
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@markaestro/mcp
Advanced tools
Model Context Protocol server that lets AI agents schedule, publish, and review Markaestro posts through the public API
A Model Context Protocol server that lets AI agents (Claude Code, Claude Desktop, Cursor, and any other MCP client) schedule, publish, and review Markaestro posts through the public API.
One API key, one brand: every Markaestro key is bound to a single brand, so the server operates on that brand only. Run one server per brand if an agent needs several.
| Tool | What it does |
|---|---|
list_products | The brand this key is bound to and its connected channels |
list_destinations | Publishable destinations of the brand (pages, accounts) with ids |
list_posts, get_post | Read posts by status, page through with cursor |
create_post | Save a draft, or schedule when scheduledAt is set |
publish_post | Queue an immediate publish; returns a job run |
delete_post | Delete a draft or cancel a scheduled post |
bulk_posts | Reschedule, delete, or restatus up to 25 posts |
create_posts | Up to 25 posts in one call, per-item results |
upload_media | Upload from a file path, URL, or data URL; returns the asset id |
list_media, get_media | Uploaded assets, processing state, reference counts |
get_job_run, list_job_runs | Follow a publish to succeeded or failed |
list_webhook_endpoints, create_webhook_endpoint | Webhook registration |
get_channel_rules | Per-channel media, caption, and delivery-mode rules |
Also served: the markaestro://channel-rules resource and a schedule_post
prompt that walks an agent through a safe scheduling flow.
Posting is draft-first. create_post without scheduledAt never publishes;
publish_post is the only tool that publishes now, and its description tells
the agent to confirm with the user first.
Hosted (nothing to install). Markaestro serves the same tools over
Streamable HTTP at https://markaestro.com/api/public/v1/mcp, authenticated
with the API key as a bearer header:
claude mcp add --transport http markaestro https://markaestro.com/api/public/v1/mcp \
--header "Authorization: Bearer mk_live_..."
{
"mcpServers": {
"markaestro": {
"type": "http",
"url": "https://markaestro.com/api/public/v1/mcp",
"headers": { "Authorization": "Bearer mk_live_..." }
}
}
}
Send x-markaestro-read-only: 1 as an extra header to get only the reading
tools.
Local package. Run the server on your machine over stdio, which also
lets upload_media read local files:
products.read, posts.read, posts.write,
media.write, and posts.publish if it may publish), and prefer a test
key while you evaluate.MARKAESTRO_API_KEY.claude mcp add markaestro -e MARKAESTRO_API_KEY=mk_live_... -- npx -y @markaestro/mcp
{
"mcpServers": {
"markaestro": {
"command": "npx",
"args": ["-y", "@markaestro/mcp"],
"env": { "MARKAESTRO_API_KEY": "mk_live_..." }
}
}
}
| Variable | Required | Default |
|---|---|---|
MARKAESTRO_API_KEY | yes | n/a |
MARKAESTRO_BASE_URL | no | https://markaestro.com |
MARKAESTRO_READ_ONLY | no | unset; 1 registers only reading tools |
Idempotency-Key on every mutation, minted once per call, so a
retried request replays instead of double-posting.429 and transient 5xx responses using the server's Retry-After.PUT to storage,
finalize) and never sends the API key to the storage URL.code, any
per-channel issues, and a hint about what to change.The skill and the hosted server ship together as a plugin:
claude plugin marketplace add D3vBaba/Markaestro
claude plugin install markaestro@markaestro
| Surface | How it ships |
|---|---|
Hosted MCP (/api/public/v1/mcp) | Part of the Next.js app; deploys on push to main like every route |
@markaestro/mcp on npm | cd mcp && npm version <x.y.z> && npm publish (public scoped package; prepublishOnly builds). Bump src/version.ts with it |
| Plugin and skill | Read straight from this repository by claude plugin marketplace add D3vBaba/Markaestro; the skill alone can be copied to ~/.claude/skills/markaestro |
cd mcp
npm install
npm run build
MARKAESTRO_API_KEY=mk_test_... MARKAESTRO_BASE_URL=http://localhost:3000 npm run smoke # local stdio
MARKAESTRO_API_KEY=mk_test_... MARKAESTRO_BASE_URL=http://localhost:3000 npm run smoke -- --remote # hosted endpoint
Unit tests live in src/__tests__ and run with the repository's npm test.
The smoke script starts the built server over stdio, lists tools, reads the
brand, creates a draft, reads it back, and deletes it. Nothing is published.
FAQs
Model Context Protocol server that lets AI agents schedule, publish, and review Markaestro posts through the public API
The npm package @markaestro/mcp receives a total of 72 weekly downloads. As such, @markaestro/mcp popularity was classified as not popular.
We found that @markaestro/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.