Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add mcp/pobibibi/youtube-transcript-mcp/youtube-transcript-mcpgit clone --depth 1 https://github.com/pobibibi/youtube-transcript-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/mcp/pobibibi/youtube-transcript-mcp/youtube-transcript-mcp)<a href="https://agentmods.dev/mcp/pobibibi/youtube-transcript-mcp/youtube-transcript-mcp"><img src="https://agentmods.dev/badge/mcp/pobibibi/youtube-transcript-mcp/youtube-transcript-mcp.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
youtube-transcript-mcp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to youtube-transcript-mcp — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
{ "youtube-transcript-mcp": { "command": "npx", "args": [ "-y", "youtube-transcript-mcp" ] } }
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 9 lines scan A da90a3291f8c
youtube-transcript-mcp is an MCP server published in the GitHub repository pobibibi/youtube-transcript-mcp (0 stars, last pushed 1mo ago), licensed MIT. Its token cost is not measured: an MCP server costs its tool schemas, not its config file. A static security scan graded it A with 0 findings. It is 100% identical to youtube-transcript-mcp, differing in 0 lines, and is treated as a copy.
Other mcp servers, from other repositories
seekstone
Filesystem-direct Obsidian MCP server — search and edit your vault with low context-tax. Runs locally from the seekstone npm package. Needs 1 environment variable to run.
clickup-mcp
Lightweight ClickUp MCP server - 37 tools, token-optimized (95% smaller responses). Runs locally from the @cavort-it-systems/clickup-mcp npm package. Needs 1 environment variable to run.
llm-sidecar
Local sidecar giving any tool grounded, cited, routed AI — Ollama or OpenRouter, no API key required. Runs locally from the llm-sidecar Python package.
web-fetcher
Fast, lightweight MCP server that fetches any web page, strips HTML bloat, converts it to clean Markdown, and extracts metadata and links for LLM analysis. Runs locally from the mcp-server-web-fetcher npm package. Needs 3 environment variables to run.
tegro-money
MCP server for Tegro.Money — connect Claude, Cursor and other AI tools to the Tegro.Money payment API (balances, shops, orders, payouts, rates). Read-only, secure, your API key never leaves your machine. Runs locally from the @tegroton/tegro-money-mcp npm package. Needs 2 environment variables to run.
passiv-mcp
MCP server "passiv-mcp" as configured in mahope/passiv-mcp. Runs locally from the passiv-mcp npm package.