surfagent-x (surfagentapp/surfagent-x) is an MCP server listed on the M8ven Trust Index. It scores 60 out of 100, grade C. It declares 76 tools. No publisher has claimed this listing.
X adapter for SurfAgent that gives AI agents X-native verbs for navigation, extraction, posting, replies, likes, reposts, proof-first task execution, recovery, and deeper research workflows.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
surfagentapp
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
x_health_checkCheck whether X is open in SurfAgent, identify current X page state, and report composer/account readiness.
x_openOpen X in SurfAgent. Optionally choose a starting section such as home, notifications, search, or a profile path.
x_get_accountsInspect the active X account and any account-switcher entries currently visible.
x_switch_accountSwitch X accounts through the in-session account switcher and verify the resulting active account state.
x_get_stateGet structured X page state for the current tab: route, page kind, selected tabs, composer state, and account info.
x_get_state_mapReturn the built-in X state maps for flaky surfaces like account switcher, composer, community, home, post, and profile.
x_open_homeOpen the X home timeline and wait for a settled X page state.
x_open_profileOpen a profile by username.
x_open_notificationsOpen X notifications.
x_open_searchOpen X search, optionally prefilled with a query and live filter.
x_open_postOpen a specific X post by full URL or by username + status ID.
x_get_timelineExtract the currently visible X timeline posts with author, text, status URL, and social action labels.
x_search_postsSearch X posts and return extracted live results from the search timeline.
x_open_communityOpen an X community URL directly. Useful because community navigation has its own weird composer behavior.
x_search_communitiesSearch X communities and return community cards/links discovered on the search surface.
x_search_profilesSearch X profiles and return discovered accounts with display names, handles, bios, and URLs.
x_get_community_feedExtract visible posts from the current or specified X community feed.
x_extract_communityOpen a community and return structured community metadata, including name, description, member/post hints, and join state when visible.
x_extract_postOpen a post and return a structured post record with author, text, media, and visible stats.
x_extract_profileOpen a profile and return a structured profile record with bio, stats, and pinned post when visible.
x_get_profile_postsOpen a profile and extract visible posts from that profile timeline.
x_get_post_threadOpen a post and extract the visible thread/timeline around it as structured post rows.
x_get_composer_stateInspect the current X composer state, including whether the Post/Reply button is enabled.
x_create_postCreate a new X post from the home composer with button-state verification and automatic real-typing fallback if X rejects the initial input.
x_reply_to_postReply to a specific post with pre-submit composer verification, automatic real-typing fallback, and post-submit visibility verification.
x_like_postLike a specific X post and verify resulting button state.
x_repost_postRepost a specific X post and verify the resulting repost state.
x_follow_profileFollow an X profile and verify the resulting follow state from the active account.
x_engage_post_taskRun a deterministic engage-post task with account switch, screenshots, optional like/repost actions, and a persisted run journal.
x_quote_post_taskRun a deterministic quote-post task with screenshots before and after submit, account switching, and profile-level verification.
x_reply_post_taskRun a deterministic reply-post task with account switching, screenshots, and post-surface verification.
x_follow_profile_taskRun a deterministic follow-profile task with account switching, screenshots, and profile-state verification.
x_community_post_taskRun a deterministic community-post task with membership check, screenshots, composer recovery, and feed verification.
x_switch_account_and_act_taskRun a deterministic account switch followed by a focused action like open-home, open-url, or follow-profile.
x_verify_text_visibleVerify that a specific text snippet is visible on X. Scope can target body, article content, or the active composer.
x_recoverApply lightweight X recovery actions for common stuck states: composer, home, or target URL.
x_research_topicRun an autonomous X research pass for a topic, with retries, receipts, post/thread/profile extraction, and community sampling.
x_map_communityRun an autonomous community mapping pass: open a community, extract feed rows, and profile a sample of visible participants.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
SURFAGENT_AUTH_TOKENoptional override, otherwise auto-detectedSURFAGENT_DAEMON_URLdefault: http://127.0.0.1:7201SURFAGENT_RUN_DIR${:-$TMPDIR/surfagent-x-runs}Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
76/76 tools missing one or more hints — x_health_check (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); x_open (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); x_get_accounts (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +73 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.17.3 (high), @modelcontextprotocol/sdk@1.17.3 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/surfagentapp/surfagent-x)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check