Atlas / MCP servers / 8beeeaaat / TouchDesigner

TouchDesignerBLOCK

mcp/8beeeaaat/touchdesigner

MCP server for TouchDesigner

Verdict
BLOCK
Grade
F
Trust score
31 /100
Exposed tools
—
Transport
stdio · streamable-http
License
MIT
Stars
556
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/touchdesigner-mcp-server) [](https://www.npmjs.com/package/touchdesigner-mcp-server)

This is an implementation of an MCP (Model Context Protocol) server for TouchDesigner. Its goal is to enable AI agents to control and operate TouchDesigner projects.

English / 日本語

Overview

[](https://youtu.be/V2znaqGU7f4?si=6HDFbcBHCFPdttkM&t=635)

TouchDesigner MCP acts as a bridge between AI models and the TouchDesigner WebServer DAT, enabling AI agents to:

  • Create, modify, and delete nodes
  • Query node properties and project structure
  • Programmatically control TouchDesigner via Python scripts

Installation

Tell the AI agent you already use:

Set up https://github.com/8beeeaaat/touchdesigner-mcp

That's it. The full procedure lives in the Installation Guide — it opens with a table matching each AI app to its route, and everyone starts from TouchDesigner Setup. Or follow it yourself, step by step.

If you are updating, please refer to the procedure in the [Latest Release](https://github.com/8beeeaaat/touchdesigner-mcp/releases/latest#for-updates-from-previous-versions).

MCP Server Features

This server enables AI agents to perform operations in TouchDesigner using the Model Context Protocol (MCP).

Tools

Tools allow AI agents to perform actions in TouchDesigner.

Read from source at commit c5490e00f946OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add touchdesigner-mcp-server -- npx -y [email protected]
03

Trust audit

BLOCKgrade F · trust 31/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (3 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
plugin/touchdesigner/skills/launch/SKILL.md:14
1. **Check whether launching is even needed.** Resolve the endpoint from the active MCP configuration or session context as in the setup skill; treat `http://127.0.0.1:9981` as an assumption when neit
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
plugins/touchdesigner/skills/launch/SKILL.md:22
1. **Check whether launching is even needed.** Resolve the endpoint from the active MCP configuration or session context as in the setup skill; treat `http://127.0.0.1:9981` as an assumption when neit
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
td/modules/mcp/services/api_service.py:515
result = eval(script, namespace, namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
td/modules/mcp/services/api_service.py:538
exec(script, namespace, namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
td/modules/mcp/services/api_service.py:557
namespace["result"] = eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
td/mcp_webserver_base.tox
mcp_webserver_base.tox
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/integration-test-guard
.agents/skills/integration-test-guard
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/prepare-release
.agents/skills/prepare-release
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/release-test-audit
.agents/skills/release-test-audit
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/touchdesigner-self-debug
.agents/skills/touchdesigner-self-debug
Why it matters. link not followed
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
td/modules/mcp/services/api_service.py:762
return importlib.import_module(target)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
td/modules/mcp_webserver_script.py:60
module = __import__(module_name, fromlist=["*"])
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/skills/integration-test-guard/SKILL.md:61
TD_WEB_SERVER_HOST=http://127.0.0.1 TD_WEB_SERVER_PORT=9981 \
LOWInventory / provenance · inv.hidden_file · CWE-1104
.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/unit/openaiPluginBuild.test.ts:29
return exec(process.execPath, [
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/unit/openaiPluginBuild.test.ts:168
const before = await exec(npm, ["prefix"], options);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
plugin/touchdesigner/hooks/scripts/td-config-context.mjs:13
new URL("../../.claude-plugin/plugin.json", import.meta.url),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/api/components/schemas/TdPythonClassDetails.yml:23
$ref: ../../index.yml#/components/schemas/TdPythonMethodInfo
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/api/components/schemas/TdPythonClassDetails.yml:28
$ref: ../../index.yml#/components/schemas/TdPythonPropertyInfo
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/api/paths/api/nodes/detail.yml:31
- $ref: ../../../index.yml#/components/schemas/TdNode
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/api/paths/api/nodes/errors.yml:28
$ref: ../../../index.yml#/components/schemas/TdNodeErrorReport
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/architecture.md:676
--host=http://127.0.0.1 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/architecture.md:763
"--host=http://127.0.0.1",

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-09-30 · audit v0.4.1 · source sha c5490e00f946full audit observations/trust-audit/mcp-server/8beeeaaat__touchdesigner.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-30c5490e00f946BLOCKF31first audit
05

Questions

What is the TouchDesigner MCP server?

MCP server for TouchDesigner

Is TouchDesigner safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (31/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does TouchDesigner need?

No credential environment variables were found in its source, so it appears to need none.

How does TouchDesigner run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as touchdesigner-mcp-server at 2.1.0.

How current is this page?

The grade is for one exact copy of the source (c5490e00f946), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement