# auditreach [Health: Active]

**Category:** 🌐 Social Media  
**Repository:** https://github.com/RudrenduPaul/auditreach  
**GitHub Stars:** 0  
**npm Downloads (last month):** 239  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/auditreach

## Description
BYOK Reddit/YouTube research CLI with a tamper-evident audit log and an MCP server.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "auditreach": {
    "command": "npx",
    "args": ["-y","auditreach-cli"]
  }
}
```

## Documentation

## What auditreach MCP server does

The auditreach MCP server gives an AI agent access to research workflows for Reddit and YouTube. Its underlying CLI supports searches against either platform, with Reddit searches optionally narrowed by subreddit. Results include source information such as titles, authors, timestamps, and URLs, then get written to a results file alongside an audit record.

The project is designed around bring-your-own-key access. Reddit uses an OAuth script-app grant with read-only access to public subreddit content. YouTube uses an API key. Credentials belong to the operator and are sent only to the relevant platform's official authentication or API endpoint.

The audit record captures the platform, endpoint, scope, and a plain-language explanation of the consent or terms-of-service basis for the request. That makes the tool relevant to research pipelines where an operator must later explain what was queried and under which authority.

## How it works

A research request is sent to Reddit or YouTube through their documented APIs. The Reddit implementation uses native `fetch` and does not depend on the archived `snoowrap` package or its deprecated request dependencies. The README describes the Reddit flow as rate-limit aware and read-only.

After a query completes, auditreach writes the returned data to a JSON results file and appends an entry to `auditreach.log.jsonl`. Entries form a hash chain: each entry is hashed from its own content, while the following entry refers to the preceding hash. Editing, deleting, or reordering records causes verification to report a broken chain.

The `verify-log` operation checks the chain and identifies where a mismatch occurs. This detects changes made after an entry was written, but it does not prevent someone from modifying the file; verification must be run to discover that change.

## Setup and configuration

Install either the npm package or the PyPI package. The npm distribution can be run with `npx auditreach-cli`, installed globally with npm, or built from the repository with Node.js. The README specifies Node.js 20 or newer. The Python distribution provides the same general BYOK model and hash-chain algorithm, with Python-specific usage documented separately.

For Reddit, create a script application in Reddit's application settings, then run the platform authentication command and provide the client ID, client secret, username, and password when prompted. For YouTube, create an API key through Google Cloud credentials and provide it through the YouTube authentication flow.

The npm package stores credentials in the operating system keychain through `@napi-rs/keyring`, not in a configuration file. The Python package also documents an environment-variable credential path for headless use, but the provided material does not list the variable names.

## Tools and capabilities

The documented operations include:

- Searching Reddit or YouTube with a supplied query.
- Restricting a Reddit search to a subreddit.
- Authenticating platform credentials before research.
- Checking credentials with an auth verification flow.
- Writing JSON research results and JSON Lines audit records.
- Verifying the audit log's hash chain.

The project supports the same API coverage and audit-chain approach in its npm and Python packages. The provided material does not enumerate MCP tool names or describe a client-specific configuration file, so integrations should be checked against the repository's current MCP documentation before deployment.

## Limitations and notes

Coverage is limited to Reddit and YouTube. The project intentionally avoids cookie import, session-token reuse, and browser-style scraping, so it may not provide the breadth of tools that depend on those methods. It also requires the operator to supply and manage valid credentials for each platform.

The audit log is local and tamper-evident rather than an external immutable archive. Its hash chain can show that records no longer match their written history, but the operator still needs to preserve the log and run verification. The README identifies Apache 2.0 as the project license.

The auditreach MCP server is therefore a fit for official-API research with traceable local records, not for broad social-platform coverage or anonymous collection.

_Full upstream README: https://allmcps.com/mcp/auditreach/readme_

