Mmcp.market

Is Clipform MCP server safe?

Yes, with the usual care.

B78/100grade B

Safe to use. Minor gaps such as a missing repository or slower maintenance.

What to know before installing
  • highWrite-action tools reachable without authentication

Public scan report

scanner v0.1.7 · 2026-09-19 · same rubric, same numbers if you re-run it

1 high1 medium1 low
  • Code scan23 source files scanned20/25
  • Live reliabilityremote reachable in 799ms20/20
  • Tool poisoning34 tool descriptions checked13/15
  • Auth qualityopen endpoint exposes 8 write-action tools with no auth3/15
  • Maintenancelast push 10 days ago15/15
  • Maintainer identityregistry namespace matches repository owner7/10

Findings (3)

  • highWrite-action tools reachable without authenticationauth.open-write
  • mediumeval / new Function usedexec.eval
    dist/chunk-I65WITUI.js: …ode, sch); const makeValidate = new Function(`${names_1.default.self}`, `${names_1.de…
  • lowUnusually long tool description (over 2,000 characters)poison.long-description
    tool clipform_create_form: …Create a new Clipform (interactive video-style form). Returns a viewer URL and form ID. When connected via an authenticated MCP client (e.g. claude.ai), the form lands directly in the user's workspace. Anonymous sessions get a claim URL to transfer ownership later. If the user hasn't said what to build yet, offer to build their first form and suggest starting points: lead-gen, feedback, quiz, or something else. Node types (omit config to use defaults where shown): - choice: Single or multiple choice node with predefined options (supports options array). Config: choice ({enable_branching, show_answer_feedback, record_scores}), selection_mode ("single"|"multiple", default: "single"), allow_text_response (boolean, default: false), randomise_options (boolean, default: false), show_option_count (boolean, default: false), option_display ("list"|"letters", default: "list"). Defaults: {"selection_mode":"single","choice":{"enable_branching":false},"randomise_options":false,"show_option_count":false,"option_display":"list"} - open: Free-form text responses from users. Config: formats (array of {format, order}), max_recording_seconds (number, default: 120). Defaults: {"formats":[{"order":0,"format":"text"},{"order":1,"format":"audio"},{"order":2,"format":"video"}]} - details: Collect several fields on one screen - name, email, phone, address, date, and more. Config: title (string), fields (array of {id, type, label, order, required, is_custom}), description (string), consent_items (array of {id, name, label, order, type, document, require_scroll_to_accept}), Available field IDs: first_name, last_name, email, phone. Defaults: {"fields":[{"id":"first_name","type":"first_name","label":"First Name","enabled":true,"required":true},{"id":"email","type":"email","label":"Email","enabled":true,"required":true}],"consent_items":[]} - payment: Collect a payment from respondents inline, charged to a connected Stripe account. Config: amount (number), currency ("usd"|"eur"|"gbp"|"cad"|"aud", default: "usd"), provider ("stripe"|"paddle", default: "stripe"), workspace_integration_id (string), title (string), description (string). Defaults: {"amount":null,"currency":"usd","provider":"stripe"} - button: Simple button for acknowledgment or navigation (supports options array). Config: button_text (string, default: "Continue"), button_style ("primary"|"secondary"|"outline", default: "primary") - redirect: Redirect users to an external URL. Config: url (string), auto_redirect (boolean, default: true). Defaults: {"url":"","auto_redirect":true} - file_download: Provide a file for respondents to download. Config: files (array of {file_name, display_name, file_path, file_size, mime_type}), button_text (string, default: "Continue"), description (string) - end_screen: Final screen shown when form is completed. Config: title (string, default: "Thank you!"), message (string, default: "Your response has been submitted."), icon ("tick"|"trophy"|"star"|"crown"|"party"|"none", default: "tick"), show_share_button (boolean, default: false), cta_type ("none"|"restart"|"external_link", default: "none"), cta_text (string, default: "Continue"), cta_url (string). Defaults: {"title":"Thank you!","message":"Your response has been submitted."} All type definitions and config schemas are derived from @vid-master/config (node-types). Refer to the config descriptions above for the correct keys and shapes. AI-PROTECTED parameters have restrictions noted in their descriptions. Example: A form that asks a question, collects contact info, then finishes: { title: "Quick Survey", nodes: [ { type: "open", prompt: "What's your biggest challenge?" }, { type: "details", prompt: "Leave your details", config: { fields: [{ id: "first_name", required: true }, { id: "email", required: true }] } }, { type: "end_screen", prompt: "Thanks for your response!" } ] }…
Overall 78/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Other servers that do what Clipform does

  • Morpha
    AI editor to build, animate & export layered short-form video projects via one tool catalog.
    C
  • Sonilo Music & Sound Effects
    Licensed soundtracks and sound effects matched to your video. Commercial use OK.
    B
  • Youtube Transcript
    An MCP server retrieving transcripts of YouTube videos
    A

Clipform reviews, tools and install