
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@stophy/mcp
Advanced tools
YouTube data for AI agents. MCP server that gives AI agents YouTube transcripts, comments, search, and channels as structured JSON.
YouTube data for AI agents. Transcripts, comments, search, channels, playlists — all as structured JSON through the Model Context Protocol.
Two ways. Pick one.
Give your MCP client this URL. Your API key goes in the path.
https://mcp.stophy.dev/$STOPHY_API_KEY/mcp
MCP client config:
{
"mcpServers": {
"stophy": {
"url": "https://mcp.stophy.dev/$STOPHY_API_KEY/mcp"
}
}
}
No install. No Node.js. Works anywhere that speaks HTTP MCP.
Get an API key at stophy.dev/dashboard.
Your MCP client runs @stophy/mcp as a local process. The API key goes in the environment.
env STOPHY_API_KEY=$STOPHY_API_KEY npx -y @stophy/mcp
Or install it once:
npm install -g @stophy/mcp
env STOPHY_API_KEY=$STOPHY_API_KEY stophy-mcp
Pick your MCP client.
File: claude_desktop_config.json
~/Library/Application Support/Claude/%APPDATA%\Claude\{
"mcpServers": {
"stophy": {
"command": "npx",
"args": ["-y", "@stophy/mcp"],
"env": {
"STOPHY_API_KEY": "your_api_key_here"
}
}
}
}
If Claude Desktop says spawn npx ENOENT, Node.js is missing from PATH. Install the LTS from nodejs.org and restart Claude Desktop completely.
Stdio:
claude mcp add stophy -e STOPHY_API_KEY=$STOPHY_API_KEY -- npx -y @stophy/mcp
HTTP (if your Claude Code version supports remote MCP):
claude mcp add --transport http stophy https://mcp.stophy.dev/$STOPHY_API_KEY/mcp
File: .cursor/mcp.json (per project) or ~/.cursor/mcp.json (global)
{
"mcpServers": {
"stophy": {
"command": "npx",
"args": ["-y", "@stophy/mcp"],
"env": {
"STOPHY_API_KEY": "$STOPHY_API_KEY"
}
}
}
}
File: ~/.codeium/windsurf/mcp_config.json
{
"mcpServers": {
"stophy": {
"command": "npx",
"args": ["-y", "@stophy/mcp"],
"env": {
"STOPHY_API_KEY": "$STOPHY_API_KEY"
}
}
}
}
Add to config.yaml under mcp_servers:
mcp_servers:
- name: stophy
command: npx
args: ["-y", "@stophy/mcp"]
env:
STOPHY_API_KEY: your_api_key_here
If your client takes a command + args + env block, use the pattern above. If it takes a URL, use the hosted endpoint.
Six tools. Each call costs one credit except stophy_get_credits which is free.
| Tool | What it does |
|---|---|
stophy_search_videos | Search YouTube by keyword. Returns videos, channels, playlists, or Shorts with pagination. |
stophy_get_video | Get details, transcript, comments, comment replies, or live chat for one video. |
stophy_get_channel | Browse a channel's videos, Shorts, playlists, or about page. |
stophy_get_playlist | Fetch every video in a playlist. |
stophy_get_suggestions | YouTube autocomplete for a partial query. |
stophy_get_credits | Your remaining credit balance. Free. |
Search YouTube. Use this to discover videos on a topic or find recent uploads. Not for fetching a specific video you already have the URL for — use stophy_get_video instead.
Arguments:
q (required): what to search fortype: "video", "short", "channel", or "playlist"uploadDate: "hour", "today", "week", "month", or "year"duration: "short", "medium", or "long"sortBy: "relevance", "popularity", "date", or "rating"continuationToken: token from previous response for the next page{
"q": "typescript tutorial",
"uploadDate": "week",
"type": "video"
}
Returns items[] and an optional continuationToken.
Get details, transcript, comments, comment replies, or live chat for a known video.
Arguments:
videoUrl (required): YouTube video URL or IDtype (required): "details", "transcript", "comments", or "livechat"sortBy: "top" or "latest" for commentschatType: "top" or "live" for live chatcontinuationToken: next page of comments, or a comment's repliesToken for repliesTranscript:
{
"videoUrl": "https://youtube.com/watch?v=d56mG7DezGs",
"type": "transcript"
}
Comments:
{
"videoUrl": "https://youtube.com/watch?v=d56mG7DezGs",
"type": "comments",
"sortBy": "top"
}
For comment replies, call again with type: "comments" and set continuationToken to the comment's repliesToken.
Browse a channel.
Arguments:
channelUrl (required): channel URL, handle (@username), or channel IDtab: "video", "short", "playlist", or "about" (default: "video")sortBy: "latest", "popular", or "oldest" for the video tabcontinuationToken: next page{
"channelUrl": "https://youtube.com/@t3dotgg",
"tab": "video",
"sortBy": "latest"
}
The about tab returns the channel's country, join date, view count, and links.
All videos in a playlist.
Arguments:
playlistUrl (required): playlist URL or IDcontinuationToken: next page{
"playlistUrl": "https://youtube.com/playlist?list=PLTjRvDozrdlxEIuOBZkMAK5uiqp8rHUax"
}
YouTube autocomplete. Good for topic discovery and query expansion.
Arguments:
q (required): partial queryhl: language code, default engl: region code, default US{
"q": "react hooks",
"hl": "en",
"gl": "US"
}
Any tool that returns continuationToken supports pagination. Pass the token back with the same arguments to get the next page. A missing or null token means you've reached the end.
When a video has no transcript, comments are off, or a comment has no replies, Stophy returns an empty object:
{
"empty": {
"code": "EMPTY_TRANSCRIPT_SEGMENTS",
"message": "No transcript segments found."
}
}
Possible codes: EMPTY_TRANSCRIPT_SEGMENTS, EMPTY_COMMENTS, EMPTY_COMMENT_REPLIES.
Errors come back as text in the MCP tool response:
Stophy error (UNAUTHORIZED): Invalid API key.
Stophy error (MISSING_API_KEY): No Stophy API key provided. Set STOPHY_API_KEY (stdio) or include your key in the URL path (hosted). Get a key at https://stophy.dev/dashboard.
| Variable | Required | What it is |
|---|---|---|
STOPHY_API_KEY | Stdio only | Your Stophy API key. Not needed for hosted — the key is in the URL path. |
FAQs
One API for live, structured web data. REST, MCP, SDK and CLI.
The npm package @stophy/mcp receives a total of 885 weekly downloads. As such, @stophy/mcp popularity was classified as not popular.
We found that @stophy/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.