
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
planvortex-mcp
Advanced tools
Official MCP server for PlanVortex: let your AI assistant schedule posts, read the comment inbox and reply to messages across eleven social networks.
The official Model Context Protocol server for PlanVortex. It lets an AI assistant — Claude Desktop, Claude Code, Cursor, VS Code — schedule posts, read the comment inbox and answer private messages across eleven social networks: Facebook, Instagram, LinkedIn, TikTok, X, WhatsApp, YouTube, Google Business, Bluesky, Discord and Telegram.
You need a PlanVortex app, and apps are part of the Custom plan. The server authenticates with a
client_idand aclient_secretthat you create in the PlanVortex panel under Settings → Apps. On any other plan those credentials cannot be created, and this server has nothing to connect with.
Nothing to install: your MCP client starts it with npx.
{
"mcpServers": {
"planvortex": {
"command": "npx",
"args": ["-y", "planvortex-mcp"],
"env": {
"PLANVORTEX_CLIENT_ID": "...",
"PLANVORTEX_CLIENT_SECRET": "...",
"PLANVORTEX_ORGANIZATION_ID": "optional, but saves a call per conversation"
}
}
}
}
claude mcp add planvortex \
--env PLANVORTEX_CLIENT_ID=... \
--env PLANVORTEX_CLIENT_SECRET=... \
-- npx -y planvortex-mcp
Then ask for something: "what do I have scheduled this week, and which comments are still unread?"
Twenty-five tools, grouped by what they act on.
| Group | Tools |
|---|---|
| Context | list_organizations, list_accounts, get_plan_use, get_unread_counts |
| Publishing | list_publications, get_publication, create_publication, update_publication, retry_publication |
| Media | upload_media |
| Comments | list_comments, get_comment_thread, reply_to_comment, hide_comment, mark_comment_read |
| Messages | list_conversations, list_messages, send_message |
| Numbers | get_dashboard_summary, get_publication_stats, get_top_publications, get_account_metrics |
| Catalog | get_social_limits, get_social_capabilities, create_connect_link |
Plus three prompts — weekly_plan, inbox_triage, publish_from_brief — and four resources with
the per-network limits, capabilities, comment matrix and your organizations.
It never deletes anything. No tool removes a post, an account, a contact or a comment. This is not a switch you can turn on; the code is not there. The reason is in the security section below.
It cannot connect a social account. Connecting Instagram is an OAuth flow with a person clicking
"authorize" on Meta's own screen, and an app with client credentials cannot do that — nobody's app
can. create_connect_link returns a single-use link that expires in fifteen minutes; hand it to the
user and let them open it.
This server runs on your machine with your app's client_secret inside the process, and it feeds a
language model text that members of the public wrote — comments, reviews, DMs — while that same
model holds tools that publish under your brand.
That is a prompt-injection surface by construction, and it is worth knowing how it is handled:
untrusted_content block with an
explicit notice that it is data, not instructions. It is not a guarantee — no wrapper is — but it
raises the bar.Set PLANVORTEX_MCP_READ_ONLY=1 to remove the nine write tools from the listing entirely — useful
if you want to give an unsupervised agent read access and nothing else.
--http modeplanvortex-mcp --http serves MCP over HTTP for a self-hosted deployment. The process holds your
client_secret, so anything that can reach the port can publish to your accounts with a plain
curl. Therefore:
127.0.0.1 by default;PLANVORTEX_MCP_AUTH_TOKEN and the server refuses to start
without it;Origin header is validated on every request (DNS rebinding);docker run --rm -p 127.0.0.1:3000:3000 \
-e PLANVORTEX_CLIENT_ID=... -e PLANVORTEX_CLIENT_SECRET=... \
-e PLANVORTEX_MCP_AUTH_TOKEN=$(openssl rand -hex 32) \
planvortex-mcp --http --host 0.0.0.0
The flags are not optional there: the image speaks stdio by default, because that is what
an MCP client starts (docker run -i planvortex-mcp) and what a server directory introspects.
--http is the deployment mode, and you ask for it.
| Variable | Required | What it does |
|---|---|---|
PLANVORTEX_CLIENT_ID | yes | The app from your Custom plan. |
PLANVORTEX_CLIENT_SECRET | yes | Its secret. Never passed as a tool argument. |
PLANVORTEX_ORGANIZATION_ID | no | Default organization. Saves a discovery call per conversation. |
PLANVORTEX_BASE_URL | no | Point at another PlanVortex deployment. |
PLANVORTEX_MCP_UPLOAD_DIRS | no | Directories upload_media may read from. Empty means none. |
PLANVORTEX_MCP_AUTH_TOKEN | with --http off-loopback | Bearer token the HTTP endpoint requires. |
PLANVORTEX_MCP_READ_ONLY | no | 1 removes the nine write tools. |
PLANVORTEX_MCP_LOG_LEVEL | no | debug, info, warn, error, silent. Always to stderr. |
With stdio the server runs on your machine, so upload_media accepts an absolute local path —
but only inside PLANVORTEX_MCP_UPLOAD_DIRS, which is empty by default. Set it to the folders you
actually want reachable:
PLANVORTEX_MCP_UPLOAD_DIRS=/Users/you/Pictures,/Users/you/Downloads
Reading an arbitrary path is exactly what an injected prompt would ask for, so there is no way to
disable the allowlist. In --http mode a local path is refused outright: it would be a path on the
server, not on your machine. Pass a public https URL there.
Almost everything in PlanVortex hangs off an organization. The server resolves it in three steps:
the id_organization argument if the model passed one, then PLANVORTEX_ORGANIZATION_ID, and
finally — only if your app reaches exactly one — that one. If it reaches several and nothing says
which, the tool answers with the list of names and ids so the model can retry correctly, rather than
failing with a bare error.
npm install
npm test # layers 1 and 2: no network, no credentials
npm run build
npm run inspector # MCP Inspector against the built server
Built on planvortex, the official Node client. This
server speaks no HTTP of its own: every call goes through the library, which is where the error
catalogue, the token cache, the multipart upload and the pagination already live.
MIT © Talia Softworks
FAQs
Official MCP server for PlanVortex: let your AI assistant schedule posts, read the comment inbox and reply to messages across all your social networks.
The npm package planvortex-mcp receives a total of 244 weekly downloads. As such, planvortex-mcp popularity was classified as not popular.
We found that planvortex-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.