yandex-marketing-mcp (skiddgoddamn/yandex-marketing-mcp) is an MCP server listed on the M8ven Trust Index. It scores 64 out of 100, grade C. It declares 160 tools. No publisher has claimed this listing.

C
Caution
64/100

yandex-marketing-mcp

MCP server for managing Yandex Direct advertising, Yandex Metrica analytics, Wordstat keyword research, and Yandex Webmaster SEO tools, with self-configuring OAuth; provides 153 tools for complete ad and search workflows from AI assistants.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

skiddgoddamn

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 3 credentials: YC_IAM_TOKEN, YC_SA_PRIVATE_KEY, YD_OAUTH_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes155 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

yd_auth_status

Show Yandex auth status: whether client_id, OAuth token, and Wordstat folder_id are configured.

yd_set_client_id

Save the Yandex OAuth application client_id and return the authorization link. Register an app at https://oauth.yandex.ru/client/new with scopes direct:api, metrika:read, metrika:write, cloud:auth and redirect 'Подставить URL для разработки'.

yd_set_token

Save the Yandex OAuth access_token (obtained via the authorize link). Validated against the Metrika API before saving. Optionally set yc_folder_id for Wordstat.

yd_set_service_account
yd_set_iam_token

Stopgap: store a ready-made IAM token from `yc iam create-token`. Valid at most 12 hours — use yd_set_service_account for a permanent fix.

yd_campaigns_get

Get list of campaigns. Filters: types, states, statuses, ids.

yd_campaigns_add

Create a new text campaign. Supports all strategies: PAY_FOR_CONVERSION, WB_MAXIMUM_CLICKS, WB_MAXIMUM_CONVERSION_RATE, AVERAGE_CPA, SERVING_OFF, etc.

yd_campaigns_update

Update campaign settings (name, budget, strategy, status, etc.).

yd_campaigns_action

Suspend, resume, archive, or unarchive campaigns.

yd_adgroups_add

Create ad groups in a campaign.

yd_adgroups_get

Get ad groups by campaign or group IDs.

yd_ads_add

Create text ads in ad groups. Supports bulk creation, sitelinks, and images.

yd_ads_update

Update existing text ads. Can change title, text, href, sitelinks, image, etc.

yd_ads_get

Get ads by campaign, ad group, or ad IDs.

yd_ads_action

Moderate, suspend, resume, archive, or unarchive ads.

yd_keywords_add

Add keywords to ad groups.

yd_keywords_get

Get keywords by campaign, ad group, or keyword IDs.

yd_keywords_research

Deduplicate keywords: merge duplicates, eliminate overlapping phrases. Preprocesses keywords before adding to campaigns.

yd_bids_set

Set bids for keywords.

yd_report

Get campaign statistics report. Returns TSV data.

yd_dictionaries

Get reference data: regions, currencies, ad categories, etc.

yd_keywords_has_volume

Check if keywords have search volume (impressions) in specified regions. Returns YES/NO per device type. Max 10000 keywords, max 20 requests per 60 seconds.

yd_keyword_bids_get

Get keyword bids and traffic forecasts.

yd_keyword_bids_set

Set keyword bids (search and network).

yd_keyword_bids_set_auto

Set automatic bidding for keywords based on target position or other criteria.

yd_bid_modifiers_add

Add bid modifiers (adjustments) for demographics, devices, regions, etc.

yd_bid_modifiers_get

Get bid modifiers for campaigns or ad groups.

yd_bid_modifiers_set

Update existing bid modifiers by their IDs.

yd_bid_modifiers_delete

Delete bid modifiers by IDs.

yd_negative_keywords_sets_add

Create shared negative keyword sets (max 30 total, reusable across campaigns).

yd_negative_keywords_sets_get

Get shared negative keyword sets.

yd_negative_keywords_sets_update

Update a shared negative keyword set.

yd_negative_keywords_sets_delete

Delete shared negative keyword sets.

yd_sitelinks_add

Create sitelink sets (quick links under ads, 1-8 per set).

yd_sitelinks_get

Get sitelink sets by IDs.

yd_sitelinks_delete

Delete sitelink sets.

yd_ad_extensions_add

Create ad extensions (callouts — short texts shown under ads, max 25 chars each).

yd_ad_extensions_get

Get ad extensions by IDs.

yd_ad_extensions_delete

Delete ad extensions.

yd_changes_check

Check what changed since a given timestamp (campaigns, ad groups, ads, stats).

yd_audience_targets_add

Add audience targeting conditions to ad groups (retargeting lists or interests).

yd_audience_targets_get

Get audience targets by campaign, ad group, or target IDs.

yd_audience_targets_delete

Delete audience targeting conditions.

yd_retargeting_lists_add

Create retargeting/audience conditions based on Yandex Metrika goals or audience segments.

yd_retargeting_lists_get

Get retargeting lists.

yd_retargeting_lists_delete

Delete retargeting lists.

yd_ad_images_add

Upload ad images (base64-encoded). Max 100 per request (recommended <=3).

yd_ad_images_get

Get ad images by IDs or linked entities.

yd_ad_images_delete

Delete ad images by hashes.

yd_businesses_get

Get organization profiles from Yandex Business linked to ads.

yd_clients_get

Get advertiser account info (settings, balance, bonuses, etc.).

yd_vcards_add

Add a VCard (business card) to a campaign.

yd_vcards_get

Get VCards. Optionally filter by IDs.

yd_vcards_delete

Delete VCards by IDs.

yd_feeds_add

Add a feed for dynamic/smart/shopping ads.

yd_feeds_get

Get feeds. Optionally filter by IDs.

yd_feeds_update

Update a feed (name, URL, auth).

yd_feeds_delete

Delete feeds by IDs.

yd_smart_targets_add

Add a smart ad target (filter) to an ad group.

yd_smart_targets_get

Get smart ad targets by campaign, ad group, or target IDs.

yd_smart_targets_action

Suspend, resume, or delete smart ad targets.

yd_ads_add_dynamic

Create a dynamic text ad.

yd_ads_add_image

Create an image ad (TextImageAd).

yd_ads_add_shopping

Create a shopping ad (uses v501 API).

yd_videos_upload

Upload a video from a local file (base64-encoded).

yd_videos_get

Get ad videos. Optionally filter by IDs.

yd_creatives_add

Create a video extension creative.

yd_creatives_get

Get creatives. Optionally filter by IDs or types.

yd_callouts_link

Link callout extensions to an ad (uses v501 API).

yd_bid_modifiers_toggle

Enable or disable bid modifiers.

yd_adgroups_update

Update an ad group (name, regions, negatives, tracking).

yd_regions_get

Get regions dictionary (convenience wrapper).

yd_interests_get

Get interests dictionary (convenience wrapper).

yd_excluded_sites_get

Get list of excluded sites (blocked placements) for a campaign.

yd_excluded_sites_update

Set excluded sites (blocked placements) for a campaign. Replaces entire list.

yd_blocked_ips_update

Set blocked IPs for a campaign (max 25). Only exact IPs, no subnets.

yd_campaign_strategy_update

Update campaign bidding strategy. Change CPA, weekly limit, goal, or strategy type.

yd_metrika_counters_get

List all Metrika counters. Optional search and favorite filter.

yd_metrika_counter_get

Get counter details by ID.

yd_metrika_counter_create

Create a new Metrika counter.

yd_metrika_counter_update

Update a Metrika counter.

yd_metrika_counter_delete

Delete a Metrika counter.

yd_metrika_goals_get

List goals for a counter.

yd_metrika_goal_create

Create a goal for a counter.

yd_metrika_goal_update

Update a goal.

yd_metrika_goal_delete

Delete a goal.

yd_metrika_segments_get

List segments for a counter.

yd_metrika_segment_create

Create a segment.

yd_metrika_segment_update

Update a segment.

yd_metrika_segment_delete

Delete a segment.

yd_metrika_filters_get

List filters for a counter.

yd_metrika_filter_create

Create a filter for a counter.

yd_metrika_filter_update

Update a filter.

yd_metrika_filter_delete

Delete a filter.

yd_metrika_grants_get

List access grants for a counter.

yd_metrika_grant_add

Add access grant to a counter.

yd_metrika_grant_update

Update access grant.

yd_metrika_grant_delete

Delete access grant.

yd_metrika_report

Get a Metrika report (table).

yd_metrika_report_by_time

Get a Metrika report grouped by time.

55 further tools are not listed here. The complete surface is in the source.

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configYANDEX_MCP_CONFIG_DIR
configYANDEX_OAUTH_CLIENT_IDClient ID OAuth-приложения (seed; сохраняется через yd_set_client_id)
configYC_FOLDER_IDID каталога Yandex Cloud для Wordstat (seed; сохраняется через yd_set_token)
🔐 secretYC_IAM_TOKENГотовый IAM-токен из yc iam create-token (seed; временный обходной путь)
configYC_SA_IDID сервисного аккаунта Yandex Cloud (seed; сохраняется через yd_set_service_account)
configYC_SA_KEY_IDID авторизованного ключа сервисного аккаунта (seed)
🔐 secretYC_SA_PRIVATE_KEYПриватный ключ сервисного аккаунта в PEM (seed)
configYD_ALLOWED_LOGINSБелый список логинов клиентов через запятую (только для инструментов Директа)
configYD_API_URL
configYD_CONFIRMtrue — изменяющие вызовы сначала возвращают превью; для выполнения нужен confirm=true
configYD_LOGINЛогин клиента по умолчанию (для агентских аккаунтов)
configYD_LOG_BODIEStrue — писать тела запросов и ответов в лог
configYD_LOG_FILEПуть к лог-файлу (пусто — только stderr, файл не создаётся)
configYD_LOG_LEVELDEBUG / INFO / WARNING / ERROR (по умолчанию INFO)
🔐 secretYD_OAUTH_TOKENOAuth access_token (seed; сохраняется через yd_set_token)
configYD_READONLYtrue — блокирует все изменяющие инструменты; только чтение и отчёты
configYD_SANDBOXtrue — тестовый режим Директа (sandbox)
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

160/160 tools missing one or more hints — yd_auth_status (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); yd_set_client_id (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); yd_set_token (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +157 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/skiddgoddamn/yandex-marketing-mcp?variant=verified)](https://m8ven.ai/mcp/skiddgoddamn/yandex-marketing-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 2f3160f229bf56f5826d4f86cb5ec96de302348c
code hash: 302bf17a42fc1190819a48c9a450151923c5223c9f84d12d388aac7a885ed8f0
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client