LearnFlow AI (Shalin-Shah-2002/Yt-MCP) is an MCP server listed on the M8ven Trust Index. It scores 52 out of 100, grade D. It declares 27 tools. No publisher has claimed this listing.
AI-powered MCP server that transforms learning by finding best YouTube tutorials, generating personalized learning paths, and tracking progress for any tech skill.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
Shalin-Shah-2002
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
search_youtubeSearch YouTube for videos on a specific topic and return detailed results with statistics.
get_video_detailsGet detailed information about a specific YouTube video by its video ID.
get_channel_infoGet information about a YouTube channel including subscriber count and video statistics.
get_video_commentsFetch comments from a YouTube video to judge its quality. Returns top comments with likes and sentiment hints. Useful for understanding viewer feedback before watching.
get_video_timestampsExtract timestamps/chapters from a YouTube video description. Returns structured timestamps with time codes and labels for easy navigation.
analyze_videoComprehensive video analysis: Get video details, comments, timestamps, sentiment analysis, and a quality recommendation score. Perfect for deciding if a video is worth watching.
get_playlist_videosGet all videos from a YouTube playlist with detailed statistics for each video. Perfect for course playlists and tutorial series.
analyze_playlistComprehensive playlist analysis: total duration, average quality, best/worst videos, consistency score, and recommendation. Great for evaluating course playlists.
compare_videosCompare 2-5 videos side by side. Returns winner, ranking, and comparison across views, engagement, timestamps, and sentiment. Perfect for choosing the best tutorial.
get_related_videosFind videos related to a given video. Useful for building a learning queue or finding alternative explanations of the same topic.
get_video_transcriptGet video transcript or summary info. Returns: video title, channel, duration, available caption languages, and when transcripts are restricted, provides suggested topics from metadata, description excerpt, and manual workaround instructions.
get_full_transcriptFetch the FULL transcript/captions text from a YouTube video. Returns the complete spoken content with timestamps, sections, and key topics covered. If transcript is restricted by YouTube, provides video summary with topics from metadata and description instead.
analyze_channelDeep analysis of a YouTube channel: upload frequency, content quality, subscriber metrics, recent videos, and recommendation on whether to subscribe. Perfect for evaluating educational channels.
generate_learning_pathGenerate a structured learning path for pre-defined topics (Flutter, MERN, DSA) with YouTube video recommendations.
get_available_pathsGet a list of available pre-defined learning paths (Flutter, MERN, DSA).
search_quality_videosSearch for videos with 80%+ positive comments. Returns only high-quality, well-received educational content. Perfect for learning new topics with trusted content.
generate_smart_roadmapGenerate a complete learning roadmap with phases, modules, and quality-filtered video recommendations. Available topics: react, nodejs, python, javascript, dsa, devops, ml (Machine Learning/AI).
create_curated_pathCreate a custom curated learning path for any topic with quality-filtered videos. Best for specific technologies not in predefined roadmaps.
get_video_trust_scoreGet a detailed trust score breakdown for a video. Shows comment sentiment, engagement metrics, creator reputation, and overall trustworthiness rating.
get_topic_dependenciesGet prerequisites and dependencies for a topic. Shows what you should learn first and what you can learn after. Perfect for planning your learning journey.
assess_skill_levelGet skill assessment questions for a topic. Answer these to determine your current level and get personalized video recommendations.
get_project_videosGet quality-filtered project tutorial videos for hands-on learning. Perfect after completing theory to build real projects.
generate_interview_prepGenerate interview preparation resources with quality-filtered videos covering common questions, coding challenges, and tips for a specific topic.
generate_study_planGenerate a personalized study plan with daily/weekly schedule based on your available time and learning goals.
track_progressTrack learning progress by marking videos/topics as completed and get next recommendations based on your progress.
set_youtube_api_keySet your YouTube API key to enable all YouTube features. Get your free API key from Google Cloud Console. The key will be validated before being saved.
check_api_statusCheck if YouTube API key is configured and working. Shows current status and instructions if not configured.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios: Header Injection via Prototype Pollution
YOUTUBE_API_KEYYesPORTDependencies
10 runtime dependencies, 1 flagged: puppeteer-core
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
27/27 tools missing one or more hints — search_youtube (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_video_details (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_channel_info (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +24 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 12 high severity in production deps — @modelcontextprotocol/sdk@1.25.2 (high), axios@1.13.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
2/10 production deps stale: node-fetch@2023-11-30 (2.8y), swagger-ui-express@2024-05-31 (2.3y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/shalin-shah-2002/yt-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check