instagram — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited instagram (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Complete skill for managing Instagram professional accounts through the Instagram API with Instagram Login (Business Login). Covers content publishing, messaging, comment moderation, insights, and profile management.
| Request | Send them to |
|---|---|
| Paid Instagram / Facebook ads, boosting a post, Advantage+ | meta-ads |
| Competitor ad research from the Meta Ad Library | meta-ads-library |
| TikTok publishing | tiktok |
| LinkedIn document or carousel posts | linkedin |
If instagram_get_me is not in the tool list, stop and tell the user to enable Hyper MCP and connect Instagram.
| Tool group | Tools |
|---|---|
| Account | instagram_get_me, instagram_get_user (look up any public IG profile by username or ID — useful for researching commenters and DM contacts) |
| Publishing | instagram_create_photo_container, instagram_create_reel_container, instagram_create_carousel_container, instagram_check_container_status, instagram_publish_media, instagram_check_publishing_limit |
| Media library | instagram_list_media, instagram_get_media, instagram_get_album_children, instagram_list_stories, instagram_get_tagged_media |
| Comments | instagram_list_comments, instagram_post_comment, instagram_reply_to_comment, instagram_hide_comment, instagram_delete_comment, instagram_toggle_comments |
| Direct Messages | instagram_list_conversations, instagram_get_conversation_messages, instagram_get_message, instagram_send_message, instagram_send_media_message, instagram_send_post_message, instagram_react_to_message |
| Insights | instagram_get_account_insights, instagram_get_media_insights |
CRITICAL: This toolkit uses the Instagram API with Instagram Login (not the older Instagram Graph API via Facebook Login). Metric names and available fields differ from the older API. Always use the metric names documented in this skill.
CRITICAL: Theengagementmetric does NOT exist in this API. Use individual metrics likelikes,comments,shares,total_interactionsinstead.
CRITICAL: Theimpressionsmetric is NOT valid for account-level insights. Usereachorviewsinstead.
CRITICAL: Content publishing uses a two-step container workflow: (1) create a media container, (2) publish it. For video content, poll the container status until FINISHED before publishing.CRITICAL: Instagram DM responses must be sent within 24 hours of the user's last message (standard messaging window). The Human Agent tag extends this to 7 days if approved.
IMPORTANT: Publishing rate limit is 100 API-published posts per 24-hour rolling window. Carousels count as 1 post. Always call instagram_check_publishing_limit before bulk publishing.CRITICAL: Do NOT use thelocation_idparameter on photo, reel, or carousel containers unless the user explicitly provides a verified Facebook Page ID. This integration uses Instagram Business Login which cannot look up or validate location IDs. Passing an invalid or guessed ID will cause a 400 error (Param location_id is not a valid location page ID). If a user asks for location tagging, explain that they need to provide their Facebook Page ID with location data.
CRITICAL: When passing media URLs (image_url,video_url,cover_url,media_url) to any Instagram tool, use the URL exactly as returned by the source tool — most commonly theurlfield fromread_fileordisplay_file. Do NOT: - Reconstruct or shorten the URL. - Drop, change, or invent any query parameters (signatures, timestamps, etc.). - Substitute a different host. - Copy a URL from memory or transcribe it character-by-character — callread_fileagain instead.
>
Hyper-hosted CDN URLs are automatically resized and re-signed for Meta when needed, so just hand them through verbatim. A single-character corruption in a presigned signature causes Meta to return a misleading 9004 / 2207052: Only photo or video can be accepted as media type error.IMPORTANT: Always call instagram_get_me first to get the user's IG user ID. Most endpoints require this ID.instagram_get_me()Returns: user_id, username, name, account_type, profile_picture_url, followers_count, follows_count, media_count, biography, website.
Store the user_id — it's required for most subsequent calls.
FINISHED).instagram_create_photo_container(
user_id="<user_id>",
image_url="https://example.com/photo.jpg", # Public JPEG URL, max 8MB
caption="Your caption here #hashtag",
alt_text="Accessibility description",
)
# Returns container ID
instagram_publish_media(
user_id="<user_id>",
creation_id="<container_id>",
)instagram_create_reel_container(
user_id="<user_id>",
video_url="https://example.com/video.mp4", # Public MP4/MOV, max 300MB, 3s-15min
caption="Reel caption #reels",
cover_url="https://example.com/cover.jpg", # Optional cover image
share_to_feed=True,
)
# MUST poll status for video content
instagram_check_container_status(container_id="<container_id>")
# Wait until status_code == "FINISHED", poll once per minute, max 5 minutes
instagram_publish_media(user_id="<user_id>", creation_id="<container_id>")Note: Story publishing is not yet supported by this MCP integration. To read currently active stories use:
>
``python instagram_list_stories(user_id="<user_id>") ``>
If the user asks to post a story, inform them this capability is not yet available and suggest posting a Reel with share_to_feed=True as an alternative.# Step 1: create child containers (each with is_carousel_item=True for photos)
instagram_create_photo_container(
user_id="<user_id>",
image_url="https://example.com/photo1.jpg",
is_carousel_item=True,
)
# Repeat for each image / video
# Step 2: create the carousel container with child IDs
instagram_create_carousel_container(
user_id="<user_id>",
children=["<child_id_1>", "<child_id_2>", "<child_id_3>"],
caption="Carousel caption",
)
# Step 3: publish
instagram_publish_media(user_id="<user_id>", creation_id="<carousel_container_id>")| Type | Format | Max size | Duration |
|---|---|---|---|
| Photo | JPEG | 8MB | — |
| Reel | MP4 / MOV | 300MB | 3s – 15min |
| Story image | JPEG | 8MB | — |
| Story video | MP4 / MOV | 100MB | 3s – 60s |
| Caption | Text | 2200 chars | 30 hashtags, 20 @tags |
| Carousel | Mixed | 2 – 10 items | — |
instagram_list_comments(media_id="<media_id>")instagram_post_comment(media_id="<media_id>", message="Great post!")instagram_reply_to_comment(comment_id="<comment_id>", message="Thanks!")# Hide spam / inappropriate comments
instagram_hide_comment(comment_id="<comment_id>", hide=True)
# Delete a comment (only the media owner can delete)
instagram_delete_comment(comment_id="<comment_id>")
# Toggle comments on / off for a post
instagram_toggle_comments(media_id="<media_id>", comment_enabled=False)Note: Mention-specific tools (instagram_reply_to_mention,instagram_get_mentioned_media,instagram_get_mentioned_comment) are not yet available in this MCP integration. Mentions appear as comments on your media — respond to them usinginstagram_reply_to_commentwith the comment ID frominstagram_list_comments.
instagram_list_conversations(user_id="<user_id>")# Get message IDs from a conversation
instagram_get_conversation_messages(conversation_id="<conversation_id>")
# Get full message details (only 20 most recent are queryable)
instagram_get_message(message_id="<message_id>")# Text message
instagram_send_message(
user_id="<user_id>",
recipient_id="<recipient_igsid>", # From the message's 'from' field
text="Thanks for reaching out!",
)
# Media attachment (image, video, audio, PDF)
instagram_send_media_message(
user_id="<user_id>",
recipient_id="<recipient_igsid>",
media_type="image", # image, video, audio, or file
media_url="https://example.com/photo.jpg",
)
# Share a published post via DM
instagram_send_post_message(
user_id="<user_id>",
recipient_id="<recipient_igsid>",
post_id="<media_id>", # Must be your own post
)
# React to a message
instagram_react_to_message(
user_id="<user_id>",
recipient_id="<recipient_igsid>",
message_id="<message_id>",
reaction="love",
)instagram_get_account_insights(
user_id="<user_id>",
metric=["reach", "profile_views", "follower_count", "accounts_engaged", "total_interactions"],
period="week",
)Note: Some metrics (profile_views,total_interactions, demographic metrics) requireinstagram_business_manage_insightspermission and a Business account — they will be silently omitted for Creator accounts. If a metric is missing from the response, check the account type returned byinstagram_get_me.
Valid account metrics:
| Metric | Description |
|---|---|
reach | Unique accounts that saw any content. |
follower_count | Total followers (lifetime period only). |
website_clicks | Clicks on the website link in the profile. |
profile_views | Profile page views. |
online_followers | Followers online at a given time. |
accounts_engaged | Unique accounts that interacted. |
total_interactions | Total likes, comments, shares, saves, replies. |
likes | Total likes across all content. |
comments | Total comments across all content. |
shares | Total shares across all content. |
saves | Total saves across all content. |
replies | Total replies (stories / messages). |
follows_and_unfollows | Net follower changes. |
profile_links_taps | Taps on profile links. |
views | Total content views. |
engaged_audience_demographics | Demographics of the engaged audience. |
reached_audience_demographics | Demographics of the reached audience. |
follower_demographics | Demographics of followers. |
Invalid account metrics: impressions, email_contacts, phone_call_clicks, text_message_clicks, get_directions_clicks.
instagram_get_media_insights(
media_id="<media_id>",
metric=["reach", "likes", "comments", "saved", "shares", "total_interactions"],
)reach, saved, likes, comments, shares, total_interactions, views.ig_reels_avg_watch_time, ig_reels_video_view_total_time, clips_replays_count, ig_reels_aggregated_all_plays_count.reach, replies, follows, navigation, profile_visits, profile_activity, views.Tip: When unsure if media is a Reel, just use the common metrics. Reel-only metrics sent to non-Reel media will be auto-stripped by the server.
Invalid media metrics: engagement, impressions, plays, saves — for media use saved (not saves; saves is account-level only).
| Period | Description |
|---|---|
day | Daily breakdown. |
week | Weekly breakdown. |
days_28 | 28-day breakdown. |
month | Monthly breakdown. |
lifetime | All time (required for follower_count). |
# List recent posts (up to 10K)
instagram_list_media(user_id="<user_id>", limit=25)
# Get details of a specific post
instagram_get_media(media_id="<media_id>")
# Get carousel children
instagram_get_album_children(media_id="<carousel_media_id>")
# List active stories (24h window)
instagram_list_stories(user_id="<user_id>")
# Get tagged media
instagram_get_tagged_media(user_id="<user_id>")~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.