MCP server for YouTube creator-ops — video metadata, comments, playlists, channel analytics, plus a ComfyUI bridge for AI thumbnail generation.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.COMFYUI_DEFAULT_CKPT— (no flag) sd_xl_base_1.0.safetensors Default checkpoint for bridge toolCOMFYUI_URL— comfyui-url (unset, bridge disabled) ComfyUI HTTP URL for bridge toolsMCP_HOST— host 0.0.0.0 Bind host (HTTP mode only)MCP_PORT— port 9120 Bind port (HTTP mode only)MCP_TRANSPORT— stdio =stdio (unset) Speak MCP over stdio instead of HTTP. Use when launched as a subprocess by a stdio-first MCP client (Claude Desktop, mcp-inspector).XDG_CONFIG_HOMEYOUTUBE_CLIENT_ID— Or provide the client credentials via env: YOUTUBE_CLIENT_SECRET_FILE, or + YOUTUBE_CLIENT_SECRET.YOUTUBE_CLIENT_SECRET— Or provide the client credentials via env: YOUTUBE_CLIENT_SECRET_FILE, or YOUTUBE_CLIENT_ID + .YOUTUBE_CLIENT_SECRET_FILE— Or provide the client credentials via env: , or YOUTUBE_CLIENT_ID + YOUTUBE_CLIENT_SECRET.YOUTUBE_TOKEN_FILE— e =/token/token.json \[](https://m8ven.ai/mcp/miller-joe-youtube-mcp-v0u7ka)