BeatOSCAUTION
Local-first beat library built for producers — catalog, BPM/key analysis, license tiers & PDFs, tagged-MP3 + loopkit export, and assisted multi-platform publishing. Chat with your catalog via a built-in AI Agent (Claude · ChatGPT · DeepSeek), or wire it to any MCP client. Desktop + web.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The beat library built for how producers actually work.
Not a spreadsheet. Not a DAW. Not a marketplace. BeatOS is a local-first home for every beat on your drive — catalog it once with the metadata that sells beats, let AI do the tagging grind, and export or publish to the platforms where you actually sell. Runs as a native desktop app (macOS · Windows) or right in your browser. Single-user, offline, no account, no telemetry.
[](CHANGELOG.md) [](#install--run) [](LICENSE) [](ROADMAP.md) [](#two-ways-to-put-ai-to-work)
English · 简体中文
Why BeatOS
I'm a beatmaker. Like most of us, my catalog lived in a spreadsheet, and every beat got its metadata typed out by hand into each platform I sell on. BeatOS is what I built instead — one canonical catalog, with three things nothing else puts together:
- 🎯 Purpose-built for selling beats — license tiers with multi-currency pricing, producer credits, tagged/untagged/loop/stems, BPM & key. Not a generic media manager bent into shape.
- 🤖 **A
fd421b42b4c0OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add beatos-desktop --env BEATOS_API_TOKEN=${BEATOS_API_TOKEN} --env BEATOS_MCP_DISABLE_AUTH=${BEATOS_MCP_DISABLE_AUTH} -- npx -y [email protected]{
"mcpServers": {
"beatos-desktop": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"BEATOS_API_TOKEN": "${BEATOS_API_TOKEN}",
"BEATOS_MCP_DISABLE_AUTH": "${BEATOS_MCP_DISABLE_AUTH}"
}
}
}
}Exposed tools (10)
5 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create_list | write | Create a new user list. Applies directly (your MCP client gates the call); |
get_track | read | Fetch a single track by id, including its audio/cover assets. For listing |
list_distinct_values | read | Enumerate distinct values + counts for one of producer/genre/mood/key. |
list_export_platforms | read | List platforms BeatOS can export metadata for (e.g. |
list_lists | read | List all user + system lists. Returns {items: [{id, name, kind, position, |
list_publish_jobs | write | List all publish jobs known this session, for recovery after losing a |
list_publish_platforms | write | List platforms BeatOS can PUBLISH to (e.g. |
ping | read | Liveness check — returns pong and the BeatOS version. |
publish_session_status | write | Check login/session state per platform before publishing. Returns |
publish_status | write | Poll a publish job started by publish_track (Pro). Returns |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (21)
const base = `http://127.0.0.1:${apiPort}`;const baseUrl = `http://127.0.0.1:${hs.port}`;const BASE = `http://127.0.0.1:${PORT}`;secret = "sk-should-never-appear"
click_120bpm_c_major.wav
.gitmodules
.prettierignore
.prettierrc.yaml
- from: ../../dist/beatos-sidecar
const repoRoot = resolve(import.meta.dirname, "../../..");
expect(isSafeAbsolutePath("/Users/me/../../etc/passwd")).toBe(false);import type { BeatosAPI } from "../../preload";import type { BeatosAPI } from "../../../preload";- **Browser** — `make web` builds the SPA and serves it at `http://127.0.0.1:8765`: same backend, same library, near-identical UI, no Electron build. The easy way to run on Windows or anywhere today.
- **浏览器**——`make web` 构建 SPA 并在 `http://127.0.0.1:8765` 提供服务:同一后端、同一个库、几乎一致的 UI,无需 Electron 构建。今天在 Windows 或任何地方运行的最简单方式。
@dnd-kit/core, @dnd-kit/sortable, @dnd-kit/utilities, @electron-toolkit/utils, @fontsource/inter, @fontsource/jetbrains-mono, @radix-ui/react-context-menu, @radix-ui/react-dialog
packages/beatos-http/beatos_http/seed/assets/hanjiangxue.mp3
packages/beatos-http/beatos_http/seed/assets/qiyue.mp3
packages/beatos-http/beatos_http/seed/assets/regalia-cover.jpg
packages/beatos-http/beatos_http/seed/assets/regalia.mp3
screenshots/beatos-core-product-demo.gif
Gates applied: no_behavioural_pass.
fd421b42b4c0full audit observations/trust-audit/mcp-server/averatec0773__beatos.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | fd421b42b4c0 | CAUTION | B | 85 | first audit |
Questions
What is the BeatOS MCP server?
Local-first beat library built for producers — catalog, BPM/key analysis, license tiers & PDFs, tagged-MP3 + loopkit export, and assisted multi-platform publishing. Chat with your catalog via a built-in AI Agent (Claude · ChatGPT · DeepSeek), or wire it to any MCP client. Desktop + web.
What tools does BeatOS expose?
10 in total: 5 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is BeatOS safe to connect to an agent?
With care. The audit graded it B (85/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does BeatOS need?
It reads BEATOS_API_TOKEN and BEATOS_MCP_DISABLE_AUTH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does BeatOS run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as beatos-desktop at 0.0.50.
How current is this page?
The grade is for one exact copy of the source (fd421b42b4c0), read on 2026-10-08. The repository is watched and re-audited when it changes.