vibo-mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited vibo-mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for Vibo (vibodj.com) — plan your event music as a host/couple. Browse your events and timeline, see and add song requests, like songs, manage notifications, and export selections to Spotify/Apple Music, all via natural language.
Developed and maintained by AI (Claude Code). Use at your own discretion. Unofficial — not affiliated with Vibo. Works only with your own account/data.
{
"mcpServers": {
"vibo": {
"command": "npx",
"args": ["-y", "vibo-mcp"],
"env": {
"VIBO_EMAIL": "[email protected]",
"VIBO_PASSWORD": "your_password"
}
}
}
}Choose one method:
| Method | Env vars | When |
|---|---|---|
| Email + password (recommended) | VIBO_EMAIL, VIBO_PASSWORD | You sign in to Vibo with an email/password. |
| Captured token | VIBO_ACCESS_TOKEN (+ VIBO_REFRESH_TOKEN) | Your account uses Apple/Google/Facebook sign-in (no password). Capture x-token/x-refresh-token from a signed-in web.vibodj.com session. |
| Browser capture (SSO) | run vibo_capture_session | With the fetchproxy browser extension installed and signed into web.vibodj.com, capture the token automatically (saved to ~/.vibo-mcp/session.json). |
The server boots without credentials; the config error only surfaces on the first tool call.
Vibo's app talks to a GraphQL API at https://api.vibodj.com/v2/graphql, authenticating with an x-token header obtained from an email/password signIn. This server reuses that same flow server-side (no browser needed) and wraps the host/couple operations as MCP tools. Every mutating tool is confirm-gated: without confirm: true it returns a dry-run preview and makes no network call.
See docs/VIBO-API.md for the reverse-engineered API notes and SKILL.md for the full tool list.
npm install
npm run build # tsc + esbuild bundle → dist/
npm test # vitestMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.