Atlas / MCP servers / acedatacloud / ProducerMCP

ProducerMCPCAUTION

mcp/acedatacloud/producermcp

MCP server for Producer/Riffusion AI music generation via AceDataCloud API

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
9 8r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
2
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/mcp-producer/) [](https://pypi.org/project/mcp-producer/) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io)

A Model Context Protocol (MCP) server for AI music generation using Producer/Riffusion (FUZZ models) through the AceDataCloud API.

Generate AI music directly from Claude, VS Code, or any MCP-compatible client.

Features

  • Text to Music - Create AI-generated music from text prompts
  • Custom Music - Full control with custom lyrics, title, and style
  • Song Extension - Continue songs from any timestamp
  • Cover/Remix - Create covers in different genres and styles
  • Variations - Generate alternative versions of songs
  • Vocal/Instrumental Swap - Mix vocals and instrumentals between songs
  • Section Replacement - Re-generate specific sections of a song
  • Stem Separation - Split songs into vocal and instrumental tracks
  • Lyrics Generation - Generate structured lyrics from prompts
  • Video Generation - Create music videos for songs
  • WAV Export - Get lossless audio format
  • 8 FUZZ Models - From FUZZ-0.8 to FUZZ-2.0 Pro

Tool Reference

Read from source at commit 6f196e1b62dfOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add mcp-producer --env ACEDATACLOUD_API_TOKEN=${ACEDATACLOUD_API_TOKEN} -- uvx mcp-producer==2026.4.5.0
03

Exposed tools (9)

8 read · 1 write · 0 destructive.

ToolRiskDescription
producer_generate_lyricsreadGenerate song lyrics from a text prompt.
producer_generate_videoreadGenerate a video for a previously generated song.
producer_generate_wavreadGet the lossless WAV format of a generated song.
producer_get_lyric_format_guidereadGet guidance on formatting lyrics for Producer music generation.
producer_get_taskreadQuery the status and result of a music generation task.
producer_get_tasks_batchreadQuery multiple music generation tasks at once.
producer_list_actionsreadList all available Producer API actions and corresponding tools.
producer_list_modelsreadList all available Producer/FUZZ models and their capabilities.
producer_upload_audiowriteUpload an external audio file for use in subsequent operations.
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (9)

MEDIUMInventory / provenance · inv.binary · CWE-1104
jetbrains/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
core/oauth.py:279
logger.info(f"Revoked token: {token.token[:8]}...")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/client.py:63
if not request_payload.get("callback_url") and "async" not in request_payload:
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/oauth.py:112
callback_url = f"{settings.server_url}/oauth/callback"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/oauth.py:117
"redirect_uri": callback_url,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/oauth.py:305
callback_url = f"{settings.server_url}/oauth/callback"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/oauth.py:315
"redirect_uri": callback_url,
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ruff.toml
.ruff.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
vscode/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6f196e1b62dffull audit observations/trust-audit/mcp-server/acedatacloud__producermcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076f196e1b62dfCAUTIONB86first audit
06

Questions

What is the ProducerMCP MCP server?

MCP server for Producer/Riffusion AI music generation via AceDataCloud API

What tools does ProducerMCP expose?

9 in total: 8 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ProducerMCP safe to connect to an agent?

With care. The audit graded it B (86/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does ProducerMCP need?

It reads ACEDATACLOUD_API_TOKEN, ACEDATACLOUD_AUTH_BASE_URL and ACEDATACLOUD_OAUTH_CLIENT_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ProducerMCP run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-producer at 0.3.0.

How current is this page?

The grade is for one exact copy of the source (6f196e1b62df), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement