FishMCPCAUTION
Fish Audio MCP server — text-to-speech with Fish Audio voice models. Powered by AceDataCloud.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for Fish Audio TTS (Text-to-Speech) via the AceDataCloud platform. Generate natural-sounding speech and explore the Fish voice model library.
Features
- High-quality TTS: Generate speech from text via Fish Audio models
- Voice library: Browse, search, and fetch metadata for Fish voice models
- Asynchronous tasks: Submit generation tasks and poll for results
- Batch task lookup: Query multiple task results in one call
One-shot voice cloning
Pass one public HTTPS reference audio URL plus its exact transcript. This conditions only the current TTS request and does not create a reusable voice model:
fish_generate_audio( text="New speech in the referenced voice", reference_audio_url="https://cdn.acedata.cloud/reference.mp3", reference_text="The exact words spoken in the reference audio", )
Use reference_id for saved or public voices, and the one-shot reference fields for a temporary voice. Do not combine them. Reference audio supports MP3/WAV and should be 10–270 seconds. Billing remains based on the target text's UTF-8 byte count.
Connect: hosted OAuth, API token, or local stdio
The hosted endpoint is https://fish.mcp.acedata.cloud/mcp. Choose one route for the MCP client:
fd3f3a8feebcOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-fish --env ACEDATACLOUD_API_TOKEN=${ACEDATACLOUD_API_TOKEN} -- uvx mcp-fish==2026.4.5.0Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
fish_get_model | read | Get a Fish voice model by ID. |
fish_get_task | read | Query the status and result of a Fish audio generation task. |
fish_get_tasks_batch | read | Query the status of multiple Fish tasks at once. |
fish_get_usage_guide | read | Get a comprehensive guide for using the Fish TTS tools. |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (10)
gradle-wrapper.jar
logger.info(f"Revoked token: {token.token[:8]}...")if not request_payload.get("callback_url") and "async" not in request_payload:callback_url = f"{settings.server_url}/oauth/callback""redirect_uri": callback_url,
callback_url = f"{settings.server_url}/oauth/callback""redirect_uri": callback_url,
.ruff.toml
.vscodeignore
first use (redirect URL `http://127.0.0.1:33418` or `https://vscode.dev/redirect`).
Gates applied: no_behavioural_pass.
fd3f3a8feebcfull audit observations/trust-audit/mcp-server/acedatacloud__fishmcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | fd3f3a8feebc | CAUTION | B | 86 | first audit |
Questions
What is the FishMCP MCP server?
Fish Audio MCP server — text-to-speech with Fish Audio voice models. Powered by AceDataCloud.
What tools does FishMCP expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is FishMCP safe to connect to an agent?
With care. The audit graded it B (86/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does FishMCP need?
It reads ACEDATACLOUD_API_TOKEN, ACEDATACLOUD_AUTH_BASE_URL and ACEDATACLOUD_OAUTH_CLIENT_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does FishMCP run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-fish at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (fd3f3a8feebc), read on 2026-10-07. The repository is watched and re-audited when it changes.