Postforme Mcp Pro — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Postforme Mcp Pro (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The most complete Post for Me MCP server — publish, schedule, edit, delete and analyze social posts across 9 platforms from any MCP client.
postforme-mcp-pro wraps the Post for Me API in 27+ fully-typed MCP tools (one per operation) plus a postforme_raw escape hatch and a readonly safety mode. Unlike the official MCP — which exposes only a doc-search + sandboxed code-execution tool ("code mode") — every operation here is a first-class, directly-callable tool, so the model can post, schedule and pull analytics without writing SDK code.
Platforms: Instagram · Facebook · TikTok · YouTube · X · LinkedIn · Pinterest · Bluesky · Threads
create_post, schedule_post, publish_now, create_draft, upload_media, list_account_feeds, list_post_results, account & webhook management, and more.publish_now / schedule_post / create_draft / reschedule_post / upload_media collapse common multi-step flows into one call.upload_media takes a local file path or a public URL, gets a signed URL, uploads the bytes, and hands back a media_url ready to attach.platform_configurations models Instagram Reels, X polls, TikTok privacy, YouTube visibility, etc., and stays permissive for new options.POSTFORME_READONLY=true blocks every write; great for analytics-only sessions.npm install
npm run buildOr run published (after release) without cloning:
npx -y postforme-mcp-proCopy .env.example → .env and set your key:
| Variable | Required | Description |
|---|---|---|
POSTFORME_API_KEY | ✅ | Your Post for Me API key (Dashboard → Settings → API Keys). |
POSTFORME_BASE_URL | — | Override the API base URL for self-hosted/open-source deployments. Default https://api.postforme.dev. |
POSTFORME_READONLY | — | true blocks all write tools (only reads + postforme_raw GET run). |
POSTFORME_DISABLE_RAW | — | true removes the postforme_raw tool. |
POSTFORME_TIMEOUT_MS | — | Per-request timeout (default 60000). |
POSTFORME_MAX_RETRIES | — | Max retries on 429/5xx/network (default 3). |
npx @modelcontextprotocol/inspector node dist/index.js.claude/settings.json → mcpServers:
"postforme": {
"command": "node",
"args": ["projects/postforme-mcp-pro/dist/index.js"],
"env": { "POSTFORME_API_KEY": "pfm_xxx" }
}%APPDATA%\Claude\claude_desktop_config.json (Windows) / ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):
"postforme": {
"command": "node",
"args": ["/abs/path/projects/postforme-mcp-pro/dist/index.js"],
"env": { "POSTFORME_API_KEY": "pfm_xxx" }
}Cursor uses the same config shape in its MCP file.
| Tool | Description |
|---|---|
list_social_accounts | List connected accounts (filter by platform/username). |
get_social_account | Get one account by id. |
create_social_account | Connect an account by supplying credentials. |
update_social_account | Update stored credentials/metadata. |
create_auth_url | Start the OAuth connect flow (returns a URL). |
disconnect_social_account | Revoke access for an account. |
list_account_feeds | Analytics: recent feed + engagement metrics for an account. |
| Tool | Description |
|---|---|
create_post | Create a post (publish now, schedule, or draft) across accounts. |
publish_now | Shortcut: publish immediately. |
schedule_post | Shortcut: schedule for an ISO-8601 time. |
create_draft | Shortcut: save as draft. |
get_post | Get a post by id. |
list_posts | List posts (filter by status). |
update_post | Edit caption/media/accounts/schedule/config. |
reschedule_post | Shortcut: change a scheduled time. |
delete_post | Delete a post. |
| Tool | Description |
|---|---|
list_post_results | Analytics: per-platform publish outcomes. |
get_post_result | One post result by id. |
create_post_preview | Preview how a post renders per platform. |
| Tool | Description |
|---|---|
create_media_upload_url | Get a signed upload URL (2-step flow). |
upload_media | One-step: upload a local file or remote URL → returns media_url. |
| Tool | Description |
|---|---|
list_webhooks · get_webhook · create_webhook · update_webhook · delete_webhook | Manage event subscriptions. |
| Tool | Description |
|---|---|
postforme_raw | Call any /v1/... endpoint directly (method, path, params, body). |
/postforme (in skill/SKILL.md) orchestrates these tools into guided workflows: post, schedule, campaign, analytics, accounts, media. Copy it into .claude/skills/ to use it in Claude Code.
You: post "Lançamos a v2 🚀" no instagram e no x, com a imagem ./hero.png
→ list_social_accounts (get the instagram + x account ids)
→ upload_media { file_path: "./hero.png" } → media_url
→ create_post_preview (optional, confirm look)
→ publish_now { social_accounts: [...], caption: "...", media: [{ url: media_url }] }
→ list_post_results (report success/links per platform)| postforme-mcp-pro | official post-for-me-mcp | |
|---|---|---|
| Tool model | 27 typed tools, one per operation | 2 tools (doc-search + code-execution sandbox) |
| Calls | Direct tool calls | Model must write SDK code in a sandbox |
| Shortcuts | publish_now / schedule_post / create_draft / upload_media | — |
| Safety | POSTFORME_READONLY mode + SSRF/file-read hardening | — |
| Escape hatch | postforme_raw (any /v1 endpoint) | code execution |
| Companion skill | /postforme guided workflows | — |
upload_media hardens remote fetches against SSRF (DNS resolution + public-unicast IP validation, no redirects, size cap) and restricts local file reads to recognized media extensions (optionally to POSTFORME_MEDIA_DIR). postforme_raw paths are validated to stay on the versioned API surface. See REVIEW.md for the full audit.
MIT © Helbert Paranhos / Strat Academy
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.