Atlas / MCP servers / cassette-editor / Oh My Cassette

Oh My CassetteSAFE

mcp/cassette-editor/oh-my-cassette

你的随身 AI 剪辑搭档 | Pocket AI co-editor for video montage — AI video editing plugin & MCP server for Claude Code, Codex, Hermes & OpenCode

Verdict
SAFE
Grade
B
Trust score
87 /100
Exposed tools
6 6r · 0w · 0d
Transport
stdio
License
MIT
Stars
157
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Oh My Cassette: Chat Your Raw Clips Into a Finished Cut

Read from source at commit fd3b08beca41OBSERVED · 2026-10-07
02

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
cassette_cancel_jobreadrequest = CancelJobInput(job_id=job_id)
cassette_list_assetsreadrequest = ListAssetsInput(session_id=session_id, chat_id=chat_id)
cassette_make_promptreadrequest = MakePromptInput.model_validate(
cassette_match_bgmreadrequest = MatchBgmInput(
cassette_match_exact_bgmreadrequest = MatchExactBgmInput(
jamendo_music_matcherreadrequest = JamendoMatcherInput.model_validate(
03

Trust audit

SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (23)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_mcp_protocol.py:790
password = "protocol-emailed-password"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codexignore
.codexignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.plugin-scanner.toml
.plugin-scanner.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
core/tools.py:1583
digest = hashlib.sha1(json.dumps(beats, sort_keys=True).encode("utf-8")).hexdigest()[:10]
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_jobs.py:48
jobs.load_job("../../credentials")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_api_transport_mock.py:54
monkeypatch.setenv("CASSETTE_API_URL", f"http://127.0.0.1:{port}")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_api_transport_mock.py:327
monkeypatch.setenv("CASSETTE_API_URL", f"http://127.0.0.1:{port}")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_api_transport_mock.py:867
monkeypatch.setenv("CASSETTE_API_URL", f"http://127.0.0.1:{port}")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_api_transport_mock.py:924
monkeypatch.setenv("CASSETTE_API_URL", f"http://127.0.0.1:{port}")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_api_transport_mock.py:1238
monkeypatch.setenv("CASSETTE_WEB_URL", "http://127.0.0.1:8080")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
core/notifier.py:447
decoded = base64.b64decode(hermes_aes_key_for_api, validate=True).decode("ascii")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
core/notifier.py:452
return base64.b64encode(bytes.fromhex(decoded)).decode("ascii")
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
core/tools.py:1493
poster.write_bytes(base64.b64decode(b64 or "", validate=False))
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:330
The Hermes installer prompts for your Cassette account email and password and saves them to `~/.hermes/.env`. Then run the setup finisher — it configures the same stdio MCP server and canonical editin
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.agents/skills/cassette-video-edit/references/auth.md:44
| `auth_not_authorized` | the address has no Cassette access | not about the password at all — relay that Cassette access has to be granted for the address first |
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SECURITY.md:55
- `.env`, credentials, access/refresh tokens, API keys, or passwords;
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/privacy.md:71
Anyone who can read the credential file can use the account. Use a dedicated account where you can,
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/cassette-video-edit/references/auth.md:44
| `auth_not_authorized` | the address has no Cassette access | not about the password at all — relay that Cassette access has to be granted for the address first |
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:212
curl -fsSL https://raw.githubusercontent.com/NousResearch/hermes-agent/main/scripts/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:263
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.zh-cn.md:206
curl -fsSL https://raw.githubusercontent.com/NousResearch/hermes-agent/main/scripts/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.zh-cn.md:256
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fd3b08beca41full audit observations/trust-audit/mcp-server/cassette-editor__oh-my-cassette.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fd3b08beca41SAFEB87first audit
05

Questions

What is the Oh My Cassette MCP server?

你的随身 AI 剪辑搭档 | Pocket AI co-editor for video montage — AI video editing plugin & MCP server for Claude Code, Codex, Hermes & OpenCode

What tools does Oh My Cassette expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Oh My Cassette safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Oh My Cassette need?

It reads CASSETTE_AUTH_ACCOUNT, CASSETTE_AUTH_EMAIL, CASSETTE_AUTH_PASSWORD, CASSETTE_AUTH_TOKEN, CASSETTE_E2E_ACCEPTANCE_HOOK_TOKEN, CASSETTE_PASSWORD and QQ_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Oh My Cassette run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (fd3b08beca41), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement