Atlas / MCP servers / benjaminr / Koii

KoiiSAFE

mcp/benjaminr/koii

MCP Server for Teenage Engineering EP-133 KO-II

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 12r · 0w · 0d
Transport
—
License
—
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This project is a Model Context Protocol (MCP) server that acts as a controller for the Teenage Engineering EP-133 K.O. II sampler via MIDI

Features

  • Connect to your EP-133 K.O. II device via MIDI
  • Play notes and patterns through text commands
  • View the default pad configuration to understand sound mapping
  • Create and play drum patterns with a simple text-based syntax
  • Support for multiple instrument reference methods (pad labels, MIDI notes, instrument names, sound names)
  • Simultaneous playback of multiple instruments in drum patterns
  • Integration with Claude through MCP

Installation

Prerequisites

  • Python 3.8 or later
  • mido (MIDI handling)
  • mcp (Model Context Protocol SDK)

Quick Install

# Install the required packages
pip install mido "mcp[cli]"

# Clone the repository
git clone https://github.com/benjaminr/mcp-koii.git
cd mcp-koii

# Install the MCP server
mcp install koii_server.py:server -e .

Usage with Claude Desktop

  1. Make sure your EP-133 K.O. II is connected to your computer via USB.
  1. Launch Claude Desktop with MCP enabled.
  1. Start controlling your EP-133 K.O. II by asking Claude natural language questions like:
  2. "List available MIDI ports"
  3. "Connect to the EP-133 device"
  4. "Play a C major scale"
  5. "Play a drum pattern with kick on beats 1 and 3, snare on 2 and 4, and hi-hat on every 8th note"

Running in Development Mode

You can run the MCP server in development mode to test it without Claude Desktop:

# Run with the inspector UI
mcp dev koii_server.py:server -e .

Features and Commands

Basic Commands

  • List available MIDI ports: Shows all available MIDI output ports on your system.
  • Connect to a MIDI device: Connect to the EP-133 K.O. II by name or port number.
  • Disconnect: Close the connection to the current MIDI device.

#

Read from source at commit f7beb845a987OBSERVED · 2026-10-08
02

Exposed tools (12)

12 read · 0 write · 0 destructive.

ToolRiskDescription
connect_to_deviceread
disconnectread
get_default_pad_configurationread
get_scale_mappingread
list_available_scalesread
list_midi_portsread
list_sound_categoriesread
list_sounds_in_categoryread
play_drum_patternread
play_noteread
play_patternread
play_scale_sequenceread
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mido, mcp
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha f7beb845a987full audit observations/trust-audit/mcp-server/benjaminr__koii.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f7beb845a987SAFEB89first audit
05

Questions

What is the Koii MCP server?

MCP Server for Teenage Engineering EP-133 KO-II

What tools does Koii expose?

12 in total: 12 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Koii safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Koii need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (f7beb845a987), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement