Atlas / MCP servers / davehenke / Rekordbox

RekordboxSAFE

mcp/davehenke/rekordbox

Open Source MCP for Rekordbox DJ

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
31 23r · 5w · 3d
Transport
—
License
MIT
Stars
116
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A comprehensive Model Context Protocol (MCP) server for rekordbox database management with real-time database access.

Built using [pyrekordbox](https://github.com/dylanljones/pyrekordbox) - This project is not affiliated with the pyrekordbox project or its maintainers.

Features

🗄️ Database Access

  • Direct SQLite Database Connection: Access the encrypted rekordbox database directly using pyrekordbox
  • Real-time Queries: Search and filter tracks with comprehensive criteria
  • Safe Mutation Operations: Playlist management with automatic backups and safety annotations

🔍 Search & Discovery

  • Advanced Search: Multi-field search across artist, title, genre, key, BPM, and more
  • Musical Key Filtering: Find tracks in compatible keys for harmonic mixing
  • BPM Range Queries: Search by tempo ranges for beatmatching
  • Rating and Play Count Filters: Discover your most loved and most played tracks

📊 Analytics & Insights

  • Library Statistics: Comprehensive stats including genre distribution, average BPM, total playtime
  • Play Count Analytics: Track listening patterns and habits
  • Collection Insights: Understand your music library composition
  • DJ History Access: Full access to your DJ session history and performance data

⚙️ Database Operations

  • Playlist Management: Create, modify, and delete playlists with safety protections
  • Batch Operations: Add multiple tracks to playlists efficiently
  • History Analysis: Access complete DJ session history and performance data
  • Library Statistics: Comprehensive analytics and insights

Architecture

  • FastMCP Framework: Modern Python MCP server using FastMCP 2.0
  • pyrekordbox Integration: Mature library for encrypted databas
Read from source at commit b00f55a2b04bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add rekordbox-mcp -- uvx rekordbox-mcp
claude-desktop
{
  "mcpServers": {
    "rekordbox-mcp": {
      "command": "uvx",
      "args": [
        "rekordbox-mcp"
      ]
    }
  }
}
03

Exposed tools (31)

23 read · 5 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_track_to_playlistwrite
add_tracks_to_playlistwrite
analyze_libraryread
cleanup_orphaned_playlist_entriesread
connect_databaseread
create_playlistwrite
delete_playlistdestructive
find_broken_tracksread
get_genre_filepathsread
get_history_sessionsread
get_history_statsread
get_library_statsread
get_most_played_tracksread
get_playlist_tracksread
get_playlistsread
get_recent_sessionsread
get_session_tracksread
get_top_rated_tracksread
get_track_detailsread
get_track_file_pathread
get_tracks_by_bpm_rangeread
get_tracks_by_keyread
get_unplayed_tracksread
import_trackwrite
import_trackswrite
remove_broken_tracksdestructive
remove_track_from_playlistdestructive
search_history_sessionsread
search_tracksread
search_tracks_by_filenameread
validate_track_idsread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_playlist, remove_broken_tracks, remove_track_from_playlist
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:28
- **DJ History Access**: Full access to your DJ session history and performance data

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b00f55a2b04bfull audit observations/trust-audit/mcp-server/davehenke__rekordbox.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b00f55a2b04bSAFEB89first audit
06

Questions

What is the Rekordbox MCP server?

Open Source MCP for Rekordbox DJ

What tools does Rekordbox expose?

31 in total: 23 read-only, 5 that write, and 3 that can delete or overwrite (delete_playlist, remove_broken_tracks, remove_track_from_playlist). Every one is listed on this page with its risk.

Is Rekordbox safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Rekordbox need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (b00f55a2b04b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement