Wan 3.0SAFE
Wan 3.0 API Python SDK and MCP server for AI video generation: text-to-video, image-to-video, multimodal references, uploads, and async job polling.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://muapi.ai) [](LICENSE) [](https://www.python.org/)
A focused Python SDK and MCP server for the Wan 3.0 API on MuAPI. It supports text-to-video, image-to-video, multimodal reference-to-video (up to 10 reference images, 5 reference videos, and 5 reference audios), synchronized audio, file upload, and asynchronous job polling.
▶ Watch: How to Access Wan 3.0 API - Best Uncensored Alternative to Seedance 2
Related Projects
- Wan 3 on MuAPI — Model landing page for Wan video-generation workflows.
- MuAPI video-generation docs — Unified API request and polling patterns.
- Wan-3.0-Spicy-API — Python SDK and MCP server for the relaxed-moderation Wan 3.0 Spicy tier.
- awesome-ai-video-models — compare AI video models by API, price, and speed.
- Open-Generative-AI — open-source AI media studio for image and video workflows.
- Seedance-2-API — Python SDK for ByteDance Seedance video generation.
- Veo-4-API — Python SDK for Google Veo AI video generation.
- Flux-3-Dev-API — Python SDK for FLUX 3 image and video generation.
- muapi-skills — agent-ready skills for
9b16958816bfOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add wan-3-api --env MUAPI_API_KEY=${MUAPI_API_KEY} -- uvx wan-3-api{
"mcpServers": {
"wan-3-api": {
"command": "uvx",
"args": [
"wan-3-api"
],
"env": {
"MUAPI_API_KEY": "${MUAPI_API_KEY}"
}
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_task_status | read | Get the status and outputs for a Wan generation job. |
image_to_video | read | Animate a source image URL into a Wan video with synchronized audio. |
reference_to_video | read | Generate a Wan video conditioned on up to 10 reference images, 5 reference |
text_to_video | read | Generate a Wan video with synchronized audio from a descriptive text prompt. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
requests, python-dotenv, mcp
Gates applied: no_behavioural_pass.
9b16958816bffull audit observations/trust-audit/mcp-server/anil-matcha__wan-3-0.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 9b16958816bf | SAFE | B | 89 | first audit |
Questions
What is the Wan 3.0 MCP server?
Wan 3.0 API Python SDK and MCP server for AI video generation: text-to-video, image-to-video, multimodal references, uploads, and async job polling.
What tools does Wan 3.0 expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Wan 3.0 safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Wan 3.0 need?
It reads MUAPI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (9b16958816bf), read on 2026-10-07. The repository is watched and re-audited when it changes.