoWhisper wallet

Fast read-only credit balance. Use before proposing or starting credit-spending generation.

### `autowhisper_platforms` (~37 tokens)

AutoWhisper platforms

Fast read-only connected-platform list and connection health for the active workspace.

Input parameters:

- `workspace_id` (number): Optional workspace id.

### `autowhisper_action` (~354 tokens)

AutoWhisper delivery action

Run an explicit feed or post action without an AI chat turn. High-impact actions return a confirmation message_id; confirm it with autowhisper_confirm. approve_feed_item PUBLISHES: it schedules the piece to every connected platform, and for a video draft it also starts the render and charges credits for it — approving is the spend, not a bookmark. When nothing is connected it schedules nothing, and connecting a platform later does NOT go back for it; the result line says which happened. regenerate_content rewrites an existing draft IN PLACE (same record id, new text) — it is the same action as the Revise button on the web feed card; it takes content_type + content_id, not feed_item_id, and always returns a confirmation because it spends credits.

Input parameters:

- `content_id` (number): Required for regenerate_content. The id from the row's `content: <type> #<id>` — NOT feed_item_id.
- `content_type` (string): Required for regenerate_content. The snake_case value from the row's `content: <type> #<id>` — NOT the class name.
- `feed_item_id` (number): Required for feed actions. The leading `feed_item #<id>` in an autowhisper_feed row — NOT the `content: <type> #<id>` on the same row.
- `post_id` (number): Required for post actions.
- `reason` (string): Optional reason for rejecting a feed item.
- `scheduled_at` (string): Required for reschedule_post; ISO8601 or natural language supported by AutoWhisper.
- `tool` (string, required)
- `workspace_id` (number): Optional workspace id.

### `autowhisper_edit_content` (~209 tokens)

AutoWhisper edit content

Directly update exact content fields without a generation run or credit spend. Pass body for the full replacement copy/story. IDs: content_id is the CONTENT id — in autowhisper_feed output that is the `content: <type> #<id>` part of a row, NOT the leading `feed_item #<id>` (that one belongs to autowhisper_action). content_type is the same snake_case value shown there.

Input parameters:

- `body` (string)
- `content_id` (number, required): The CONTENT id from the feed row's `content: <type> #<id>` — not the feed_item id.
- `content_type` (string, required): Content type in snake_case, as printed in the feed row's `content:` part.
- `cta` (string)
- `hook` (string)
- `keywords` (array)
- `title` (string)
- `tone` (string)
- `workspace_id` (number)

### `autowhisper_cmo` (~295 tokens)

Talk to your AutoWhisper CMO

Send a natural-language instruction to your AutoWhisper AI CMO and get its reply. Best at: (1) generating batches of on-brand ad creatives (UGC video, posts, images) for paid campaigns, (2) advising which creative to fund and how to target, (3) keeping every social channel alive across 30+ networks, plus analytics. Examples: "Make a batch of ad creatives for my product https://mystore.com/widget", "Which creative should I run first, and how should I target?", "Keep my channels posted this week". Honest scope: posting ≠ traffic — reach comes from the user's paid ads. To add a product, pass a product URL (the CMO extracts the image from the page) — a text-only description will not create it, and placeholder/stock images are rejected.

Input parameters:

- `instruction` (string, required): What you want the CMO to do, in natural language.
- `product_id` (string): Optional: act on a specific product by its id.
- `workspace_id` (number): Workspace to act in. Omitting it uses the account's FIRST active workspace, which may not be the one you were just reading — and the workspace decides the generated content's LANGUAGE. Pass the works…

### `autowhisper_confirm` (~84 tokens)

Confirm an AutoWhisper action

Approve or decline a high-impact action the CMO or autowhisper_action asked you to confirm. Pass the message_id it gave you and decision "yes" or "no".

Input parameters:

- `decision` (string, required): "yes" to perform the action, "no" to decline.
- `message_id` (number, required): The message_id from the confirmation request.

## Diagnostics

Captured diagnostic sections: Provenance, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/xnjiang-autowhisper-mcp/autowhisper-mcp#diagnostics

## Score history

- 2026-08-04: 34
- 2026-08-03: 35
- 2026-08-02: 35
- 2026-08-01: 5
- 2026-07-31: 5
- 2026-07-30: 6
- 2026-07-28: 6
- 2026-07-27: 47

## Links

- npm package: https://www.npmjs.com/package/autowhisper-mcp
- Socket report: https://socket.dev/npm/package/autowhisper-mcp
- Repository: https://github.com/xnjiang/autowhisper-mcp
- Website: https://autowhisper.xyz/skill
- Changelog RSS feed: https://verifymcp.io/servers/xnjiang-autowhisper-mcp/autowhisper-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/xnjiang-autowhisper-mcp/autowhisper-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/xnjiang-autowhisper-mcp/autowhisper-mcp
