Atlas / MCP servers / acedatacloud / SunoMCP

SunoMCPCAUTION

mcp/acedatacloud/sunomcp

MCP server for Suno AI music generation, lyrics, and cover workflows via Ace Data Cloud.

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
10 10r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
62
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/mcp-suno/) [](https://pypi.org/project/mcp-suno/) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io)

A Model Context Protocol (MCP) server for AI music generation using Suno through the AceDataCloud API.

Generate AI music, lyrics, and manage audio projects directly from Claude, VS Code, or any MCP-compatible client.

Features

  • Music Generation - Create AI-generated songs from text prompts
  • Custom Lyrics & Style - Full control over lyrics, title, and music style
  • Song Extension - Continue existing songs from any timestamp
  • Cover/Remix - Create cover versions with different styles
  • Lyrics Generation - Generate structured lyrics from descriptions
  • Persona Management - Save and reuse voice styles
  • Custom Music Models - Create and reuse app-owned custom music models
  • Task Tracking - Monitor generation progress and retrieve results

Tool Reference

Read from source at commit f12f56a4c264OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add mcp-suno --env ACEDATACLOUD_API_TOKEN=${ACEDATACLOUD_API_TOKEN} -- uvx mcp-suno==2026.3.19.7
03

Exposed tools (10)

10 read · 0 write · 0 destructive.

ToolRiskDescription
suno_archive_custom_modelreadArchive a custom music model so it can no longer be used.
suno_get_custom_modelreadRetrieve a single custom music model by ID.
suno_get_lyric_format_guidereadGet guidance on formatting lyrics for Suno music generation.
suno_get_mp4readGet an MP4 video version of a generated song.
suno_get_taskreadQuery the status and result of a music generation task.
suno_get_tasks_batchreadQuery multiple music generation tasks at once.
suno_get_timingreadGet timing and subtitle data for a generated song.
suno_list_actionsreadList all available Suno API actions and corresponding tools.
suno_list_modelsreadList all available Suno models and their capabilities.
suno_optimize_stylereadOptimize a music style description for better generation results.
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (9)

MEDIUMInventory / provenance · inv.binary · CWE-1104
jetbrains/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
core/oauth.py:279
logger.info(f"Revoked token: {token.token[:8]}...")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/client.py:63
if not request_payload.get("callback_url"):
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/oauth.py:112
callback_url = f"{settings.server_url}/oauth/callback"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/oauth.py:117
"redirect_uri": callback_url,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/oauth.py:305
callback_url = f"{settings.server_url}/oauth/callback"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
core/oauth.py:315
"redirect_uri": callback_url,
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ruff.toml
.ruff.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
vscode/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha f12f56a4c264full audit observations/trust-audit/mcp-server/acedatacloud__sunomcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07f12f56a4c264CAUTIONB87first audit
06

Questions

What is the SunoMCP MCP server?

MCP server for Suno AI music generation, lyrics, and cover workflows via Ace Data Cloud.

What tools does SunoMCP expose?

10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SunoMCP safe to connect to an agent?

With care. The audit graded it B (87/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does SunoMCP need?

It reads ACEDATACLOUD_API_TOKEN, ACEDATACLOUD_AUTH_BASE_URL and ACEDATACLOUD_OAUTH_CLIENT_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SunoMCP run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-suno at 0.3.0.

How current is this page?

The grade is for one exact copy of the source (f12f56a4c264), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement