
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
social-commerce-intelligence-mcp
Advanced tools
Creator affiliate, video, and shop revenue data is siloed across TikTok, Instagram, Pinterest, YouTube, and Shopify.
This folder contains a production-minded MCP server scaffold with typed JSON tool responses, connector health metadata, OAuth-oriented configuration, rate-limit guards, stable error envelopes, and deterministic demo data until live vendor integrations are attached.
This server has received a production pass. It now includes local creator and social commerce models for creator ROI, video conversion, trending products, affiliate commissions, platform revenue, and underperforming creator detection.
seller.read; env prefix TIKTOK_SHOPadvertiser.read; env prefix TIKTOK_BUSINESSinstagram_basic; env prefix INSTAGRAMpins:read; env prefix PINTERESTyoutube.readonly; env prefix YOUTUBEread_orders; env prefix SHOPIFYget_creator_roi_report - Creator revenue, commission, CAC, and margin.get_top_converting_videos - Rank videos by conversion quality.get_trending_products - Trending shop products by niche.get_affiliate_commissions_summary - Commission liability and payout status.get_social_commerce_revenue_by_platform - Revenue by social commerce platform.identify_underperforming_creators - Creators needing coaching or pause.python -m pytest .\tests -q -p no:cacheprovider
Customers only need to connect the social-commerce platforms they actually use. Missing TikTok Shop, TikTok Business, Instagram, Pinterest, YouTube, Shopify, or affiliate credentials do not prevent the server from starting or running local intelligence tools.
Use get_live_connector_status to see configured connectors. Use test_tiktok_shop_connection, test_affiliate_connection, and test_social_content_connection for read-only live smoke checks when those platforms are connected.
powershell python -m venv .venv .\.venv\Scripts\pip install -e . .\.venv\Scripts\python -m social_commerce_intelligence_mcp.server
json { "mcpServers": { "social-commerce-intelligence": { "command": "python", "args": ["-m", "social_commerce_intelligence_mcp.server"], "cwd": "D:\CUSTOMS\EARNALL\MCP Servers\07-social-commerce-intelligence" } } }
FAQs
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.