TouchDesignerBLOCK
MCP server for TouchDesigner
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/touchdesigner-mcp-server) [](https://www.npmjs.com/package/touchdesigner-mcp-server)
This is an implementation of an MCP (Model Context Protocol) server for TouchDesigner. Its goal is to enable AI agents to control and operate TouchDesigner projects.
English / 日本語
Overview
[](https://youtu.be/V2znaqGU7f4?si=6HDFbcBHCFPdttkM&t=635)
TouchDesigner MCP acts as a bridge between AI models and the TouchDesigner WebServer DAT, enabling AI agents to:
- Create, modify, and delete nodes
- Query node properties and project structure
- Programmatically control TouchDesigner via Python scripts
Installation
Tell the AI agent you already use:
Set up https://github.com/8beeeaaat/touchdesigner-mcp
That's it. The full procedure lives in the Installation Guide — it opens with a table matching each AI app to its route, and everyone starts from TouchDesigner Setup. Or follow it yourself, step by step.
If you are updating, please refer to the procedure in the [Latest Release](https://github.com/8beeeaaat/touchdesigner-mcp/releases/latest#for-updates-from-previous-versions).
MCP Server Features
This server enables AI agents to perform operations in TouchDesigner using the Model Context Protocol (MCP).
Tools
Tools allow AI agents to perform actions in TouchDesigner.
c5490e00f946OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add touchdesigner-mcp-server -- npx -y [email protected]
Trust audit
BLOCKgrade F · trust 31/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
1. **Check whether launching is even needed.** Resolve the endpoint from the active MCP configuration or session context as in the setup skill; treat `http://127.0.0.1:9981` as an assumption when neit
1. **Check whether launching is even needed.** Resolve the endpoint from the active MCP configuration or session context as in the setup skill; treat `http://127.0.0.1:9981` as an assumption when neit
result = eval(script, namespace, namespace)
exec(script, namespace, namespace)
namespace["result"] = eval(
mcp_webserver_base.tox
.agents/skills/integration-test-guard
.agents/skills/prepare-release
.agents/skills/release-test-audit
.agents/skills/touchdesigner-self-debug
return importlib.import_module(target)
module = __import__(module_name, fromlist=["*"])
TD_WEB_SERVER_HOST=http://127.0.0.1 TD_WEB_SERVER_PORT=9981 \
.node-version
.prettierignore
.prettierrc.json
return exec(process.execPath, [
const before = await exec(npm, ["prefix"], options);
new URL("../../.claude-plugin/plugin.json", import.meta.url),$ref: ../../index.yml#/components/schemas/TdPythonMethodInfo
$ref: ../../index.yml#/components/schemas/TdPythonPropertyInfo
- $ref: ../../../index.yml#/components/schemas/TdNode
$ref: ../../../index.yml#/components/schemas/TdNodeErrorReport
--host=http://127.0.0.1 \
"--host=http://127.0.0.1",
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
c5490e00f946full audit observations/trust-audit/mcp-server/8beeeaaat__touchdesigner.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | c5490e00f946 | BLOCK | F | 31 | first audit |
Questions
What is the TouchDesigner MCP server?
MCP server for TouchDesigner
Is TouchDesigner safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (31/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does TouchDesigner need?
No credential environment variables were found in its source, so it appears to need none.
How does TouchDesigner run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as touchdesigner-mcp-server at 2.1.0.
How current is this page?
The grade is for one exact copy of the source (c5490e00f946), read on 2026-09-30. The repository is watched and re-audited when it changes.