Atlas / MCP servers / cswkim / Discogs

DiscogsSAFE

mcp/cswkim/discogs

MCP Server for Discogs

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
53 33r · 15w · 5d
Transport
streamable-http
License
MIT
Stars
128
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE) [](https://github.com/cswkim/discogs-mcp-server/releases) [](https://github.com/cswkim/discogs-mcp-server/actions/workflows/check-pr.yml) [](https://www.npmjs.com/package/discogs-mcp-server) [](https://github.com/sponsors/cswkim)

MCP Server for the Discogs API, enabling music catalog operations, search functionality, and more.

Quickstart

If you just want to get started immediately using this MCP Server with the Claude desktop app and don't care about development or running the server yourself, then make sure you have Node.js installed and your Discogs personal access token ready and skip straight to the Claude configuration section. Use the NPX method from that section.

Table of Contents

  • Acknowledgements
  • Available Tools
  • Caveats
  • Prerequisites
  • Setup
  • Running the Server
  • Option 1: Local Development
  • Option 2: Docker
  • Inspection
  • MCP Clients
  • Claude Desktop Configuration
  • NPX
  • Local Node
  • Docker
  • LibreChat
  • LM Studio
  • TODO
  • License

Acknowledgements

This MCP server is built using FastMCP,

Read from source at commit 8bb8881f30d2OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add discogs-mcp-server --env DISCOGS_PERSONAL_ACCESS_TOKEN=${DISCOGS_PERSONAL_ACCESS_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "discogs-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DISCOGS_PERSONAL_ACCESS_TOKEN": "${DISCOGS_PERSONAL_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (53)

33 read · 15 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_release_to_user_collection_folderwriteAdd a release to a folder in a user
add_to_wantlistwriteAdd a release to a user
create_marketplace_listingwriteCreate a new marketplace listing
create_marketplace_order_messagewriteAdds a new message to the order
create_user_collection_folderwriteCreate a new folder in a user
delete_item_in_wantlistdestructiveDelete a release from a user
delete_marketplace_listingdestructiveDelete a marketplace listing
delete_release_from_user_collection_folderdestructiveRemove an instance of a release from a user
delete_release_ratingdestructiveDeletes the release
delete_user_collection_folderdestructiveDelete a folder from a user
download_inventory_exportreadDownload an inventory export as a CSV
edit_item_in_wantlistwriteEdit a release in a user
edit_marketplace_orderwriteEdit a marketplace order
edit_release_ratingwriteUpdates the release
edit_user_collection_custom_field_valuewriteEdit a custom field value for a release in a user
edit_user_collection_folderwriteEdit a folder
edit_user_profilewriteEdit a user
fetch_imagereadFetch an image by URL
find_release_in_user_collectionreadFind a release in a user
get_artistreadGet an artist
get_artist_releasesreadGet an artist
get_inventory_exportreadGet details about an inventory export
get_inventory_exportsreadGet a list of all recent exports of your inventory
get_labelreadGet a label
get_label_releasesreadReturns a list of Releases associated with the label
get_listreadGet a list by ID
get_marketplace_listingreadGet a listing from the marketplace
get_marketplace_orderwriteGet a marketplace order
get_marketplace_order_messageswriteGet a list of an order
get_marketplace_ordersreadGet a list of marketplace orders
get_marketplace_release_statsreadRetrieve marketplace statistics for the provided Release ID
get_master_releasereadGet a master release
get_master_release_versionsreadRetrieves a list of all Releases that are versions of this master
get_releasereadGet a release
get_release_community_ratingreadRetrieves the release community rating average and count
get_release_rating_by_userreadRetrieves the release
get_user_collection_custom_fieldsreadRetrieve a list of user-defined collection notes fields. These fields are available on every release in the collection.
get_user_collection_folderreadRetrieve metadata about a folder in a user
get_user_collection_foldersreadRetrieve a list of folders in a user
get_user_collection_itemsreadRetrieve a list of items in a user
get_user_collection_valuereadReturns the minimum, median, and maximum value of a user
get_user_contributionsreadRetrieve a user
get_user_identityreadRetrieve basic information about the authenticated user
get_user_inventoryreadReturns the list of listings in a user
get_user_listsreadGet a user
get_user_profilereadRetrieve a user by username
get_user_submissionsreadRetrieve a user
get_user_wantlistreadReturns the list of releases in a user
inventory_exportreadRequest an export of your inventory as a CSV
move_release_in_user_collectionwriteMove a release in a user
rate_release_in_user_collectionreadRate a release in a user
searchreadIssue a search query to the Discogs database
update_marketplace_listingwriteUpdate a marketplace listing
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_item_in_wantlist, delete_marketplace_listing, delete_release_from_user_collection_folder, delete_release_rating, delete_user_collection_folder
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.test
.env.test
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/scripts/check-version.js:9
const pkgPath = join(__dirname, '../../package.json');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/scripts/check-version.js:15
const versionTs = readFileSync(join(__dirname, '../../src/version.ts'), 'utf8');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/user/collection.ts:1
import { isDiscogsError } from '../../errors.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/user/collection.ts:2
import { UsernameInput } from '../../types/common.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/user/collection.ts:26
} from '../../types/user/index.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:118
This will start the MCP Inspector at `http://127.0.0.1:6274`. Visit this URL in your browser to interact with your local MCP server.
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
tests/utils/testImageData.ts:6
data: '/9j/4QAiRXhpZgAATU0AKgAAAAgAAQESAAMAAAABAAEAAAAAAAD/2wCEAAMCAgMCAgMDAwMEAwMEBQgFBQQEBQoHBwYIDAoMDAsKCwsNDhIQDQ4RDgsLEBYQERMUFRUVDA8XGBYUGBIUFRQBAwQEBQQFCQUFCRQNCw0UFBQUFBQUFBQUFBQUFBQUFBQUFBQUF
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, fastmcp, zod, @changesets/cli, @eslint/js, @svitejs/changesets-changelog-github-compact, @types/node
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:64
To get your Discogs personal access token, go to your [Discogs Settings > Developers](https://www.discogs.com/settings/developers) page and find your token or generate a new one. **_DO NOT SHARE YOUR
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 8bb8881f30d2full audit observations/trust-audit/mcp-server/cswkim__discogs.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-078bb8881f30d2SAFEB89first audit
06

Questions

What is the Discogs MCP server?

MCP Server for Discogs

What tools does Discogs expose?

53 in total: 33 read-only, 15 that write, and 5 that can delete or overwrite (delete_item_in_wantlist, delete_marketplace_listing, delete_release_from_user_collection_folder, delete_release_rating, delete_user_collection_folder). Every one is listed on this page with its risk.

Is Discogs safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Discogs need?

It reads DISCOGS_PERSONAL_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Discogs run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as discogs-mcp-server at 0.5.7.

How current is this page?

The grade is for one exact copy of the source (8bb8881f30d2), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement