Postoria Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Postoria Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Postoria MCP Server connects MCP-compatible AI clients to Postoria.
Use it to list workspaces, find social accounts and queues, upload or import media, publish posts, schedule posts, add posts to queues, check post status, and delete posts.
npx -y @postoria/mcp-serverstdio transport for desktop and IDE MCP clientsserver.json| Tool | Description |
|---|---|
list_workspaces | List available Postoria workspaces |
list_social_accounts | List social accounts in a workspace |
list_queues | List queues in a workspace |
create_media_upload | Create a signed media upload URL |
complete_media_upload | Complete a media upload after raw bytes are uploaded |
upload_media_from_file | Upload a local file from stdio clients |
import_media_from_url | Import media from a public URL |
get_media | Get media status and details |
publish_post_now | Publish a post immediately |
schedule_post | Schedule a post for a specific time |
add_post_to_queue | Add a post to a Postoria queue |
get_post | Get post status and details |
delete_post | Delete a post created through the Public API |
upload_media_from_file is available only in local stdio mode. It is not exposed through the hosted Streamable HTTP endpoint.
Add this to your MCP client configuration:
{
"mcpServers": {
"postoria": {
"command": "npx",
"args": ["-y", "@postoria/mcp-server"],
"env": {
"POSTORIA_API_KEY": "ptr_your_api_key_here"
}
}
}
}Hosted endpoint:
https://mcp.postoria.io/mcpSend your Postoria API key as a Bearer token:
Authorization: Bearer ptr_your_api_key_hereUse import_media_from_url when the media is already available through a public URL.
Use create_media_upload when the client will upload raw file bytes to the returned signed upload URL. After the raw bytes are uploaded with PUT, call complete_media_upload.
Use upload_media_from_file in local stdio mode when the media file exists on the same machine where the MCP server is running.
npm install
npm run buildRun in local stdio mode:
POSTORIA_API_KEY=ptr_your_api_key_here npm run dev:stdioRun in local HTTP mode:
npm run dev:httpHTTP mode requires the MCP client to send the Postoria API key in the Authorization header. POSTORIA_API_KEY is used by local stdio mode only.
Local HTTP endpoint:
http://localhost:3000/mcpHealth check:
http://localhost:3000/healthserver.json includes distribution metadata for:
https://mcp.postoria.io/mcp@postoria/mcp-serverPOSTORIA_API_KEY from the environment.Authorization: Bearer <api_key> on MCP initialization.POSTORIA_API_KEY is used by local stdio mode only.delete_post is destructive and should only be called after user confirmation.npm install
npm run typecheck
npm run build
npm run format:check~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.