
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@chirpie/mcp
Advanced tools
Post, schedule, and track social posts on X, Bluesky, LinkedIn, Instagram and more from AI agents.
Post, schedule, and track social posts on X, Bluesky, LinkedIn, Instagram and more from AI agents. Chirpie is one API for X/Twitter, Bluesky, LinkedIn, Threads, Mastodon, Instagram, Facebook and Telegram, covering posting, threads, scheduling, deletion and analytics. This MCP server puts all of it in front of Claude, Cursor, ChatGPT or any other MCP-capable agent, so "post this to X and LinkedIn, and schedule the follow-up for 9am" is a single sentence rather than a pile of platform SDKs, OAuth dances and rate-limit handling.
You don't need to install anything. Point your client at:
https://chirpie.ai/mcp
Sign in when prompted and you're connected. No API key to copy, nothing to keep up to date.
Claude Code
claude mcp add --transport http chirpie https://chirpie.ai/mcp
Claude: Settings → Connectors → Add custom connector → https://chirpie.ai/mcp
Cursor: add to .cursor/mcp.json:
{
"mcpServers": {
"chirpie": {
"url": "https://chirpie.ai/mcp"
}
}
}
ChatGPT: Settings → Connectors → Create → MCP server → https://chirpie.ai/mcp
Prefer a key over OAuth (CI, scripts, clients without an OAuth flow)? Send it as a header:
{
"mcpServers": {
"chirpie": {
"type": "http",
"url": "https://chirpie.ai/mcp",
"headers": { "Authorization": "Bearer chirpie_sk_your_key_here" }
}
}
}
Run the same tool set locally over stdio.
npm install -g chirpie
chirpie login
Claude Code
claude mcp add chirpie -- npx @chirpie/mcp
Claude Desktop: ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"chirpie": {
"command": "npx",
"args": ["@chirpie/mcp"]
}
}
}
Cursor: add to your MCP settings:
{
"mcpServers": {
"chirpie": {
"command": "npx",
"args": ["@chirpie/mcp"]
}
}
}
The local server resolves credentials in this order:
CHIRPIE_API_KEY environment variable~/.chirpie/config.json (written by chirpie login)The CLI and this server share that config, so one chirpie login covers both.
| Tool | What it does |
|---|---|
chirpie_post | Post to any connected account, now or scheduled |
chirpie_thread | Post a 2–25 part thread |
chirpie_list_posts | List posts, filtered by status or account |
chirpie_get_post | Fetch one post |
chirpie_update_post | Edit a post that has not published yet: text, media, or time |
chirpie_delete_post | Delete a post (and remove it from the platform) |
chirpie_list_accounts | List connected social accounts, active and inactive |
chirpie_activate_account | Activate an account so it can publish |
chirpie_deactivate_account | Deactivate an account (stays connected, frees a plan slot) |
chirpie_disconnect_account | Disconnect an account (ends the connection, cancels its scheduled posts, frees a plan slot) |
chirpie_analytics | Engagement metrics for a published post |
chirpie_create_key | Create an API key |
chirpie_list_keys | List API keys |
chirpie_revoke_key | Revoke an API key |
chirpie_connect_x | Connect X/Twitter (returns an authorization link) |
chirpie_connect_linkedin | Connect a LinkedIn profile |
chirpie_connect_linkedin_pages | Connect the LinkedIn Pages you administer (coming soon) |
chirpie_connect_threads | Connect Threads (coming soon) |
chirpie_connect_instagram | Connect Instagram (coming soon) |
chirpie_connect_facebook | Connect a Facebook Page (coming soon) |
chirpie_connect_bluesky | Connect Bluesky with an app password |
chirpie_connect_mastodon | Connect Mastodon on any instance |
chirpie_connect_telegram | Connect a Telegram bot |
chirpie_set_x_keys | Register your own X developer app for connecting X accounts |
chirpie_get_x_keys_status | Check whether your own X developer app is configured |
chirpie_remove_x_keys | Remove your own X developer app |
The hosted and local servers expose exactly the same tools. On the hosted server,
chirpie_create_key, chirpie_list_keys, chirpie_revoke_key and
chirpie_remove_x_keys require API-key auth. Sign in with OAuth and they are not
offered, since an OAuth connection must not leave a long-lived key behind or tear
down credentials your other connections depend on.
Once connected, ask your agent:
MIT © Fireflo LLC
FAQs
Post, schedule, and track social posts on X, Bluesky, LinkedIn, Instagram and more from AI agents.
The npm package @chirpie/mcp receives a total of 2,014 weekly downloads. As such, @chirpie/mcp popularity was classified as popular.
We found that @chirpie/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.