← Index

io.github.dewtech-technologies/tubemind-secure-mcp

io.github.dewtech-technologies/tubemind-secure-mcp·v0.1.3·Other

Secure MCP server for YouTube intelligence — 18 tools, OAuth2, OWASP Top 10 controls.

Trust verdict · v1 advisory · method
NOT YET SCREENEDno verdict on file

Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.

Own this server? Screen its description →

Environment variables
YOUTUBE_CLIENT_ID
required

Google OAuth2 Client ID for YouTube Data API v3 + Analytics API

YOUTUBE_CLIENT_SECRET
requiredsecret

Google OAuth2 Client Secret

YOUTUBE_REDIRECT_URI

OAuth2 redirect URI (must match Google Cloud Console)

TOKEN_ENCRYPTION_KEY
requiredsecret

64-char hex key for AES-256-GCM token encryption at rest. Generate with: openssl rand -hex 32

RATE_LIMIT_PER_MINUTE

Max tool invocations per minute

REQUEST_TIMEOUT_MS

HTTP request timeout (ms)

AUDIT_LOG_PATH

Path to the audit log file

NODE_ENV

production | development

MCP quality score · maturity, not trust · methodology
freshness
24
completeness
10
installability
25
documentation
15
stability
5
Alternatives in Other